AU-3: CONTENT OF AUDIT RECORDS
TAILORED FOR INDUSTRIAL CONTROL SYSTEMS
The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.
SUPPLEMENTAL GUIDANCE
Audit record content that may be necessary to satisfy the requirement of this control, includes, for example, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked. Event outcomes can include indicators of event success or failure and event-specific results (e.g., the security state of the information system after the event occurred).
ICS SUPPLEMENTAL GUIDANCE
Example compensating controls include providing an auditing capability on a separate information system.
RELATED CONTROLS: AU-3
CONTROL ENHANCEMENTS
AU-3 (1) CONTENT OF AUDIT RECORDS | ADDITIONAL AUDIT INFORMATION
ICS Control Baselines:
- Moderate
- High
The information system generates audit records containing the following additional information: [Assignment: organization-defined additional, more detailed information].
Supplemental Guidance:
Detailed information that organizations may consider in audit records includes, for example, full text recording of privileged commands or the individual identities of group account users. Organizations consider limiting the additional audit information to only that information explicitly needed for specific audit requirements. This facilitates the use of audit trails and audit logs by not including information that could potentially be misleading or could make it more difficult to locate information of interest.
No ICS Supplemental Guidance.
AU-3 (2) CONTENT OF AUDIT RECORDS | CENTRALIZED MANAGEMENT OF PLANNED AUDIT RECORD CONTENT
ISC Control Baseline:
- High
The information system provides centralized management and configuration of the content to be captured in audit records generated by [Assignment: organization-defined information system components].
Supplemental Guidance:
This control enhancement requires that the content to be captured in audit records be configured from a central location (necessitating automation). Organizations coordinate the selection of required audit content to support the centralized management and configuration capability provided by the information system.
No ICS Supplemental Guidance.
RELATED CONTROLS: AU-3 (2)
REFERENCES:
- NIST Special Publication 800-82 | GUIDE TO INDUSTRIAL CONTROL SYSTEMS (ICS) SECURITY