Skip to content

AU-2: Event Logging

An OSCAL Control

Statement

    • a.

      Identify the types of events that the system is capable of logging in support of the audit function: ;

    • b.

      Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged;

    • c.

      Specify the following event types for logging within the system: ;

    • d.

      Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and

    • e.

      Review and update the event types selected for logging .

      • Requirement:

        Coordination between service provider and consumer shall be documented and accepted by the JAB/AO.

      • (e) Guidance:

        Annually or whenever changes in the threat environment are communicated to the service provider by the JAB/AO.