AU-9 Protection of Audit Information
Audit and Accountability family. 21 Control Correlation Identifiers map to this control, and 41 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AU-9 |
|---|---|---|
| Red Hat Enterprise Linux 8 | V2 | 12 |
| Red Hat Enterprise Linux 9 | V2 | 11 |
| Microsoft Windows Server 2019 | V3 | 5 |
| Microsoft Windows Server 2022 | V2 | 5 |
| Microsoft Windows 10 | V3 | 4 |
| Microsoft Windows 11 | V2 | 4 |
Control Correlation Identifiers mapped to AU-9
| CCI | Definition | Rev |
|---|---|---|
| CCI-000162 | Protect audit information from unauthorized access. | 5, 4 |
| CCI-000163 | Protect audit information from unauthorized modification. | 5, 4 |
| CCI-000164 | Protect audit information from unauthorized deletion. | 5, 4 |
| CCI-000165 | Write audit records to hardware-enforced, write-once media. | 5, 4 |
| CCI-001348 | Store audit records on an organization-defined frequency in a repository that is part of a physically different system or system component than the system or component being audited. | 5, 4 |
| CCI-001349 | Defines a frequency for storing audit records in a repository that is part of a physically different system or system component than the system or component being audited. | 5, 4 |
| CCI-001350 | Implement cryptographic mechanisms to protect the integrity of audit information. | 5, 4 |
| CCI-001351 | Authorize access to management of audit logging functionality to only an organization-defined subset of privileged users or roles. | 5, 4 |
| CCI-001493 | Protect audit tools from unauthorized access. | 5, 4 |
| CCI-001494 | Protect audit tools from unauthorized modification. | 5, 4 |
| CCI-001495 | Protect audit tools from unauthorized deletion. | 5, 4 |
| CCI-001496 | Implement cryptographic mechanisms to protect the integrity of audit tools. | 5, 4 |
| CCI-001575 | The organization defines the system or system component for storing audit records that is a different system or system component than the system or component being audited. | 4 |
| CCI-001894 | Defines the subset of privileged users who will be authorized access to the management of audit functionality. | 5, 4 |
| CCI-001895 | Defines the audit information requiring dual authorization for movement or deletion actions. | 5, 4 |
| CCI-001896 | Enforce dual authorization for movement and/or deletion of organization-defined audit information. | 5, 4 |
| CCI-001897 | Defines the subset of privileged users or roles who will be authorized read-only access to audit information. | 5, 4 |
| CCI-001898 | Authorize read-only access to audit information to an organization-defined subset of privileged users or roles. | 5, 4 |
| CCI-003831 | Alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information. | 5 |
| CCI-003832 | Defines the personnel or roles to be alerted upon detection of unauthorized access, modification, or deletion of audit information. | 5 |
| CCI-003833 | Store audit information on a component running a different operating system than the system component being audited. | 5 |
STIG rules that implement AU-9
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205640 | WN19-AU-000030 | medium | Windows Server 2019 permissions for the Application event log must prevent access by non-privileged accounts. |
| V-205641 | WN19-AU-000040 | medium | Windows Server 2019 permissions for the Security event log must prevent access by non-privileged accounts. |
| V-205642 | WN19-AU-000050 | medium | Windows Server 2019 permissions for the System event log must prevent access by non-privileged accounts. |
| V-205643 | WN19-UR-000170 | medium | Windows Server 2019 Manage auditing and security log user right must only be assigned to the Administrators group. |
| V-205731 | WN19-AU-000060 | medium | Windows Server 2019 Event Viewer must be protected from unauthorized modification and deletion. |
| V-220782 | WN10-AU-000515 | medium | Windows 10 permissions for the Application event log must prevent access by non-privileged accounts. |
| V-220783 | WN10-AU-000520 | medium | Windows 10 permissions for the Security event log must prevent access by non-privileged accounts. |
| V-220784 | WN10-AU-000525 | medium | Windows 10 permissions for the System event log must prevent access by non-privileged accounts. |
| V-220978 | WN10-UR-000130 | medium | The Manage auditing and security log user right must only be assigned to the Administrators group. |
| V-230396 | RHEL-08-030070 | medium | RHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access. |
| V-230397 | RHEL-08-030080 | medium | RHEL 8 audit logs must be owned by root to prevent unauthorized read access. |
| V-230398 | RHEL-08-030090 | medium | RHEL 8 audit logs must be group-owned by root to prevent unauthorized read access. |
| V-230399 | RHEL-08-030100 | medium | RHEL 8 audit log directory must be owned by root to prevent unauthorized read access. |
| V-230400 | RHEL-08-030110 | medium | RHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access. |
| V-230401 | RHEL-08-030120 | medium | RHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access. |
| V-230402 | RHEL-08-030121 | medium | RHEL 8 audit system must protect auditing rules from unauthorized change. |
| V-230403 | RHEL-08-030122 | medium | RHEL 8 audit system must protect logon UIDs from unauthorized change. |
| V-230472 | RHEL-08-030620 | medium | RHEL 8 audit tools must have a mode of 0755 or less permissive. |
| V-230473 | RHEL-08-030630 | medium | RHEL 8 audit tools must be owned by root. |
| V-230474 | RHEL-08-030640 | medium | RHEL 8 audit tools must be group-owned by root. |
| V-230475 | RHEL-08-030650 | medium | RHEL 8 must use cryptographic mechanisms to protect the integrity of audit tools. |
| V-253340 | WN11-AU-000515 | medium | Windows 11 permissions for the Application event log must prevent access by non-privileged accounts. |
| V-253341 | WN11-AU-000520 | medium | Windows 11 permissions for the Security event log must prevent access by non-privileged accounts. |
| V-253342 | WN11-AU-000525 | medium | Windows 11 permissions for the System event log must prevent access by non-privileged accounts. |
| V-253501 | WN11-UR-000130 | medium | The "Manage auditing and security log" user right must only be assigned to the Administrators group. |
| V-254296 | WN22-AU-000030 | medium | Windows Server 2022 permissions for the Application event log must prevent access by nonprivileged accounts. |
| V-254297 | WN22-AU-000040 | medium | Windows Server 2022 permissions for the Security event log must prevent access by nonprivileged accounts. |
| V-254298 | WN22-AU-000050 | medium | Windows Server 2022 permissions for the System event log must prevent access by nonprivileged accounts. |
| V-254299 | WN22-AU-000060 | medium | Windows Server 2022 Event Viewer must be protected from unauthorized modification and deletion. |
| V-254507 | WN22-UR-000170 | medium | Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group. |
| V-257887 | RHEL-09-232035 | medium | RHEL 9 audit tools must have a mode of 0755 or less permissive. |
| V-257924 | RHEL-09-232220 | medium | RHEL 9 audit tools must be owned by root. |
| V-257925 | RHEL-09-232225 | medium | RHEL 9 audit tools must be group-owned by root. |
| V-258137 | RHEL-09-651025 | medium | RHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools. |
| V-258165 | RHEL-09-653080 | medium | RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access. |
| V-258166 | RHEL-09-653085 | medium | RHEL 9 audit log directory must be owned by root to prevent unauthorized read access. |
| V-258167 | RHEL-09-653090 | medium | RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log. |
| V-258228 | RHEL-09-654270 | medium | RHEL 9 audit system must protect logon UIDs from unauthorized change. |
| V-258229 | RHEL-09-654275 | medium | RHEL 9 audit system must protect auditing rules from unauthorized change. |
| V-270175 | RHEL-09-232103 | medium | RHEL 9 "/etc/audit/" must be owned by root. |
| V-270176 | RHEL-09-232104 | medium | RHEL 9 "/etc/audit/" must be group-owned by root. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-9. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.