PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AU-6 — Audit Record Review, Analysis, and Reporting

Framework: NIST SP 800-53 Rev.5 AU-6 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine documented procedures that define the frequency, scope, and roles for reviewing and analyzing audit records for indications of inappropriate or unusual activity (CIS Control 8.11).
Examine Examine review artifacts (SIEM case records, analyst sign-offs, dated review logs, or tickets) demonstrating that audit-record reviews are actually performed at the organization-defined frequency, not just documented.
Examine Examine the SIEM/analytic tooling to confirm automated mechanisms and correlation rules are in place to integrate and analyze records across multiple repositories (AU-6(1)/(3)) rather than relying solely on manual review.
Test Inject a known suspicious pattern (e.g., repeated failed logons followed by success, or off-hours privileged access) and confirm the control detects, alerts on, and surfaces it for analyst review.
Interview Interview SOC/security analysts on how anomalies are triaged, escalated, and reported to the organization-defined roles, and how findings are documented.
Interview Interview responsible personnel on how the level or frequency of audit review and analysis is adjusted when there is a change in organizational risk (AU-6c), citing a recent example.
Examine Examine reporting outputs (incident reports, escalations, or management summaries) to confirm review findings are communicated to the designated roles for action.