San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AU-3 Content of Audit Records

Audit and Accountability family. 14 Control Correlation Identifiers map to this control, and 76 STIG rules implement those CCIs.

0CAT I (high)
75CAT II (medium)
1CAT III (low)
14CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AU-3
Red Hat Enterprise Linux 9V250
Microsoft Windows 11V210
Microsoft Windows 10V39
Microsoft Windows Server 2019V33
Microsoft Windows Server 2022V23
KubernetesV21

Control Correlation Identifiers mapped to AU-3

CCIDefinitionRev
CCI-000130Ensure that audit records contain information that establishes what type of event occurred.5, 4
CCI-000131Ensure that audit records containing information that establishes when the event occurred.5, 4
CCI-000132Ensure that audit records containing information that establishes where the event occurred.5, 4
CCI-000133Ensure that audit records containing information that establishes the source of the event.5, 4
CCI-000134Ensure that audit records containing information that establishes the outcome of the event.5, 4
CCI-000135Generate audit records containing the organization-defined additional information that is to be included in the audit records.5, 4
CCI-001487Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.5, 4
CCI-001488Defines the additional information to be included in the audit records.5, 4
CCI-001844The information system provides centralized management and configuration of the content to be captured in audit records generated by organization-defined information system components.4
CCI-001845The information system provides centralized configuration of the content to be captured in audit records generated by organization-defined information system components.4
CCI-001846The organization defines information system components that will generate the audit records which are to be captured for centralized management of the content.4
CCI-001847The organization defines information system components that will generate the audit records which are to be captured for centralized configuration of the content.4
CCI-003812Limit personally identifiable information contained in audit records to organization-defined elements identified in the privacy risk assessment.5
CCI-003813Defines the elements identified in the privacy risk assessment for limiting personally identifiable information contained in audit records.5

STIG rules that implement AU-3

RuleSTIG IDSeverityRequirement
V-205638WN19-CC-000090mediumWindows Server 2019 command line data must be included in process creation events.
V-205639WN19-CC-000460mediumWindows Server 2019 PowerShell script block logging must be enabled.
V-220786WN10-AU-000555mediumWindows 10 must be configured to audit Other Policy Change Events Failures.
V-220787WN10-AU-000560mediumWindows 10 must be configured to audit other Logon/Logoff Events Successes.
V-220788WN10-AU-000565mediumWindows 10 must be configured to audit other Logon/Logoff Events Failures.
V-220789WN10-AU-000570mediumWindows 10 must be configured to audit Detailed File Share Failures.
V-220790WN10-AU-000575mediumWindows 10 must be configured to audit MPSSVC Rule-Level Policy Change Successes.
V-220791WN10-AU-000580mediumWindows 10 must be configured to audit MPSSVC Rule-Level Policy Change Failures.
V-220809WN10-CC-000066mediumCommand line data must be included in process creation events.
V-220860WN10-CC-000326mediumPowerShell script block logging must be enabled on Windows 10.
V-242403CNTR-K8-000700mediumKubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.
V-252896WN10-CC-000327mediumPowerShell Transcription must be enabled on Windows 10.
V-253343WN11-AU-000550mediumWindows 11 must be configured to audit Other Policy Change Events Successes.
V-253344WN11-AU-000555mediumWindows 11 must be configured to audit Other Policy Change Events Failures.
V-253345WN11-AU-000560mediumWindows 11 must be configured to audit other Logon/Logoff Events Successes.
V-253346WN11-AU-000565mediumWindows 11 must be configured to audit other Logon/Logoff Events Failures.
V-253347WN11-AU-000570mediumWindows 11 must be configured to audit Detailed File Share Failures.
V-253348WN11-AU-000575mediumWindows 11 must be configured to audit MPSSVC Rule-Level Policy Change Successes.
V-253349WN11-AU-000580mediumWindows 11 must be configured to audit MPSSVC Rule-Level Policy Change Failures.
V-253367WN11-CC-000066mediumCommand line data must be included in process creation events.
V-253414WN11-CC-000326mediumPowerShell script block logging must be enabled on Windows 11.
V-253415WN11-CC-000327mediumPowerShell Transcription must be enabled on Windows 11.
V-254341WN22-CC-000090mediumWindows Server 2022 command line data must be included in process creation events.
V-254377WN22-CC-000460mediumWindows Server 2022 PowerShell script block logging must be enabled.
V-254384WN22-CC-000530mediumWindows Server 2022 must have PowerShell Transcription enabled.
V-257503WN19-CC-000530mediumWindows Server 2019 must have PowerShell Transcription enabled.
V-257796RHEL-09-212055lowRHEL 9 must enable auditing of processes that start prior to the audit daemon.
V-258045RHEL-09-411030mediumRHEL 9 duplicate User IDs (UIDs) must not exist for interactive users.
V-258151RHEL-09-653010mediumRHEL 9 audit package must be installed.
V-258152RHEL-09-653015mediumRHEL 9 audit service must be enabled.
V-258161RHEL-09-653060mediumRHEL 9 must label all offloaded audit logs before sending them to the central log server.
V-258169RHEL-09-653100mediumRHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.
V-258177RHEL-09-654015mediumRHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.
V-258178RHEL-09-654020mediumRHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.
V-258179RHEL-09-654025mediumRHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
V-258180RHEL-09-654030mediumRHEL 9 must audit all uses of umount system calls.
V-258181RHEL-09-654035mediumRHEL 9 must audit all uses of the chacl command.
V-258182RHEL-09-654040mediumRHEL 9 must audit all uses of the setfacl command.
V-258183RHEL-09-654045mediumRHEL 9 must audit all uses of the chcon command.
V-258184RHEL-09-654050mediumRHEL 9 must audit all uses of the semanage command.
V-258185RHEL-09-654055mediumRHEL 9 must audit all uses of the setfiles command.
V-258186RHEL-09-654060mediumRHEL 9 must audit all uses of the setsebool command.
V-258187RHEL-09-654065mediumRHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.
V-258188RHEL-09-654070mediumRHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
V-258189RHEL-09-654075mediumRHEL 9 must audit all uses of the delete_module system call.
V-258190RHEL-09-654080mediumRHEL 9 must audit all uses of the init_module and finit_module system calls.
V-258191RHEL-09-654085mediumRHEL 9 must audit all uses of the chage command.
V-258192RHEL-09-654090mediumRHEL 9 must audit all uses of the chsh command.
V-258193RHEL-09-654095mediumRHEL 9 must audit all uses of the crontab command.
V-258194RHEL-09-654100mediumRHEL 9 must audit all uses of the gpasswd command.
V-258195RHEL-09-654105mediumRHEL 9 must audit all uses of the kmod command.
V-258196RHEL-09-654110mediumRHEL 9 must audit all uses of the newgrp command.
V-258197RHEL-09-654115mediumRHEL 9 must audit all uses of the pam_timestamp_check command.
V-258198RHEL-09-654120mediumRHEL 9 must audit all uses of the passwd command.
V-258199RHEL-09-654125mediumRHEL 9 must audit all uses of the postdrop command.
V-258200RHEL-09-654130mediumRHEL 9 must audit all uses of the postqueue command.
V-258201RHEL-09-654135mediumRHEL 9 must audit all uses of the ssh-agent command.
V-258202RHEL-09-654140mediumRHEL 9 must audit all uses of the ssh-keysign command.
V-258203RHEL-09-654145mediumRHEL 9 must audit all uses of the su command.
V-258204RHEL-09-654150mediumRHEL 9 must audit all uses of the sudo command.
V-258205RHEL-09-654155mediumRHEL 9 must audit all uses of the sudoedit command.
V-258206RHEL-09-654160mediumRHEL 9 must audit all uses of the unix_chkpwd command.
V-258207RHEL-09-654165mediumRHEL 9 must audit all uses of the unix_update command.
V-258208RHEL-09-654170mediumRHEL 9 must audit all uses of the userhelper command.
V-258209RHEL-09-654175mediumRHEL 9 must audit all uses of the usermod command.
V-258210RHEL-09-654180mediumRHEL 9 must audit all uses of the mount command.
V-258215RHEL-09-654205mediumSuccessful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.
V-258216RHEL-09-654210mediumSuccessful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.
V-258217RHEL-09-654215mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
V-258218RHEL-09-654220mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.
V-258219RHEL-09-654225mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
V-258220RHEL-09-654230mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
V-258221RHEL-09-654235mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
V-258222RHEL-09-654240mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
V-258223RHEL-09-654245mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
V-258225RHEL-09-654255mediumRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-3. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.