Policy and Procedures AU-1
Audit and Accountability · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds AU-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Audit and Accountability family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
AU-1 (Audit and Accountability Policy and Procedures) is about writing down, on purpose, how this system handles logging and accountability: what the policy says, who owns it, who receives it, and how often it gets reviewed. It is the foundation the rest of the AU (Audit and Accountability) family is built on, and it sits in the Low baseline.
What good looks like
- Write an audit and accountability policy that states the purpose, scope, roles, and responsibilities — and matches any laws or standards you answer to.
- Write procedures that say how the policy is actually carried out on this server: what gets logged, where logs go, and who reviews them.
- Name an owner — a specific person or role responsible for keeping the policy and procedures current.
- Disseminate both to the people who need them, so no one has to guess how logging is supposed to work.
- Review and update the policy and procedures on a set schedule, and after any event that changes how the system logs.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established, communicated, and enforced
- CIS Controls v8 — Control 8 — Audit Log Management
How to move it toward Implemented
- Draft a one-page audit policy: what this server logs, why, and who is accountable — keep it plain enough to actually follow.
- Write a short companion procedure that names the log locations (
/var/log,journalctl), the reviewer, and the review cadence (for example, monthly). - Put a review date and an owner at the top of both documents, and set a reminder to revisit them at least yearly.
- Attach that policy and procedure as hardening evidence on the asset, naming
AU-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.