NIST 800-53 Rev 5

424 controls available

AU-9(2)high

Store on Separate Physical Systems or Components

Audit and Accountability

Control Statement

Store audit records {{ insert: param, au-09.02_odp }} in a repository that is part of a physically different system or system component than the system or component being audited.

Discussion

Storing audit records in a repository separate from the audited system or system component helps to ensure that a compromise of the system being audited does not also result in a compromise of the audit records. Storing audit records on separate physical systems or components also preserves the confidentiality and integrity of audit records and facilitates the management of audit records as an organization-wide activity. Storing audit records on separate systems or components applies to initial generation as well as backup or long-term storage of audit records.

Framework
NIST SP 800-53 Rev 5
Family
Audit and Accountability
Baselines
high

Related Frameworks

3 paths across 1 framework
CCI3 mappings
CCI-001348
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001349
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001575
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

214 STIGs reach this control through 21 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

42 STIGs
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-1312 of 375 findings match
Show 34 more STIGs in this category →
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-1910 of 103 findings match
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-178 of 448 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-067 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-167 of 283 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-197 of 216 findings match

Operating System — Mainframe

10 STIGs
Mainframe Product Security Requirements Guide
V3R42025-09-108 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-058 of 193 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-091 of 225 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-091 of 222 findings match
Show 2 more STIGs in this category →
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-091 of 230 findings match

Network Device

48 STIGs
Riverbed NetIM OS Security Technical Implementation Guide
V1R12025-10-0210 of 154 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-156 of 160 findings match
Network Device Management Security Requirements Guide
V5R32025-02-116 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-106 of 105 findings match
BIND 9.x Security Technical Implementation Guide
V3R22026-02-254 of 73 findings match
BIND 9.x Security Technical Implementation Guide
22024-02-154 of 70 findings match
Show 40 more STIGs in this category →
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-192 of 119 findings match
Firewall Security Requirements Guide
V3R32025-09-222 of 35 findings match
Firewall Security Requirements Guide
32024-12-042 of 34 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-111 of 26 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-071 of 32 findings match
SEL-2740S NDM Security Technical Implementation Guide
V1R12019-05-061 of 13 findings match

Database

25 STIGs
Database Security Requirements Guide
V4R52026-02-267 of 142 findings match
Database Security Requirements Guide
42024-12-047 of 142 findings match
Show 17 more STIGs in this category →

Web / Application Server

27 STIGs
Application Server Security Requirements Guide
V4R42025-09-1010 of 137 findings match
Application Server Security Requirements Guide
42025-02-1110 of 128 findings match
Show 19 more STIGs in this category →
Web Server Security Requirements Guide
V4R42025-09-105 of 126 findings match
Web Server Security Requirements Guide
42025-02-125 of 124 findings match

Virtualization / Container

34 STIGs
Container Platform Security Requirements Guide
V2R42025-09-109 of 188 findings match
Container Platform Security Requirements Guide
22025-05-159 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-067 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-107 of 198 findings match
Show 26 more STIGs in this category →

Cloud / Identity Service

1 STIG

Endpoint Security Management

17 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-128 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-048 of 125 findings match
Show 9 more STIGs in this category →
HYCU Protege Security Technical Implementation Guide
V1R22026-03-042 of 55 findings match
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-142 of 98 findings match
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-201 of 34 findings match

Productivity Application

3 STIGs