PlumbTrackLive demoGRC Risk System

← control library

Content of Audit Records AU-3

Audit and Accountability · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AU-3 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Audit and Accountability family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AU-3 (Content of Audit Records) says each log entry must carry enough detail to be useful: what type of event happened, when (timestamp), where it came from (source), the outcome (success or failure), and the identity of the user or process involved. It is the 'what is inside each record' companion to AU-2's 'what to log.'

What good looks like

Framework mapping

How to move it toward Implemented