# AU-15 Alternate Audit Logging Capability

NIST SP 800-53 control. Family: AU Audit and Accountability. Function: detective. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into AU-05.

Statement: Provide an alternate audit logging capability in the event of a failure in primary audit logging capability that implements [Assignment: organization-defined alternate audit logging functionality].
Guidance: Since an alternate audit logging capability may be a short-term protection measure employed until the failure in the primary audit logging capability is corrected, organizations may determine that the alternate audit logging capability need only provide a subset of the primary audit logging capability that is affected by the failure.

## Clauses by framework (1 frameworks)
- iso_27001_2022: 7.5. OSA's own, not in NIST's crosswalk: 7.5
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AU-15
- Clauses only: /api/v1/controls/AU-15?fields=mappings
- Page for people: /controls/au-15/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
