NIST 800-53 Rev 5

424 controls available

AU-6(5)high

Integrated Analysis of Audit Records

Audit and Accountability

Control Statement

Integrate analysis of audit records with analysis of {{ insert: param, au-06.05_odp.01 }} to further enhance the ability to identify inappropriate or unusual activity.

Discussion

Integrated analysis of audit records does not require vulnerability scanning, the generation of performance data, or system monitoring. Rather, integrated analysis requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security Information and Event Management tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of standardized audit record analysis scripts developed by organizations (with localized script adjustments, as necessary) provides more cost-effective approaches for analyzing audit record information collected. The correlation of audit record information with vulnerability scanning information is important in determining the veracity of vulnerability scans of the system and in correlating attack detection events with scanning results. Correlation with performance data can uncover denial-of-service attacks or other types of attacks that result in the unauthorized use of resources. Correlation with system monitoring information can assist in uncovering attacks and in better relating audit information to operational situations.

Framework
NIST SP 800-53 Rev 5
Family
Audit and Accountability
Baselines
high

Related Frameworks

4 paths across 2 frameworks
SCF1 mapping
MON-02.3Integration of Scanning & Other Monitoring Information
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI3 mappings
CCI-001284
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001866
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001867
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

87 STIGs reach this control through 24 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System - Desktop

4 STIGs

Operating System - Server

12 STIGs
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-193 of 103 findings match
Show 4 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-171 of 448 findings match

Operating System - Mainframe

2 STIGs
Mainframe Product Security Requirements Guide
32024-12-052 of 193 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-102 of 194 findings match

Operating System - Mobile

18 STIGs
Show 10 more STIGs in this category →

Network Device

5 STIGs

Database

3 STIGs
Database Security Requirements Guide
42024-12-041 of 142 findings match
Database Security Requirements Guide
V4R52026-02-261 of 142 findings match

Web / Application Server

10 STIGs

Virtualization / Container

6 STIGs

Endpoint Security Management

8 STIGs

Uncategorized

19 STIGs
Mainframe Product Security Requirements Guide
V3R52026-05-232 of 194 findings match
Show 11 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R62026-05-141 of 448 findings match
Virtual Machine Manager Security Requirements Guide
V2R42026-06-291 of 198 findings match
Web Server Security Requirements Guide
V4R52026-05-231 of 126 findings match