800-53|AU-7(1)

Title

AUTOMATIC PROCESSING

Description

The information system provides the capability to process audit records for events of interest based on [Assignment: organization-defined audit fields within audit records].

Supplemental

Events of interest can be identified by the content of specific audit record fields including, for example, identities of individuals, event types, event locations, event times, event dates, system resources involved, IP addresses involved, or information objects accessed. Organizations may define audit event criteria to any degree of granularity required, for example, locations selectable by general networking location (e.g., by network or subnetwork) or selectable by specific information system component.

Reference Item Details

Related: AU-12,AU-2

Category: AUDIT AND ACCOUNTABILITY

Parent Title: AUDIT REDUCTION AND REPORT GENERATION

Family: AUDIT AND ACCOUNTABILITY

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.4 SOL-11.1-010080UnixCIS Solaris 11 X86 STIG v1.0.0 CAT II
1.4 SOL-11.1-010080UnixCIS Solaris 11 SPARC STIG v1.0.0 CAT II
1.4.3 SNMP TrapsArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 L2
1.4.3 SNMP TrapsArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
1.13 UBTU-24-100400UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.14 UBTU-24-100410UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.24 AZLX-23-001025UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.25 AZLX-23-001030UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.65 RHEL-10-200660UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.66 RHEL-10-200661UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.84 OL09-00-000440UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.85 OL09-00-000441UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.108 SLES-15-030050UnixCIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II
1.119 UBTU-22-653010UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.120 UBTU-22-653015UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.138 APPL-26-005001UnixCIS Apple macOS 26 Tahoe STIG v1.0.0 CAT I
1.139 APPL-14-005001UnixCIS Apple macOS 14 Sonoma STIG v1.0.0 CAT I
1.229 OL08-00-030180UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.230 OL08-00-030181UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.361 ALMA-09-047100UnixCIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II
1.367 RHEL-09-653010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.368 RHEL-09-653015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.425 ALMA-09-054910UnixCIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II
2.1 Ensure monitoring and alerting exist for ACCOUNTADMIN and SECURITYADMIN role grantsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.1 Ensure That Cloud Audit Logging Is Configured ProperlyGCPCIS Google Cloud Platform Foundation v5.0.0 L1
2.2 Ensure monitoring and alerting exist for MANAGE GRANTS privilege grantsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.3 Ensure monitoring and alerting exist for password sign-ins of SSO usersSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.4 Ensure monitoring and alerting exist for password sign-in without MFASnowflakeCIS Snowflake Foundations v1.0.0 L1
2.5 Ensure monitoring and alerting exist for creation, update and deletion of security integrationsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.6 Ensure monitoring and alerting exist for changes to network policies and associated objectsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.7 Ensure monitoring and alerting exist for SCIM token creationSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.8 Ensure monitoring and alerting exists for new share exposuresSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.9 Ensure monitoring and alerting exists for sessions from unsupported Snowflake Connector for Python and JDBC and ODBC driversSnowflakeCIS Snowflake Foundations v1.0.0 L2
2.13 Ensure That Cloud DNS Logging Is Enabled for All VPC NetworksGCPCIS Google Cloud Platform Foundation v5.0.0 L1
3.4 Ensure proxies pass source IP informationUnixCIS NGINX v3.0.0 L1 Proxy
3.4 Ensure proxies pass source IP informationUnixCIS NGINX v3.0.0 L1 Loadbalancer
4.2 Ensure CloudTrail log file validation is enabledamazon_awsCIS Amazon Web Services Foundations v7.0.0 L2
5.1 Ensure unauthorized API calls are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L2
5.2 Ensure management console sign-in without MFA is monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1
5.3 Ensure usage of the 'root' account is monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1
5.4 Ensure IAM policy changes are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1
5.5 Ensure CloudTrail configuration changes are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1
5.6 Ensure AWS Management Console authentication failures are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L2
5.7 Ensure disabling or scheduled deletion of customer created CMKs is monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L2
5.10 Ensure security group changes are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L2
5.11 Ensure Network Access Control List (NACL) changes are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L2
5.12 Ensure changes to network gateways are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1
5.13 Ensure route table changes are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1
5.14 Ensure VPC changes are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1
5.15 Ensure AWS Organizations changes are monitoredamazon_awsCIS Amazon Web Services Foundations v7.0.0 L1