NIST 800-53 r5 · Controls catalogue · Family AU
AU-14Session Audit
Provide and implement the capability for {{ insert: param, au-14_odp.01 }} to {{ insert: param, au-14_odp.02 }} the content of a user session under {{ insert: param, au-14_odp.03 }} ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | Session auditing enables detection of unauthorized exposure or access to sensitive information during user activities. |
CWE-862 | Missing Authorization | 10,200+ | Session auditing detects missing authorization by exposing unauthorized actions taken within sessions. |
CWE-284 | Improper Access Control | 6,900+ | Provides capability to review session content, directly detecting violations of access control. |
CWE-287 | Improper Authentication | 5,200+ | Session content review can reveal authentication bypasses or failures in session establishment. |
CWE-863 | Incorrect Authorization | 3,900+ | Enables detection of incorrect authorization through review of session-level activities and decisions. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Auditing sessions makes it possible to detect access to critical functions without required authentication. |
CWE-285 | Improper Authorization | 1,500+ | Auditing session actions allows identification of improper authorization decisions and enforcement failures. |
CWE-778 | Insufficient Logging | 28 | Directly implements detailed session logging to address the weakness of insufficient logging. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||