# AU-06 Audit Record Review, Analysis, and Reporting

NIST SP 800-53 control. Family: AU Audit and Accountability. Function: detective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Review and analyze system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity] and the potential impact of the inappropriate or unusual activity; b. Report findings to [Assignment: organization-defined personnel or roles]; and c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.
Guidance: Audit record review, analysis, and reporting covers information security- and privacy-related logging performed by organizations, including logging that results from the monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and non-local maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at system interfaces, and use of mobile code or Voice over Internet Protocol (VoIP). Findings can be reported to organizational entities that include the incident response team, help desk, and security or privacy offices. If organizations are prohibited from reviewing and analyzing audit records or unable to conduct such activities, the review or analysis may be carried out by other organizations granted such authority. The frequency, scope, and/or depth of the audit record review, analysis, and reporting may be adjusted to meet organizational needs based on new information received.

## Enhancements (8)
- AU-06(01) Automated Process Integration. Baselines: moderate, high
- AU-06(03) Correlate Audit Record Repositories. Baselines: moderate, high
- AU-06(04) Central Review and Analysis
- AU-06(05) Integrated Analysis of Audit Records. Baselines: high
- AU-06(06) Correlation with Physical Monitoring. Baselines: high
- AU-06(07) Permitted Actions
- AU-06(08) Full Text Analysis of Privileged Commands
- AU-06(09) Correlation with Information from Nontechnical Sources
Withdrawn by NIST: AU-06(02) (now in SI-04); AU-06(10) (now in AU-06).
Each enhancement's statement: /api/v1/controls/AU-06?fields=enhancements

## Patterns that use it (30)
- Critical (9): SP-002 Server Module; SP-011 Cloud Computing Pattern; SP-016 DMZ Module; SP-020 Email Transport Layer Security (TLS) Pattern; SP-025 Advanced Monitoring and Detection; SP-026 PCI Full Environment; SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-036 Incident Response
- Important (17): SP-017 Secure Network Zone Module; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-021 Realtime Collaboration Pattern; SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline Pattern; SP-030 API Security; SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-035 Offensive Security Testing; SP-037 Privileged User Management; SP-043 Security Metrics and Measurement; SP-044 SaaS Identity Lifecycle Management; SP-045 AI Governance and Responsible AI; SP-047 Secure Agentic AI Frameworks; SP-048 Offensive AI and Deepfake Defence (draft); SP-049 AI in Security Operations (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (4): SP-038 Vulnerability Management and Patching; SP-039 Client-Side Encryption and Data Privacy; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-052 Decentralised Identity & Verifiable Credentials (draft)

## Clauses by framework (83 frameworks)
- iso_27001_2022: 7.5, 9.2, A.5.25, A.5.28, A.5.36, A.6.8, A.8.15, A.8.16, A.8.34. OSA's own, not in NIST's crosswalk: 7.5, 9.2, A.5.28, A.5.36, A.8.16, A.8.34
- iso_27002_2022: 5.28, 5.36, 8.15, 8.16, 8.34
- cobit_2019: DSS06, MEA01, MEA02
- pci_dss_v4: 10.4, 11.5
- nist_csf_2: DE.AE-02, DE.AE-03, DE.AE-04, DE.AE-06, DE.CM-01, DE.CM-03, DE.CM-09, PR.PS-04, RS.AN-03. OSA's own, not in NIST's crosswalk: DE.AE-04, DE.AE-06, DE.CM-01, DE.CM-03, DE.CM-09, RS.AN-03
- cis_controls_v8: CIS 8, CIS 8.9, CIS 8.11, CIS 12.5, CIS 13, CIS 13.1, CIS 13.11
- soc2_tsc: CC7.2, CC7.2-POF1, CC7.3
- finos_ccc: CCC-C04, CCC-C08, CCC-C17
- iso_42001_2023: A.6.2.6, A.6.2.8
- iec_62443: 3-3 SR 6.1
- apra_cps_234: Para 22-23
- mas_trm: 12
- pra_op_resilience: SS2/21-15.1
- bsi_grundschutz: DER.1, OPS.1.1.5
- anssi: Hygiene.29, Hygiene.39, SecNumCloud.13.7, SecNumCloud.17.1
- osfi_b13: B-13.3.3
- finma_circular: IV.C(66), IV.C(67), IV.C(68), IV.C(69)
- gdpr: Art.32(1)(d), Art.33(3)(d)
- dora: Art.10(1), Art.10(2)
- bio2: 5.28, 5.36, 8.15, 8.16, 8.34
- rbi_csf: Annex1.16, Annex1.20, Annex1.22
- fisc: FISC.O2, FISC.O11
- lgpd_bcb: BCB.Art.6, BCB.Art.8, LGPD.Art.48
- hkma_tme1: TME1.2.6, TME1.5.2, TME1.7.5
- mlps_2: 8.1.3.5, 8.1.4.3, 8.1.5.2, 8.1.5.4
- dnb_good_practice: DNB.16.1
- cra: CRA.I.2d, CRA.I.2l
- swift_cscf: SWIFT.2.9, SWIFT.6.4
- cbb_tm: TM-12, TM-13, TM-16
- cbuae: CR-3
- nca_ecc: 1-8, 2-12
- qatar_nia: IM, OS
- sama_csf: 1.9, 3.6
- uae_ia: T7, T11
- bog_cisd: CISD-IV, CISD-VII
- bom_ctrm: 1.5, 4.2, 5.1
- cbe_csf: CD-1
- cbn_csf: Part3.5, Part9
- popia: s19, s22, s73-99
- sa_js2: JS2-7.3, JS2-9
- bcbs_239: Principle 7, Principle 10, Principle 12
- bot_cyber: Ch3.1, Ch6.1, Ch8.2
- cpmi_pfmi: CG.DE, PFMI.P17
- eba_ict: 3.4.5, 3.5(c), 3.8(c)
- ecb_croe: CROE.2.4
- ffiec_is: II.C.15, II.C.18, II.D, III.B, III.C, IV.A.4
- hipaa_sr: §164.308(a)(1)(ii)(D), §164.308(a)(5)(ii)(C), §164.308(a)(6)(ii), §164.312(b)
- iosco_cyber: DET-1, DET-2, DET-4
- nydfs_500: 500.6, 500.14, 500.17
- sebi_cscrf: AUDIT, DE.AU, DE.CM, RS.AN, SOC
- cmmc_2: AU
- nerc_cip: CIP-007-6, CIP-015-1
- nrc_73_54: RG5.71-A-AU
- tsa_psd: SD-2 Sec C
- ieee_1686: 5.2
- ferc_cip: Order 881
- doe_c2m2: SITUATION
- api_1164: Sec 9
- awia: AWWA Sec 5
- iaea_nss: Sec 5.5
- pci_pts: L
- cbest: CBEST.5
- tiber_eu: TIBER.BT
- pci_hsm: 8, 10
- common_criteria: CC Part 2 — FAU
- isae_3402: Clause 4, Clause 6, Clause 10
- fca_sysc_13: SYSC 13.7.5
- fda_21_cfr_11: §11.10(e)
- fda_cyber: SA-5
- hitrust_csf: 09.g, 11.b
- iso_27799: 9.2, 12.4
- lloyds_ms: MS2.1, MS5.1, MS8.5, MS8.12
- naic_ds: 4-audit, 4B, 5, 6-a
- pra_ss1_23: P3.4, P3.6, P4.5, P5.2, P-IT.2
- solvency_ii: Art.46, EIOPA-ICT-4.9
- csa_ccm_v4: AA-05, LOG-03, LOG-04, LOG-05, LOG-13, SEF-06
- csa_aicm: A&A-05, AIS-12, LOG-03, LOG-04, LOG-05, LOG-13, LOG-14, MDS-05, SEF-06
- ccss_v9: 1.02.8, 2.01.3, 2.03.1, 2.03.2, 2.04.2, 2.04.3
- mica: Art.62(8), Art.88(1), Art.92(1)
- basel_sco60: SCO60.13, SCO60.23, SCO60.55, SCO60.72, SCO60.73, SCO60.74
- bssc: GSP-12, NOS-06
- sec_custody_digital: SEC-CD-11, SEC-CD-14, SEC-CD-15, SEC-CD-16, SEC-CD-18, SEC-CD-20
- dpdpa: Act.8(5), Rules.6(1)(c), Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AU-06
- Clauses only: /api/v1/controls/AU-06?fields=mappings
- Page for people: /controls/au-06/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
