Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: AU-FAMILY: AUDIT AND ACCOUNTABILITY

AU-6(6) AUDIT REVIEW, ANALYSIS, AND REPORTING  |  CORRELATION WITH PHYSICAL MONITORING

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

au-6(6)

audit review, analysis, and reporting | correlation with physical monitoring

 

assessment objective:

Determine if the organization correlates information from audit records with information obtained from monitoring physical access to enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.

potential assessment methods and objects:

Examine: [select from: Audit and accountability policy; procedures addressing audit review, analysis, and reporting; procedures addressing physical access monitoring; information system design documentation; information system configuration settings and associated documentation; documentation providing evidence of correlated information obtained from audit records and physical access monitoring records; security plan; other relevant documents or records].

Interview: [select from: Organizational personnel with audit review, analysis, and reporting responsibilities; organizational personnel with physical access monitoring responsibilities; organizational personnel with information security responsibilities].

Test: [select from: Automated mechanisms implementing capability to correlate information from audit records with information from monitoring physical access].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056