AU-16 Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries
Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Evidence that audit information transmitted externally preserves the identity of the originating subject · Policy repository / GRC workspace
- Records of audit information actually exchanged during the period · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Agreements with each external organisation covering audit information exchanged across the boundary · Vendor register / contract repository
- The defined methods for coordinating audit information, such as agreed formats, identifiers and time base · Policy repository / GRC workspace
- Points of contact on both sides for audit coordination and dispute · Policy repository / GRC workspace
First move
Common gaps auditors find
- Logs shared with a provider under contract while no method exists to correlate their records with yours
- Timestamps in different zones or unsynchronised clocks, so cross boundary sequences cannot be reconstructed
- Subject identity anonymised in transit for privacy reasons with no agreed way to re-attribute during an investigation
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAU-14 Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and · CA-1 Policy and procedures for assessment, authorization, and monitoring