AU-16 Cross-Organizational Audit Logging

Audit and Accountability

Description

Employ [Assignment: organization-defined methods] for coordinating [Assignment: organization-defined audit information] among external organizations when audit information is transmitted across organizational boundaries.

Supplemental Guidance

When organizations use systems and/or services of external organizations, the auditing capability necessitates a coordinated, cross-organization approach. Organizations coordinate with external organizations to develop methods for cross-organizational audit logging, including the events to be audited, the event-related data, and approaches for sharing audit information.

Changes from Rev 4

No significant changes from Rev 4.

Compliance Mappings

ISO 27001:2022

7.5

CIS Controls v8

CIS 8.12

FINOS CCC

CCC-C17

RBI CSF

Annex1.16

LGPD + BCB 4893

BCB.Art.15

HKMA TM-E-1

TME1.12.3

CBB TM

TM-12

Qatar NIA

OS

BoG CISD

CISD-COMP

BOT Cyber Resilience

Ch6.1

CMMC 2.0

AU

ISAE 3402

Clause 6

FCA SYSC 13

SYSC 13.9.3