AU-3 Content of Audit Records
Audit and Accountability family. 14 Control Correlation Identifiers map to this control, and 76 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AU-3 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 50 |
| Microsoft Windows 11 | V2 | 10 |
| Microsoft Windows 10 | V3 | 9 |
| Microsoft Windows Server 2019 | V3 | 3 |
| Microsoft Windows Server 2022 | V2 | 3 |
| Kubernetes | V2 | 1 |
Control Correlation Identifiers mapped to AU-3
| CCI | Definition | Rev |
|---|---|---|
| CCI-000130 | Ensure that audit records contain information that establishes what type of event occurred. | 5, 4 |
| CCI-000131 | Ensure that audit records containing information that establishes when the event occurred. | 5, 4 |
| CCI-000132 | Ensure that audit records containing information that establishes where the event occurred. | 5, 4 |
| CCI-000133 | Ensure that audit records containing information that establishes the source of the event. | 5, 4 |
| CCI-000134 | Ensure that audit records containing information that establishes the outcome of the event. | 5, 4 |
| CCI-000135 | Generate audit records containing the organization-defined additional information that is to be included in the audit records. | 5, 4 |
| CCI-001487 | Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event. | 5, 4 |
| CCI-001488 | Defines the additional information to be included in the audit records. | 5, 4 |
| CCI-001844 | The information system provides centralized management and configuration of the content to be captured in audit records generated by organization-defined information system components. | 4 |
| CCI-001845 | The information system provides centralized configuration of the content to be captured in audit records generated by organization-defined information system components. | 4 |
| CCI-001846 | The organization defines information system components that will generate the audit records which are to be captured for centralized management of the content. | 4 |
| CCI-001847 | The organization defines information system components that will generate the audit records which are to be captured for centralized configuration of the content. | 4 |
| CCI-003812 | Limit personally identifiable information contained in audit records to organization-defined elements identified in the privacy risk assessment. | 5 |
| CCI-003813 | Defines the elements identified in the privacy risk assessment for limiting personally identifiable information contained in audit records. | 5 |
STIG rules that implement AU-3
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205638 | WN19-CC-000090 | medium | Windows Server 2019 command line data must be included in process creation events. |
| V-205639 | WN19-CC-000460 | medium | Windows Server 2019 PowerShell script block logging must be enabled. |
| V-220786 | WN10-AU-000555 | medium | Windows 10 must be configured to audit Other Policy Change Events Failures. |
| V-220787 | WN10-AU-000560 | medium | Windows 10 must be configured to audit other Logon/Logoff Events Successes. |
| V-220788 | WN10-AU-000565 | medium | Windows 10 must be configured to audit other Logon/Logoff Events Failures. |
| V-220789 | WN10-AU-000570 | medium | Windows 10 must be configured to audit Detailed File Share Failures. |
| V-220790 | WN10-AU-000575 | medium | Windows 10 must be configured to audit MPSSVC Rule-Level Policy Change Successes. |
| V-220791 | WN10-AU-000580 | medium | Windows 10 must be configured to audit MPSSVC Rule-Level Policy Change Failures. |
| V-220809 | WN10-CC-000066 | medium | Command line data must be included in process creation events. |
| V-220860 | WN10-CC-000326 | medium | PowerShell script block logging must be enabled on Windows 10. |
| V-242403 | CNTR-K8-000700 | medium | Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event. |
| V-252896 | WN10-CC-000327 | medium | PowerShell Transcription must be enabled on Windows 10. |
| V-253343 | WN11-AU-000550 | medium | Windows 11 must be configured to audit Other Policy Change Events Successes. |
| V-253344 | WN11-AU-000555 | medium | Windows 11 must be configured to audit Other Policy Change Events Failures. |
| V-253345 | WN11-AU-000560 | medium | Windows 11 must be configured to audit other Logon/Logoff Events Successes. |
| V-253346 | WN11-AU-000565 | medium | Windows 11 must be configured to audit other Logon/Logoff Events Failures. |
| V-253347 | WN11-AU-000570 | medium | Windows 11 must be configured to audit Detailed File Share Failures. |
| V-253348 | WN11-AU-000575 | medium | Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Successes. |
| V-253349 | WN11-AU-000580 | medium | Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Failures. |
| V-253367 | WN11-CC-000066 | medium | Command line data must be included in process creation events. |
| V-253414 | WN11-CC-000326 | medium | PowerShell script block logging must be enabled on Windows 11. |
| V-253415 | WN11-CC-000327 | medium | PowerShell Transcription must be enabled on Windows 11. |
| V-254341 | WN22-CC-000090 | medium | Windows Server 2022 command line data must be included in process creation events. |
| V-254377 | WN22-CC-000460 | medium | Windows Server 2022 PowerShell script block logging must be enabled. |
| V-254384 | WN22-CC-000530 | medium | Windows Server 2022 must have PowerShell Transcription enabled. |
| V-257503 | WN19-CC-000530 | medium | Windows Server 2019 must have PowerShell Transcription enabled. |
| V-257796 | RHEL-09-212055 | low | RHEL 9 must enable auditing of processes that start prior to the audit daemon. |
| V-258045 | RHEL-09-411030 | medium | RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users. |
| V-258151 | RHEL-09-653010 | medium | RHEL 9 audit package must be installed. |
| V-258152 | RHEL-09-653015 | medium | RHEL 9 audit service must be enabled. |
| V-258161 | RHEL-09-653060 | medium | RHEL 9 must label all offloaded audit logs before sending them to the central log server. |
| V-258169 | RHEL-09-653100 | medium | RHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event. |
| V-258177 | RHEL-09-654015 | medium | RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls. |
| V-258178 | RHEL-09-654020 | medium | RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls. |
| V-258179 | RHEL-09-654025 | medium | RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. |
| V-258180 | RHEL-09-654030 | medium | RHEL 9 must audit all uses of umount system calls. |
| V-258181 | RHEL-09-654035 | medium | RHEL 9 must audit all uses of the chacl command. |
| V-258182 | RHEL-09-654040 | medium | RHEL 9 must audit all uses of the setfacl command. |
| V-258183 | RHEL-09-654045 | medium | RHEL 9 must audit all uses of the chcon command. |
| V-258184 | RHEL-09-654050 | medium | RHEL 9 must audit all uses of the semanage command. |
| V-258185 | RHEL-09-654055 | medium | RHEL 9 must audit all uses of the setfiles command. |
| V-258186 | RHEL-09-654060 | medium | RHEL 9 must audit all uses of the setsebool command. |
| V-258187 | RHEL-09-654065 | medium | RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls. |
| V-258188 | RHEL-09-654070 | medium | RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls. |
| V-258189 | RHEL-09-654075 | medium | RHEL 9 must audit all uses of the delete_module system call. |
| V-258190 | RHEL-09-654080 | medium | RHEL 9 must audit all uses of the init_module and finit_module system calls. |
| V-258191 | RHEL-09-654085 | medium | RHEL 9 must audit all uses of the chage command. |
| V-258192 | RHEL-09-654090 | medium | RHEL 9 must audit all uses of the chsh command. |
| V-258193 | RHEL-09-654095 | medium | RHEL 9 must audit all uses of the crontab command. |
| V-258194 | RHEL-09-654100 | medium | RHEL 9 must audit all uses of the gpasswd command. |
| V-258195 | RHEL-09-654105 | medium | RHEL 9 must audit all uses of the kmod command. |
| V-258196 | RHEL-09-654110 | medium | RHEL 9 must audit all uses of the newgrp command. |
| V-258197 | RHEL-09-654115 | medium | RHEL 9 must audit all uses of the pam_timestamp_check command. |
| V-258198 | RHEL-09-654120 | medium | RHEL 9 must audit all uses of the passwd command. |
| V-258199 | RHEL-09-654125 | medium | RHEL 9 must audit all uses of the postdrop command. |
| V-258200 | RHEL-09-654130 | medium | RHEL 9 must audit all uses of the postqueue command. |
| V-258201 | RHEL-09-654135 | medium | RHEL 9 must audit all uses of the ssh-agent command. |
| V-258202 | RHEL-09-654140 | medium | RHEL 9 must audit all uses of the ssh-keysign command. |
| V-258203 | RHEL-09-654145 | medium | RHEL 9 must audit all uses of the su command. |
| V-258204 | RHEL-09-654150 | medium | RHEL 9 must audit all uses of the sudo command. |
| V-258205 | RHEL-09-654155 | medium | RHEL 9 must audit all uses of the sudoedit command. |
| V-258206 | RHEL-09-654160 | medium | RHEL 9 must audit all uses of the unix_chkpwd command. |
| V-258207 | RHEL-09-654165 | medium | RHEL 9 must audit all uses of the unix_update command. |
| V-258208 | RHEL-09-654170 | medium | RHEL 9 must audit all uses of the userhelper command. |
| V-258209 | RHEL-09-654175 | medium | RHEL 9 must audit all uses of the usermod command. |
| V-258210 | RHEL-09-654180 | medium | RHEL 9 must audit all uses of the mount command. |
| V-258215 | RHEL-09-654205 | medium | Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record. |
| V-258216 | RHEL-09-654210 | medium | Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record. |
| V-258217 | RHEL-09-654215 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| V-258218 | RHEL-09-654220 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory. |
| V-258219 | RHEL-09-654225 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| V-258220 | RHEL-09-654230 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| V-258221 | RHEL-09-654235 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd. |
| V-258222 | RHEL-09-654240 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| V-258223 | RHEL-09-654245 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| V-258225 | RHEL-09-654255 | medium | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-3. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.