AU-2 Event logging
Requires identification of the events the system can log, coordination with the parties who need audit information, selection of the specific event types to be logged with the frequency or situation for each, a documente
5
artefacts
2
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Approved list of selected event types with logging frequency or trigger · SIEM / log platform
- Written rationale linking the selection to investigation and monitoring needs · SIEM / log platform
periodic reviewEvidence produced at each review
- Minutes or correspondence evidencing coordination with incident response and other consumers · Policy repository / GRC workspace
- Review record showing the selection was revisited on the defined frequency · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Catalogue of loggable event types for the system · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Event selection copied from a vendor default with no rationale recorded
- Selection never reviewed after new components or new threats appeared
- Consumers of the logs were never consulted, so the events captured do not support their work
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAU-1 Policy and procedures for audit and accountability · AU-3 Content of audit records