{"data":{"id":"AU-14","name":"Session Audit","family":"AU","family_name":"Audit and Accountability","withdrawn":false,"description":"a. Provide and implement the capability for [Assignment: organization-defined users or roles] to [Selection (one or more): record; view; hear; log] the content of a user session under [Assignment: organization-defined circumstances]; and\nb. Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.","supplemental_guidance":"Session audits can include monitoring keystrokes, tracking websites visited, and recording information and/or file transfers. Session audit capability is implemented in addition to event logging and may involve implementation of specialized session capture technology. Organizations consider how session auditing can reveal information about individuals that may give rise to privacy risk as well as how to mitigate those risks. Because session auditing can impact system and network performance, organizations activate the capability under well-defined situations (e.g., the organization is suspicious of a specific individual). Organizations consult with legal counsel, civil liberties officials, and privacy officials to ensure that any legal, privacy, civil rights, or civil liberties issues, including the use of personally identifiable information, are appropriately addressed.","enhancements":[{"id":"AU-14(01)","name":"System Start-up","statement":"Initiate session audits automatically at system start-up.","baselines":[]},{"id":"AU-14(02)","name":"Capture and Record Content","withdrawn":true,"incorporated_into":["AU-14"]},{"id":"AU-14(03)","name":"Remote Viewing and Listening","statement":"Provide and implement the capability for authorized users to remotely view and hear content related to an established user session in real time.","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"AU-14","name":"Session Audit","description":"a. Provide and implement the capability for [Assignment: organization-defined users or roles] to [Selection (one or more): record; view; hear; log] the content of a user session under [Assignment: organization-defined circumstances]; and\nb. Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.","discussion":"Session audits can include monitoring keystrokes, tracking websites visited, and recording information and/or file transfers. Session audit capability is implemented in addition to event logging and may involve implementation of specialized session capture technology. Organizations consider how session auditing can reveal information about individuals that may give rise to privacy risk as well as how to mitigate those risks. Because session auditing can impact system and network performance, organizations activate the capability under well-defined situations (e.g., the organization is suspicious of a specific individual). Organizations consult with legal counsel, civil liberties officials, and privacy officials to ensure that any legal, privacy, civil rights, or civil liberties issues, including the use of personally identifiable information, are appropriately addressed.","related_controls":["AC-03","AC-08","AU-02","AU-03","AU-04","AU-05","AU-08","AU-09","AU-11","AU-12"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":["7.5","A.8.15"],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":["CIS 8.8"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.16","Annex1.17"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":["TME1.8.2"],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2l"],"swift_cscf":["SWIFT.2.6"],"cbb_tm":["TM-12"],"nca_ecc":["2-12"],"qatar_nia":["OS"],"bom_ctrm":["4.2"],"cbe_csf":["CD-1"],"bot_cyber":["Ch3.1"],"cpmi_pfmi":["CG.DE"],"eba_ict":["3.4.5"],"ecb_croe":["CROE.2.4"],"ffiec_is":["III.B"],"hipaa_sr":["§164.308(a)(1)(ii)(D)","§164.312(b)"],"iosco_cyber":["DET-1"],"sebi_cscrf":["DE.AU"],"cmmc_2":["AU"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":["TIBER.BT"],"pci_hsm":[],"common_criteria":["CC Part 2 — FAU"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.10(e)"],"fda_cyber":[],"hitrust_csf":["09.g","11.c"],"iso_27799":["12.4"],"lloyds_ms":["MS8.12"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":["P-IT.2"],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: iso_27001_2022 A.8.15 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":[]}}