NIST800-AU-13 AU-13 Monitoring for Information Disclosure
NIST800-AU-13 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
AU-13 Monitoring for Information Disclosure. a. Monitor [Assignment: organization-defined open-source information and/or information sites] [Assignment: organization-defined frequency] for evidence of unauthorized disclosure of organizational information; and b. If an information disclosure is discovered: 1. Notify [Assignment: organization-defined personnel or roles]; and 2. Take the following additional actions: [Assignment: organization-defined additional actions].
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches (closest match)
- SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures (closest match)
- SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications (closest match)
HIPAA Security Rule
- 164.308(a)(1)(ii)(D) Information System Activity Review (Required) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: AU - Audit and Accountability), in our words, not a statement of the standard and not binding on an assessor.
- the audit and accountability policy
- the log-capture configuration and a sample
- the log-review records