800-53|AU-6

Title

AUDIT REVIEW, ANALYSIS, AND REPORTING

Description

The organization:

Supplemental

Audit review, analysis, and reporting covers information security-related auditing performed by organizations including, for example, auditing that results from monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and nonlocal maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at the information system boundaries, use of mobile code, and use of VoIP. Findings can be reported to organizational entities that include, for example, incident response team, help desk, information security group/department. If organizations are prohibited from reviewing and analyzing audit information or unable to conduct such activities (e.g., in certain national security applications or systems), the review/analysis may be carried out by other organizations granted such authority.

Reference Item Details

Related: AC-17,AC-2,AC-3,AC-6,AT-3,AU-16,AU-7,CA-7,CM-10,CM-11,CM-5,IA-3,IA-5,IR-5,IR-6,MA-4,MP-4,PE-14,PE-16,PE-3,PE-6,RA-5,SC-18,SC-19,SC-7,SI-3,SI-4,SI-7

Category: AUDIT AND ACCOUNTABILITY

Family: AUDIT AND ACCOUNTABILITY

Priority: P1

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2.15 Ensure that the --profiling argument is set to falseUnixCIS Kubernetes Benchmark v1.9.0 L1 Master
1.2.17 Ensure that the --profiling argument is set to falseUnixCIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master
1.2.17 Ensure that the --profiling argument is set to falseUnixCIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master
1.2.20 Ensure that the --profiling argument is set to falseUnixCIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master
1.6.4 Configure NTP AuthenticationCiscoCIS Cisco NX-OS L2 v1.0.0
1.7 Ensure logging data is monitoredJuniperCIS Juniper OS Benchmark v2.1.0 L1
2.1 Ensure That Cloud Audit Logging Is Configured ProperlyGCPCIS Google Cloud Platform v3.0.0 L1
2.1.11 Ensure the spoofed domains report is reviewed weeklymicrosoft_azureCIS Microsoft 365 Foundations E5 L1 v3.0.0
2.1.12 Ensure the 'Restricted entities' report is reviewed weeklymicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v3.0.0
2.1.13 Ensure all security threats in the Threat protection status report are reviewed at least weeklymicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v3.0.0
2.2.1 Ensure Firewall Is EnabledUnixCIS Apple macOS 13.0 Ventura v2.0.0 L1
2.2.1 Ensure Firewall Is EnabledUnixCIS Apple macOS 14.0 Sonoma v1.0.0 L1
2.2.4 Set IP address for 'logging host'CiscoCIS Cisco IOS 16 L1 v2.0.0
2.2.4 Set IP address for 'logging host'CiscoCIS Cisco IOS 17 L1 v2.0.0
2.2.4 Set IP address for 'logging host'CiscoCIS Cisco IOS 15 L1 v4.1.1
2.3.1 Ensure the Account Provisioning Activity report is reviewed at least weeklymicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v3.0.0
2.3.2 Ensure non-global administrator role group assignments are reviewed at least weeklymicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v3.0.0
2.5.2.1 Ensure Firewall Is EnabledUnixCIS Apple macOS 11.0 Big Sur v4.0.0 L1
2.5.2.1 Ensure Firewall Is EnabledUnixCIS Apple macOS 10.15 Catalina v3.0.0 L1
2.5.2.1 Ensure Firewall Is EnabledUnixCIS Apple macOS 12.0 Monterey v3.0.0 L1
2.5.2.2 Ensure Firewall Is EnabledUnixCIS Apple macOS 10.14 v2.0.0 L1
2.12 Ensure That Cloud DNS Logging Is Enabled for All VPC NetworksGCPCIS Google Cloud Platform v3.0.0 L1
2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated every 20 minutes or less on weekday 8a-5p'UnixCIS AIX 5.3/6.1 L2 v1.1.0
2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated hourly on weekday 6p-7a'UnixCIS AIX 5.3/6.1 L2 v1.1.0
2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated hourly on weekends'UnixCIS AIX 5.3/6.1 L2 v1.1.0
2.12.8 - Miscellaneous Config - enable sar accounting - 'daily summaries are being prepared'UnixCIS AIX 5.3/6.1 L2 v1.1.0
2.13 Ensure centralized and remote logging is configuredUnixCIS Docker v1.6.0 L2 Docker Linux
3.1 Ensure a centralized location is configured to collect ESXi host core dumpsUnixCIS VMware ESXi 6.7 v1.3.0 Level 1 Bare Metal
3.1 Ensure a centralized location is configured to collect ESXi host core dumpsUnixCIS VMware ESXi 7.0 v1.3.0 Level 1 Bare Metal
3.1.2 Ensure user role group changes are reviewed at least weeklymicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v3.0.0
3.1.14 Ensure 'debug_print_parse' is disabledPostgreSQLDBCIS PostgreSQL 10 DB v1.0.0
3.1.14 Ensure 'debug_print_parse' is disabledPostgreSQLDBCIS PostgreSQL 9.6 DB v1.0.0
3.1.15 Ensure 'debug_print_rewritten' is disabledPostgreSQLDBCIS PostgreSQL 10 DB v1.0.0
3.1.15 Ensure 'debug_print_rewritten' is disabledPostgreSQLDBCIS PostgreSQL 9.6 DB v1.0.0
3.1.15 Ensure 'log_min_duration_statement' is disabledPostgreSQLDBCIS PostgreSQL 9.5 DB v1.1.0
3.1.16 Ensure 'debug_print_parse' is disabledPostgreSQLDBCIS PostgreSQL 9.5 DB v1.1.0
3.1.16 Ensure 'debug_print_plan' is disabledPostgreSQLDBCIS PostgreSQL 10 DB v1.0.0
3.1.16 Ensure 'debug_print_plan' is disabledPostgreSQLDBCIS PostgreSQL 9.6 DB v1.0.0
3.1.17 Ensure 'debug_print_rewritten' is disabledPostgreSQLDBCIS PostgreSQL 9.5 DB v1.1.0
3.1.18 Ensure 'debug_print_plan' is disabledPostgreSQLDBCIS PostgreSQL 9.5 DB v1.1.0
3.1.21 Ensure 'log_hostname' is set correctlyPostgreSQLDBCIS PostgreSQL 10 DB v1.0.0
3.1.21 Ensure 'log_hostname' is set correctlyPostgreSQLDBCIS PostgreSQL 9.6 DB v1.0.0
20.13 Ensure 'Audit records must be backed up to a different system or media than the system being audited'WindowsCIS Microsoft Windows Server 2016 STIG DC STIG v1.1.0
20.13 Ensure 'Audit records must be backed up to a different system or media than the system being audited'WindowsCIS Microsoft Windows Server 2019 STIG DC STIG v1.0.1
20.13 Ensure 'Audit records must be backed up to a different system or media than the system being audited'WindowsCIS Microsoft Windows Server 2016 STIG MS STIG v1.1.0
20.13 Ensure 'Audit records must be backed up to a different system or media than the system being audited'WindowsCIS Microsoft Windows Server 2019 STIG MS STIG v1.0.1
20.38 Ensure 'Off-load of audit records of interconnected systems in real time and off-load standalone systems weekly'WindowsCIS Microsoft Windows Server 2019 STIG DC STIG v1.0.1
20.38 Ensure 'Off-load of audit records of interconnected systems in real time and off-load standalone systems weekly'WindowsCIS Microsoft Windows Server 2019 STIG MS STIG v1.0.1
20.39 Ensure 'Off-load of audit records of interconnected systems in real time and off-load standalone systems weekly'WindowsCIS Microsoft Windows Server 2016 STIG DC STIG v1.1.0
20.39 Ensure 'Off-load of audit records of interconnected systems in real time and off-load standalone systems weekly'WindowsCIS Microsoft Windows Server 2016 STIG MS STIG v1.1.0