Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Audit and Accountability · Enhancement
AU-3(3) · Limit Personally Identifiable Information Elements
View parent controlControl statement and discussion
NIST control statement
Limit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: [Assignment: elements].
Discussion
Limiting personally identifiable information in audit records when such information is not needed for operational purposes helps reduce the level of privacy risk created by a system.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Base control
AU-4 · Audit Log Storage Capacity
Control statement and discussion
NIST control statement
Allocate audit log storage capacity to accommodate [Assignment: audit log retention requirements].
Discussion
Organizations consider the types of audit logging to be performed and the audit log processing requirements when allocating audit log storage capacity. Allocating sufficient audit log storage capacity reduces the likelihood of such capacity being exceeded and resulting in the potential loss or reduction of audit logging capability.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AU-4 — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Enhancement
AU-4(1) · Transfer to Alternate Storage
View parent controlControl statement and discussion
NIST control statement
Transfer audit logs [Assignment: frequency] to a different system, system component, or media other than the system or system component conducting the logging.
Discussion
Audit log transfer, also known as off-loading, is a common process in systems with limited audit log storage capacity and thus supports availability of the audit logs. The initial audit log storage is only used in a transitory fashion until the system can communicate with the secondary or alternate system allocated to audit log storage, at which point the audit logs are transferred. Transferring audit logs to alternate storage is similar to [AU-9(2)](#au-9.2) in that audit logs are transferred to a different entity. However, the purpose of selecting [AU-9(2)](#au-9.2) is to protect the confidentiality and integrity of audit records. Organizations can select either control enhancement to obtain the benefit of increased audit log storage capacity and preserving the confidentiality, integrity, and availability of audit records and logs.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Base control
AU-5 · Response to Audit Logging Process Failures
Control statement and discussion
NIST control statement
a. Alert [Assignment: personnel or roles] within [Assignment: time period] in the event of an audit logging process failure; and
b. Take the following additional actions: [Assignment: additional actions].
Discussion
Audit logging process failures include software and hardware errors, failures in audit log capturing mechanisms, and reaching or exceeding audit log storage capacity. Organization-defined actions include overwriting oldest audit records, shutting down the system, and stopping the generation of audit records. Organizations may choose to define additional actions for audit logging process failures based on the type of failure, the location of the failure, the severity of the failure, or a combination of such factors. When the audit logging process failure is related to storage, the response is carried out for the audit log storage repository (i.e., the distinct system component where the audit logs are stored), the system on which the audit logs reside, the total audit log storage capacity of the organization (i.e., all audit log storage repositories combined), or all three. Organizations may decide to take no additional actions after alerting designated roles or personnel.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AU-5 — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Enhancement
AU-5(1) · Storage Capacity Warning
View parent controlControl statement and discussion
NIST control statement
Provide a warning to [Assignment: personnel, roles, and/or locations] within [Assignment: time period] when allocated audit log storage volume reaches [Assignment: percentage] of repository maximum audit log storage capacity.
Discussion
Organizations may have multiple audit log storage repositories distributed across multiple system components with each repository having different storage volume capacities.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-5(2) · Real-time Alerts
View parent controlControl statement and discussion
NIST control statement
Provide an alert within [Assignment: real-time period] to [Assignment: personnel, roles, and/or locations] when the following audit failure events occur: [Assignment: audit logging failure events requiring real-time alerts].
Discussion
Alerts provide organizations with urgent messages. Real-time alerts provide these messages at information technology speed (i.e., the time from event detection to alert occurs in seconds or less).
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-5(3) · Configurable Traffic Volume Thresholds
View parent controlControl statement and discussion
NIST control statement
Enforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and [Selection (one-or-more): reject; delay] network traffic above those thresholds.
Discussion
Organizations have the capability to reject or delay the processing of network communications traffic if audit logging information about such traffic is determined to exceed the storage capacity of the system audit logging function. The rejection or delay response is triggered by the established organizational traffic volume thresholds that can be adjusted based on changes to audit log storage capacity.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-5(4) · Shutdown on Failure
View parent controlControl statement and discussion
NIST control statement
Invoke a [Selection (one-or-more): full system shutdown; partial system shutdown; degraded operational mode with limited mission or business functionality available] in the event of [Assignment: audit logging failures] , unless an alternate audit logging capability exists.
Discussion
Organizations determine the types of audit logging failures that can trigger automatic system shutdowns or degraded operations. Because of the importance of ensuring mission and business continuity, organizations may determine that the nature of the audit logging failure is not so severe that it warrants a complete shutdown of the system supporting the core organizational mission and business functions. In those instances, partial system shutdowns or operating in a degraded mode with reduced capability may be viable alternatives.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-5(5) · Alternate Audit Logging Capability
View parent controlControl statement and discussion
NIST control statement
Provide an alternate audit logging capability in the event of a failure in primary audit logging capability that implements [Assignment: alternate audit logging functionality].
Discussion
Since an alternate audit logging capability may be a short-term protection solution employed until the failure in the primary audit logging capability is corrected, organizations may determine that the alternate audit logging capability need only provide a subset of the primary audit logging functionality that is impacted by the failure.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Base control
AU-6 · Audit Record Review, Analysis, and Reporting
Control statement and discussion
NIST control statement
a. Review and analyze system audit records [Assignment: frequency] for indications of [Assignment: inappropriate or unusual activity] and the potential impact of the inappropriate or unusual activity;
b. Report findings to [Assignment: personnel or roles] ; and
c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.
Discussion
Audit record review, analysis, and reporting covers information security- and privacy-related logging performed by organizations, including logging that results from the monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and non-local maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at system interfaces, and use of mobile code or Voice over Internet Protocol (VoIP). Findings can be reported to organizational entities that include the incident response team, help desk, and security or privacy offices. If organizations are prohibited from reviewing and analyzing audit records or unable to conduct such activities, the review or analysis may be carried out by other organizations granted such authority. The frequency, scope, and/or depth of the audit record review, analysis, and reporting may be adjusted to meet organizational needs based on new information received.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AU-6 — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Enhancement
AU-6(1) · Automated Process Integration
View parent controlControl statement and discussion
NIST control statement
Integrate audit record review, analysis, and reporting processes using [Assignment: automated mechanisms].
Discussion
Organizational processes that benefit from integrated audit record review, analysis, and reporting include incident response, continuous monitoring, contingency planning, investigation and response to suspicious activities, and Inspector General audits.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AU-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Enhancement
AU-6(3) · Correlate Audit Record Repositories
View parent controlControl statement and discussion
NIST control statement
Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.
Discussion
Organization-wide situational awareness includes awareness across all three levels of risk management (i.e., organizational level, mission/business process level, and information system level) and supports cross-organization awareness.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AU-6 (3) — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Enhancement
AU-6(4) · Central Review and Analysis
View parent controlControl statement and discussion
NIST control statement
Provide and implement the capability to centrally review and analyze audit records from multiple components within the system.
Discussion
Automated mechanisms for centralized reviews and analyses include Security Information and Event Management products.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-6(5) · Integrated Analysis of Audit Records
View parent controlControl statement and discussion
NIST control statement
Integrate analysis of audit records with analysis of [Selection (one-or-more): vulnerability scanning information; performance data; system monitoring information; [Assignment: data/information collected from other sources] ] to further enhance the ability to identify inappropriate or unusual activity.
Discussion
Integrated analysis of audit records does not require vulnerability scanning, the generation of performance data, or system monitoring. Rather, integrated analysis requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security Information and Event Management tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of standardized audit record analysis scripts developed by organizations (with localized script adjustments, as necessary) provides more cost-effective approaches for analyzing audit record information collected. The correlation of audit record information with vulnerability scanning information is important in determining the veracity of vulnerability scans of the system and in correlating attack detection events with scanning results. Correlation with performance data can uncover denial-of-service attacks or other types of attacks that result in the unauthorized use of resources. Correlation with system monitoring information can assist in uncovering attacks and in better relating audit information to operational situations.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-6(6) · Correlation with Physical Monitoring
View parent controlControl statement and discussion
NIST control statement
Correlate information from audit records with information obtained from monitoring physical access to further enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.
Discussion
The correlation of physical audit record information and the audit records from systems may assist organizations in identifying suspicious behavior or supporting evidence of such behavior. For example, the correlation of an individual’s identity for logical access to certain systems with the additional physical security information that the individual was present at the facility when the logical access occurred may be useful in investigations.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-6(7) · Permitted Actions
View parent controlControl statement and discussion
NIST control statement
Specify the permitted actions for each [Selection (one-or-more): system process; role; user] associated with the review, analysis, and reporting of audit record information.
Discussion
Organizations specify permitted actions for system processes, roles, and users associated with the review, analysis, and reporting of audit records through system account management activities. Specifying permitted actions on audit record information is a way to enforce the principle of least privilege. Permitted actions are enforced by the system and include read, write, execute, append, and delete.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-6(8) · Full Text Analysis of Privileged Commands
View parent controlControl statement and discussion
NIST control statement
Perform a full text analysis of logged privileged commands in a physically distinct component or subsystem of the system, or other system that is dedicated to that analysis.
Discussion
Full text analysis of privileged commands requires a distinct environment for the analysis of audit record information related to privileged users without compromising such information on the system where the users have elevated privileges, including the capability to execute privileged commands. Full text analysis refers to analysis that considers the full text of privileged commands (i.e., commands and parameters) as opposed to analysis that considers only the name of the command. Full text analysis includes the use of pattern matching and heuristics.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-6(9) · Correlation with Information from Nontechnical Sources
View parent controlControl statement and discussion
NIST control statement
Correlate information from nontechnical sources with audit record information to enhance organization-wide situational awareness.
Discussion
Nontechnical sources include records that document organizational policy violations related to harassment incidents and the improper use of information assets. Such information can lead to a directed analytical effort to detect potential malicious insider activity. Organizations limit access to information that is available from nontechnical sources due to its sensitive nature. Limited access minimizes the potential for inadvertent release of privacy-related information to individuals who do not have a need to know. The correlation of information from nontechnical sources with audit record information generally occurs only when individuals are suspected of being involved in an incident. Organizations obtain legal advice prior to initiating such actions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Base control
AU-7 · Audit Record Reduction and Report Generation
Control statement and discussion
NIST control statement
Provide and implement an audit record reduction and report generation capability that:
a. Supports on-demand audit record review, analysis, and reporting requirements and after-the-fact investigations of incidents; and
b. Does not alter the original content or time ordering of audit records.
Discussion
Audit record reduction is a process that manipulates collected audit log information and organizes it into a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not always emanate from the same system or from the same organizational entities that conduct audit logging activities. The audit record reduction capability includes modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. The report generation capability provided by the system can generate customizable reports. Time ordering of audit records can be an issue if the granularity of the timestamp in the record is insufficient.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · AU-7 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · AU-7 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · AU-7 — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Enhancement
AU-7(1) · Automatic Processing
View parent controlControl statement and discussion
NIST control statement
Provide and implement the capability to process, sort, and search audit records for events of interest based on the following content: [Assignment: fields within audit records].
Discussion
Events of interest can be identified by the content of audit records, including system resources involved, information objects accessed, identities of individuals, event types, event locations, event dates and times, Internet Protocol addresses involved, or event success or failure. Organizations may define event criteria to any degree of granularity required, such as locations selectable by a general networking location or by specific system component.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · AU-7 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · AU-7 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · AU-7 (1) — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Base control
AU-8 · Time Stamps
Control statement and discussion
NIST control statement
a. Use internal system clocks to generate time stamps for audit records; and
b. Record time stamps for audit records that meet [Assignment: granularity of time measurement] and that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.
Discussion
Time stamps generated by the system include date and time. Time is commonly expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC. Granularity of time measurements refers to the degree of synchronization between system clocks and reference clocks (e.g., clocks synchronizing within hundreds of milliseconds or tens of milliseconds). Organizations may define different time granularities for different system components. Time service can be critical to other security capabilities such as access control and identification and authentication, depending on the nature of the mechanisms used to support those capabilities.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AU-8 — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Base control
AU-9 · Protection of Audit Information
Control statement and discussion
NIST control statement
a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and
b. Alert [Assignment: personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.
Discussion
Audit information includes all information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are those programs and devices used to conduct system audit and logging activities. Protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. Physical protection of audit information is addressed by both media protection controls and physical and environmental protection controls.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AU-9 — Direct NIST identifier reference. GovRAMP source matrix
Audit and Accountability · Enhancement
AU-9(1) · Hardware Write-once Media
View parent controlControl statement and discussion
NIST control statement
Write audit trails to hardware-enforced, write-once media.
Discussion
Writing audit trails to hardware-enforced, write-once media applies to the initial generation of audit trails (i.e., the collection of audit records that represents the information to be used for detection, analysis, and reporting purposes) and to the backup of those audit trails. Writing audit trails to hardware-enforced, write-once media does not apply to the initial generation of audit records prior to being written to an audit trail. Write-once, read-many (WORM) media includes Compact Disc-Recordable (CD-R), Blu-Ray Disc Recordable (BD-R), and Digital Versatile Disc-Recordable (DVD-R). In contrast, the use of switchable write-protection media, such as tape cartridges, Universal Serial Bus (USB) drives, Compact Disc Re-Writeable (CD-RW), and Digital Versatile Disc-Read Write (DVD-RW) results in write-protected but not write-once media.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-9(2) · Store on Separate Physical Systems or Components
View parent controlControl statement and discussion
NIST control statement
Store audit records [Assignment: frequency] in a repository that is part of a physically different system or system component than the system or component being audited.
Discussion
Storing audit records in a repository separate from the audited system or system component helps to ensure that a compromise of the system being audited does not also result in a compromise of the audit records. Storing audit records on separate physical systems or components also preserves the confidentiality and integrity of audit records and facilitates the management of audit records as an organization-wide activity. Storing audit records on separate systems or components applies to initial generation as well as backup or long-term storage of audit records.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Audit and Accountability · Enhancement
AU-9(3) · Cryptographic Protection
View parent controlControl statement and discussion
NIST control statement
Implement cryptographic mechanisms to protect the integrity of audit information and audit tools.
Discussion
Cryptographic mechanisms used for protecting the integrity of audit information include signed hash functions using asymmetric cryptography. This enables the distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.