San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AU-9 Protection of Audit Information

Audit and Accountability family. 21 Control Correlation Identifiers map to this control, and 41 STIG rules implement those CCIs.

0CAT I (high)
41CAT II (medium)
0CAT III (low)
21CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AU-9
Red Hat Enterprise Linux 8V212
Red Hat Enterprise Linux 9V211
Microsoft Windows Server 2019V35
Microsoft Windows Server 2022V25
Microsoft Windows 10V34
Microsoft Windows 11V24

Control Correlation Identifiers mapped to AU-9

CCIDefinitionRev
CCI-000162Protect audit information from unauthorized access.5, 4
CCI-000163Protect audit information from unauthorized modification.5, 4
CCI-000164Protect audit information from unauthorized deletion.5, 4
CCI-000165Write audit records to hardware-enforced, write-once media.5, 4
CCI-001348Store audit records on an organization-defined frequency in a repository that is part of a physically different system or system component than the system or component being audited.5, 4
CCI-001349Defines a frequency for storing audit records in a repository that is part of a physically different system or system component than the system or component being audited.5, 4
CCI-001350Implement cryptographic mechanisms to protect the integrity of audit information.5, 4
CCI-001351Authorize access to management of audit logging functionality to only an organization-defined subset of privileged users or roles.5, 4
CCI-001493Protect audit tools from unauthorized access.5, 4
CCI-001494Protect audit tools from unauthorized modification.5, 4
CCI-001495Protect audit tools from unauthorized deletion.5, 4
CCI-001496Implement cryptographic mechanisms to protect the integrity of audit tools.5, 4
CCI-001575The organization defines the system or system component for storing audit records that is a different system or system component than the system or component being audited.4
CCI-001894Defines the subset of privileged users who will be authorized access to the management of audit functionality.5, 4
CCI-001895Defines the audit information requiring dual authorization for movement or deletion actions.5, 4
CCI-001896Enforce dual authorization for movement and/or deletion of organization-defined audit information.5, 4
CCI-001897Defines the subset of privileged users or roles who will be authorized read-only access to audit information.5, 4
CCI-001898Authorize read-only access to audit information to an organization-defined subset of privileged users or roles.5, 4
CCI-003831Alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.5
CCI-003832Defines the personnel or roles to be alerted upon detection of unauthorized access, modification, or deletion of audit information.5
CCI-003833Store audit information on a component running a different operating system than the system component being audited.5

STIG rules that implement AU-9

RuleSTIG IDSeverityRequirement
V-205640WN19-AU-000030mediumWindows Server 2019 permissions for the Application event log must prevent access by non-privileged accounts.
V-205641WN19-AU-000040mediumWindows Server 2019 permissions for the Security event log must prevent access by non-privileged accounts.
V-205642WN19-AU-000050mediumWindows Server 2019 permissions for the System event log must prevent access by non-privileged accounts.
V-205643WN19-UR-000170mediumWindows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group.
V-205731WN19-AU-000060mediumWindows Server 2019 Event Viewer must be protected from unauthorized modification and deletion.
V-220782WN10-AU-000515mediumWindows 10 permissions for the Application event log must prevent access by non-privileged accounts.
V-220783WN10-AU-000520mediumWindows 10 permissions for the Security event log must prevent access by non-privileged accounts.
V-220784WN10-AU-000525mediumWindows 10 permissions for the System event log must prevent access by non-privileged accounts.
V-220978WN10-UR-000130mediumThe Manage auditing and security log user right must only be assigned to the Administrators group.
V-230396RHEL-08-030070mediumRHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access.
V-230397RHEL-08-030080mediumRHEL 8 audit logs must be owned by root to prevent unauthorized read access.
V-230398RHEL-08-030090mediumRHEL 8 audit logs must be group-owned by root to prevent unauthorized read access.
V-230399RHEL-08-030100mediumRHEL 8 audit log directory must be owned by root to prevent unauthorized read access.
V-230400RHEL-08-030110mediumRHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access.
V-230401RHEL-08-030120mediumRHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
V-230402RHEL-08-030121mediumRHEL 8 audit system must protect auditing rules from unauthorized change.
V-230403RHEL-08-030122mediumRHEL 8 audit system must protect logon UIDs from unauthorized change.
V-230472RHEL-08-030620mediumRHEL 8 audit tools must have a mode of 0755 or less permissive.
V-230473RHEL-08-030630mediumRHEL 8 audit tools must be owned by root.
V-230474RHEL-08-030640mediumRHEL 8 audit tools must be group-owned by root.
V-230475RHEL-08-030650mediumRHEL 8 must use cryptographic mechanisms to protect the integrity of audit tools.
V-253340WN11-AU-000515mediumWindows 11 permissions for the Application event log must prevent access by non-privileged accounts.
V-253341WN11-AU-000520mediumWindows 11 permissions for the Security event log must prevent access by non-privileged accounts.
V-253342WN11-AU-000525mediumWindows 11 permissions for the System event log must prevent access by non-privileged accounts.
V-253501WN11-UR-000130mediumThe "Manage auditing and security log" user right must only be assigned to the Administrators group.
V-254296WN22-AU-000030mediumWindows Server 2022 permissions for the Application event log must prevent access by nonprivileged accounts.
V-254297WN22-AU-000040mediumWindows Server 2022 permissions for the Security event log must prevent access by nonprivileged accounts.
V-254298WN22-AU-000050mediumWindows Server 2022 permissions for the System event log must prevent access by nonprivileged accounts.
V-254299WN22-AU-000060mediumWindows Server 2022 Event Viewer must be protected from unauthorized modification and deletion.
V-254507WN22-UR-000170mediumWindows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group.
V-257887RHEL-09-232035mediumRHEL 9 audit tools must have a mode of 0755 or less permissive.
V-257924RHEL-09-232220mediumRHEL 9 audit tools must be owned by root.
V-257925RHEL-09-232225mediumRHEL 9 audit tools must be group-owned by root.
V-258137RHEL-09-651025mediumRHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools.
V-258165RHEL-09-653080mediumRHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
V-258166RHEL-09-653085mediumRHEL 9 audit log directory must be owned by root to prevent unauthorized read access.
V-258167RHEL-09-653090mediumRHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
V-258228RHEL-09-654270mediumRHEL 9 audit system must protect logon UIDs from unauthorized change.
V-258229RHEL-09-654275mediumRHEL 9 audit system must protect auditing rules from unauthorized change.
V-270175RHEL-09-232103mediumRHEL 9 "/etc/audit/" must be owned by root.
V-270176RHEL-09-232104mediumRHEL 9 "/etc/audit/" must be group-owned by root.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-9. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.