AU-4 Audit Log Storage Capacity
Audit and Accountability family. 4 Control Correlation Identifiers map to this control, and 34 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AU-4 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 11 |
| Red Hat Enterprise Linux 8 | V2 | 7 |
| Microsoft Windows Server 2019 | V3 | 5 |
| Microsoft Windows Server 2022 | V2 | 5 |
| Microsoft Windows 10 | V3 | 3 |
| Microsoft Windows 11 | V2 | 3 |
Control Correlation Identifiers mapped to AU-4
| CCI | Definition | Rev |
|---|---|---|
| CCI-001848 | Defines the audit log retention requirements for allocating audit log storage capacity. | 5, 4 |
| CCI-001849 | Allocate audit log storage capacity to accommodate organization-defined audit log retention requirements. | 5, 4 |
| CCI-001850 | Defines the frequency to off-load audit records onto a different system or media than the system being audited. | 5, 4 |
| CCI-001851 | Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging. | 5, 4 |
STIG rules that implement AU-4
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205796 | WN19-CC-000270 | medium | Windows Server 2019 Application event log size must be configured to 32768 KB or greater. |
| V-205797 | WN19-CC-000280 | medium | Windows Server 2019 Security event log size must be configured to 196608 KB or greater. |
| V-205798 | WN19-CC-000290 | medium | Windows Server 2019 System event log size must be configured to 32768 KB or greater. |
| V-205799 | WN19-AU-000010 | medium | Windows Server 2019 audit records must be backed up to a different system or media than the system being audited. |
| V-205843 | WN19-AU-000020 | medium | Windows Server 2019 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly. |
| V-220779 | WN10-AU-000500 | medium | The Application event log size must be configured to 32768 KB or greater. |
| V-220780 | WN10-AU-000505 | medium | The Security event log size must be configured to 1024000 KB or greater. |
| V-220781 | WN10-AU-000510 | medium | The System event log size must be configured to 32768 KB or greater. |
| V-230394 | RHEL-08-030062 | medium | RHEL 8 must label all off-loaded audit logs before sending them to the central log server. |
| V-230469 | RHEL-08-030602 | low | RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. |
| V-230476 | RHEL-08-030660 | medium | RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility. |
| V-230479 | RHEL-08-030690 | medium | The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited. |
| V-230480 | RHEL-08-030700 | medium | RHEL 8 must take appropriate action when the internal event queue is full. |
| V-230481 | RHEL-08-030710 | medium | RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited. |
| V-230482 | RHEL-08-030720 | medium | RHEL 8 must authenticate the remote logging server for off-loading audit logs. |
| V-253337 | WN11-AU-000500 | medium | The Application event log size must be configured to 32768 KB or greater. |
| V-253338 | WN11-AU-000505 | medium | The Security event log size must be configured to 1024000 KB or greater. |
| V-253339 | WN11-AU-000510 | medium | The System event log size must be configured to 32768 KB or greater. |
| V-254294 | WN22-AU-000010 | medium | Windows Server 2022 audit records must be backed up to a different system or media than the system being audited. |
| V-254295 | WN22-AU-000020 | medium | Windows Server 2022 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly. |
| V-254358 | WN22-CC-000270 | medium | Windows Server 2022 Application event log size must be configured to 32768 KB or greater. |
| V-254359 | WN22-CC-000280 | medium | Windows Server 2022 Security event log size must be configured to 196608 KB or greater. |
| V-254360 | WN22-CC-000290 | medium | Windows Server 2022 System event log size must be configured to 32768 KB or greater. |
| V-257847 | RHEL-09-231030 | low | RHEL 9 must use a separate file system for the system audit data path. |
| V-258140 | RHEL-09-652010 | medium | RHEL 9 must have the rsyslog package installed. |
| V-258146 | RHEL-09-652040 | medium | RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog. |
| V-258147 | RHEL-09-652045 | medium | RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. |
| V-258148 | RHEL-09-652050 | medium | RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. |
| V-258149 | RHEL-09-652055 | medium | RHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog. |
| V-258155 | RHEL-09-653030 | medium | RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records. |
| V-258161 | RHEL-09-653060 | medium | RHEL 9 must label all offloaded audit logs before sending them to the central log server. |
| V-258162 | RHEL-09-653065 | medium | RHEL 9 must take appropriate action when the internal event queue is full. |
| V-258173 | RHEL-09-653120 | low | RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. |
| V-258175 | RHEL-09-653130 | medium | RHEL 9 audispd-plugins package must be installed. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-4. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.