PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AU-9 — Protection of Audit Information

Framework: NIST SP 800-53 Rev.5 AU-9 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine access controls on audit logs and log repositories to confirm read access is limited to authorized roles and that modification/deletion of records is restricted, ideally to a documented least-privilege subset.
Test Attempt to alter or delete an existing audit record as both an ordinary and a privileged user to confirm tamper protection (e.g., write-once/immutable or WORM storage) prevents or records the attempt.
Examine Examine that audit records are backed up or forwarded to a physically or logically separate system/central log server (AU-9(2), CIS 8.9) so that compromise of the source host does not destroy the evidence.
Examine Examine configuration for cryptographic integrity protection of audit information (e.g., hashing, signing, or checksums per AU-9(3)) and verify integrity can be validated on demand.
Interview Interview security personnel to confirm separation of duties: the privileged users authorized to manage the audit/logging function are distinct from the administrators whose activity is being logged (AU-9(4)/(5)).
Examine Examine that audit tools (log viewers, collectors, export utilities) are themselves access-restricted so unauthorized users cannot use them to read or alter audit information.
Test Test that log forwarding to the central store is continuous and that access to the central repository enforces authorized accounts and multi-factor authentication.