NIST 800-53 r5 · Controls catalogue · Family AU
AU-2Event Logging
Identify the types of events that the system is capable of logging in support of the audit function: {{ insert: param, au-02_odp.01 }}; Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged; Specify the following event types for logging within the system: {{ insert: param, au-2_prm_2 }}; Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and Review and update the event types selected for logging {{ insert: param, au-02_odp.04 }}.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)
Implementations targeting this control (17)
- aws-config-cloudtrail-enabled CloudTrail is enabled in the account AWS::CloudTrail::Trail partial detect enforce
- aws-config-vpc-flow-logs-enabled VPC flow logs are enabled AWS::EC2::VPC partial detect enforce CIS §3.7Hub EC2.6
- azure-mcsb-lt-04-resource-logs Resource logs are streamed to Log Analytics or storage Microsoft.Insights/diagnosticSettings partial protect enforce
- azure-mcsb-network-flow-logs NSG flow logs are enabled Microsoft.Network/networkSecurityGroups partial protect enforce
- gcp-cis-vpc-flow-logs-enabled VPC subnetworks have flow logs enabled compute.googleapis.com/Subnetwork partial protect enforce
- gcp-cis-cloud-audit-logs-enabled Cloud Audit Logs cover all admin/data services cloudresourcemanager.googleapis.com/Project partial protect enforce
- aws-config-api-gw-execution-logging-enabled Api Gw Execution Logging Enabled AWS::ApiGateway::Stage partial detect enforce
- aws-config-cloud-trail-cloud-watch-logs-enabled Cloud Trail Cloud Watch Logs Enabled AWS::CloudTrail::Trail partial detect enforce
- aws-config-cloudtrail-s3-dataevents-enabled Cloudtrail S3 Dataevents Enabled AWS::CloudTrail::Trail partial detect enforce
- aws-config-elasticsearch-logs-to-cloudwatch Elasticsearch Logs To Cloudwatch AWS::OpenSearchService::Domain partial detect enforce
- aws-config-elb-logging-enabled Elb Logging Enabled AWS::ElasticLoadBalancing::LoadBalancer partial detect enforce
- aws-config-multi-region-cloudtrail-enabled Multi Region Cloudtrail Enabled AWS::CloudTrail::Trail partial detect enforce CIS §3.1Hub CloudTrail.1
- aws-config-opensearch-logs-to-cloudwatch Opensearch Logs To Cloudwatch AWS::OpenSearchService::Domain partial detect enforce
- aws-config-rds-logging-enabled Rds Logging Enabled AWS::RDS::DBInstance partial detect enforce
- aws-config-redshift-cluster-configuration-check Redshift Cluster Configuration Check AWS::Redshift::Cluster partial protect enforce
- aws-config-s3-bucket-logging-enabled S3 Bucket Logging Enabled AWS::S3::Bucket partial detect enforce CIS §3.4Hub CloudTrail.7
- aws-config-wafv2-logging-enabled Wafv2 Logging Enabled AWS::WAFv2::WebACL partial detect enforce
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (1)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-778 | Insufficient Logging | 28 | This control requires identifying, specifying, and justifying event types for logging with a focus on adequacy for post-incident investigations, directly mitigating insufficient logging. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-36072 UPD | 7.5 | 9.8 | 0.0101 | good |
CVE-2024-36416 UPD | 6.6 | 8.6 | 0.0195 | good |
CVE-2024-55628 UPD | 6.0 | 7.5 | 0.0069 | good |
CVE-2025-8696 UPD | 5.8 | 7.5 | 0.0044 | good |
CVE-2026-28718 | 5.8 | 7.5 | 0.0034 | good |
CVE-2025-51397 UPD | 4.4 | 5.4 | 0.0087 | good |
CVE-2025-69230 UPD | 4.4 | 5.3 | 0.0034 | good |
CVE-2025-53636 UPD | 4.3 | 5.4 | 0.0028 | good |
CVE-2024-1141 UPD | 4.2 | 5.5 | 0.0023 | good |
CVE-2026-20209 UPD | 4.2 | 5.4 | 0.0019 | good |
CVE-2026-20210 UPD | 4.2 | 5.4 | 0.0019 | good |
CVE-2024-48967 UPD | 7.5 | 10.0 | 0.0063 | good |
CVE-2026-76208 | 6.1 | 8.2 | 0.0025 | good |
CVE-2025-2562 UPD | 4.4 | 5.4 | 0.0041 | good |
CVE-2026-25598 UPD | 4.4 | 5.3 | 0.0031 | good |
CVE-2025-32967 UPD | 4.3 | 5.4 | 0.0026 | good |
CVE-2025-53498 UPD | 4.3 | 5.3 | 0.0025 | good |
CVE-2025-52644 | 4.3 | 5.8 | 0.0014 | good |
CVE-2025-62307 | 4.2 | 5.4 | 0.0018 | good |
CVE-2024-2291 UPD | 3.7 | 4.3 | 0.0039 | good |
CVE-2024-52813 UPD | 3.7 | 4.3 | 0.0048 | good |
CVE-2025-66552 | 3.6 | 4.3 | 0.0030 | good |
CVE-2026-22279 | 3.6 | 4.3 | 0.0024 | good |
CVE-2026-3494 UPD | 3.6 | 4.3 | 0.0027 | good |
CVE-2024-10863 UPD | 3.5 | 5.1 | 0.0044 | good |