NIST 800-53 r5 · Controls catalogue · Family AU
AU-12Audit Record Generation
Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on {{ insert: param, au-12_odp.01 }}; Allow {{ insert: param, au-12_odp.02 }} to select the event types that are to be logged by specific components of the system; and Generate audit records for the event types defined in [AU-2c](#au-2_smt.c) that include the audit record content defined in [AU-3](#au-3).
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)
Implementations targeting this control (16)
- aws-config-cloudtrail-enabled CloudTrail is enabled in the account AWS::CloudTrail::Trail partial detect enforce
- aws-config-vpc-flow-logs-enabled VPC flow logs are enabled AWS::EC2::VPC partial detect enforce CIS §3.7Hub EC2.6
- azure-mcsb-lt-04-resource-logs Resource logs are streamed to Log Analytics or storage Microsoft.Insights/diagnosticSettings partial protect enforce
- gcp-cis-vpc-flow-logs-enabled VPC subnetworks have flow logs enabled compute.googleapis.com/Subnetwork partial protect enforce
- gcp-cis-cloud-audit-logs-enabled Cloud Audit Logs cover all admin/data services cloudresourcemanager.googleapis.com/Project encompass protect enforce
- aws-config-api-gw-execution-logging-enabled Api Gw Execution Logging Enabled AWS::ApiGateway::Stage partial detect enforce
- aws-config-cloud-trail-cloud-watch-logs-enabled Cloud Trail Cloud Watch Logs Enabled AWS::CloudTrail::Trail partial detect enforce
- aws-config-cloudtrail-s3-dataevents-enabled Cloudtrail S3 Dataevents Enabled AWS::CloudTrail::Trail partial detect enforce
- aws-config-elasticsearch-logs-to-cloudwatch Elasticsearch Logs To Cloudwatch AWS::OpenSearchService::Domain partial detect enforce
- aws-config-elb-logging-enabled Elb Logging Enabled AWS::ElasticLoadBalancing::LoadBalancer partial detect enforce
- aws-config-multi-region-cloudtrail-enabled Multi Region Cloudtrail Enabled AWS::CloudTrail::Trail partial detect enforce CIS §3.1Hub CloudTrail.1
- aws-config-opensearch-logs-to-cloudwatch Opensearch Logs To Cloudwatch AWS::OpenSearchService::Domain partial detect enforce
- aws-config-rds-logging-enabled Rds Logging Enabled AWS::RDS::DBInstance partial detect enforce
- aws-config-redshift-cluster-configuration-check Redshift Cluster Configuration Check AWS::Redshift::Cluster partial protect enforce
- aws-config-s3-bucket-logging-enabled S3 Bucket Logging Enabled AWS::S3::Bucket partial detect enforce CIS §3.4Hub CloudTrail.7
- aws-config-wafv2-logging-enabled Wafv2 Logging Enabled AWS::WAFv2::WebACL partial detect enforce
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (1)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-778 | Insufficient Logging | 28 | Directly requires generation of audit records for specified events, preventing the absence of logging that allows undetected malicious activity. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-48967 UPD | 7.5 | 10.0 | 0.0063 | good |
CVE-2026-76208 | 6.1 | 8.2 | 0.0025 | good |
CVE-2025-2562 UPD | 4.4 | 5.4 | 0.0041 | good |
CVE-2026-25598 UPD | 4.4 | 5.3 | 0.0031 | good |
CVE-2025-32967 UPD | 4.3 | 5.4 | 0.0026 | good |
CVE-2025-53498 UPD | 4.3 | 5.3 | 0.0025 | good |
CVE-2025-52644 | 4.3 | 5.8 | 0.0014 | good |
CVE-2025-62307 | 4.2 | 5.4 | 0.0018 | good |
CVE-2024-2291 UPD | 3.7 | 4.3 | 0.0039 | good |
CVE-2024-52813 UPD | 3.7 | 4.3 | 0.0048 | good |
CVE-2025-66552 | 3.6 | 4.3 | 0.0030 | good |
CVE-2026-22279 | 3.6 | 4.3 | 0.0024 | good |
CVE-2026-3494 UPD | 3.6 | 4.3 | 0.0027 | good |
CVE-2024-10863 UPD | 3.5 | 5.1 | 0.0044 | good |
CVE-2025-35987 | 3.5 | 4.3 | 0.0010 | good |
CVE-2026-32803 UPD | 2.7 | 3.3 | 0.0009 | good |
CVE-2026-41709 | 2.6 | 2.7 | 0.0038 | good |
CVE-2024-24901 UPD | 2.5 | 3.0 | 0.0014 | good |
CVE-2025-52926 UPD | 2.2 | 2.7 | 0.0014 | good |
CVE-2026-9247 UPD | 2.2 | 2.4 | 0.0022 | good |
CVE-2026-49426 | 0.0 | 0.0 | 0.0015 | good |
CVE-2026-32693 | 6.5 | 8.8 | 0.0030 | good |
CVE-2026-31890 UPD | 4.1 | 5.5 | 0.0014 | good |