HOME

AU-5

AU-5 H M L
Description

The information system:
a. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; and
b. Takes the following additional actions: [Assignment: organization-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)].

FedRAMP
  • H AU-5 (b) [organization-defined actions to be taken (overwrite oldest record)
  • M AU-5 (b) [organization-defined actions to be taken (overwrite oldest record)
  • L AU-5 (b) [organization-defined actions to be taken (overwrite oldest record)
DISA Cloud Computing SRG

a. At a minimum, the SCA and ISSO
b. Not appropriate for DoD to define for all CSP's infrastructure or service offerings

Source:
DoD RMF TAG

Supplemental Guidance

Audit processing failures include, for example, software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. Organizations may choose to define additional actions for different audit processing failures (e.g., by type, by location, by severity, or a combination of such factors). This control applies to each audit data storage repository (i.e., distinct information system component where audit records are stored), the total audit storage capacity of organizations (i.e., all audit data storage repositories combined), or both.

Related Controls