PlumbTrackLive demoGRC Risk System

← control library

Non-repudiation AU-10

Audit and Accountability · High baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AU-10 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Audit and Accountability family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AU-10 (Non-repudiation) is about proving, beyond honest dispute, that a specific person (or a process acting for them) actually did a specific action — so they cannot credibly deny it later. It is a strong Audit and Accountability control, which is why it lives in the High baseline. On a Linux server it leans on unique identities and tamper-evident logs.

What good looks like

Framework mapping

How to move it toward Implemented