PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AU-2 — Event Logging

Framework: NIST SP 800-53 Rev.5 AU-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Does an approved event logging policy/procedure exist that enumerates the specific event types the organization requires to be logged (e.g., logon/logoff, account and group management, privilege use, object/file access, security policy changes, process creation) and the rationale that these support after-the-fact investigations, per CIS Control 8.2?
Examine On a representative sample of in-scope systems (OS, database, network device, cloud/SaaS tenant), inspect the active audit/logging configuration to confirm the organization-defined event types are actually enabled and not left at vendor defaults, giving coverage across all in-scope assets (CIS 8.5).
Test Perform a controlled test event of each major category (e.g., a failed and successful logon, a privilege escalation, and an account creation) and confirm each generates a corresponding audit record in the log store.
Interview Interview system owners and the security/logging team on how the audit logging function is coordinated among the systems, components, and entities in scope so that required events are captured consistently end to end.
Examine Examine review records (dated minutes, tickets, or a change log) showing the set of logged event types is reviewed and updated at the organization-defined frequency and upon significant system or threat changes (AU-2c/e).
Interview Interview security personnel to determine how the selected subset of logged events was justified against risk and investigative need, and how gaps identified in prior incidents fed back into the logging selection.