AU-14 Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and
Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activ.
system holds itEvidence a system already holds
- Configuration of the session capture capability and a sample captured session · Cloud console / configuration management
periodic reviewEvidence produced at each review
- The defined circumstances under which session capture or record and view is invoked · Policy repository / GRC workspace
- Legal counsel consultation record, plus the civil liberties or privacy officials engaged · Data governance / DLP tooling
governing documentDocuments that govern the control
- The users or roles able to invoke session audit, and the approval required · Policy repository / GRC workspace
- Retention, access and handling rules for captured session content, given that it may hold personal data · Policy repository / GRC workspace
First move
Common gaps auditors find
- Capability deployed broadly and always on, exceeding the defined circumstances
- Legal and privacy consultation absent, which the control requires explicitly and an assessor checks for
- Captured sessions retained indefinitely with the same access as ordinary logs
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAU-13 Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [organization-defined] ; and Take the following additional actions: [organization-defined] · AU-16 Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries