Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family AU

AU-14Session Audit

Provide and implement the capability for {{ insert: param, au-14_odp.01 }} to {{ insert: param, au-14_odp.02 }} the content of a user session under {{ insert: param, au-14_odp.03 }} ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-200Exposure of Sensitive Information to an Unauthorized Actor11,000+Session auditing enables detection of unauthorized exposure or access to sensitive information during user activities.
CWE-862Missing Authorization10,200+Session auditing detects missing authorization by exposing unauthorized actions taken within sessions.
CWE-284Improper Access Control6,900+Provides capability to review session content, directly detecting violations of access control.
CWE-287Improper Authentication5,200+Session content review can reveal authentication bypasses or failures in session establishment.
CWE-863Incorrect Authorization3,900+Enables detection of incorrect authorization through review of session-level activities and decisions.
CWE-306Missing Authentication for Critical Function3,300+Auditing sessions makes it possible to detect access to critical functions without required authentication.
CWE-285Improper Authorization1,500+Auditing session actions allows identification of improper authorization decisions and enforcement failures.
CWE-778Insufficient Logging28Directly implements detailed session logging to address the weakness of insufficient logging.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family AU

AU-1 AU-10 AU-11 AU-12 AU-13 AU-15 AU-16 AU-2 AU-3 AU-4 AU-5 AU-6 AU-7 AU-8 AU-9