PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AU-3 — Content of Audit Records

Framework: NIST SP 800-53 Rev.5 AU-3 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Examine a sample of raw audit records and confirm each contains all AU-3 required content: type of event, date/time (timestamp), where the event occurred (system/component), the source of the event, the outcome (success/failure), and the identity of the individual or subject associated with the event.
Test Trigger a live event and inspect the produced record to verify every required content field is populated (no null/blank actor, timestamp, or outcome fields).
Examine Examine the logging configuration for AU-3(1) additional content where required (e.g., full text of privileged commands, session identifiers, source/destination IP and port, or accessed filenames) and confirm it is captured for high-risk events.
Examine Examine that timestamps in audit records are drawn from an authoritative, synchronized time source and recorded in a consistent format/time zone (e.g., UTC), consistent with CIS Control 8.4.
Test Verify by test that records attribute actions to an individual account rather than a shared/generic identity, so the record content is sufficient to identify the responsible user.
Interview Interview log-engineering personnel on how record content is standardized or normalized across heterogeneous log sources so that the required fields are reliably present when records are aggregated in the SIEM.