NIST 800-53 r5 · Controls catalogue · Family AU
AU-3Content of Audit Records
Ensure that audit records contain information that establishes the following: What type of event occurred; When the event occurred; Where the event occurred; Source of the event; Outcome of the event; and Identity of any individuals, subjects, or objects/entities associated with the event.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (13)
- aws-config-cloudtrail-enabled CloudTrail is enabled in the account AWS::CloudTrail::Trail partial detect enforce
- aws-config-vpc-flow-logs-enabled VPC flow logs are enabled AWS::EC2::VPC partial detect enforce CIS §3.7Hub EC2.6
- aws-config-api-gw-execution-logging-enabled Api Gw Execution Logging Enabled AWS::ApiGateway::Stage partial detect enforce
- aws-config-cloud-trail-cloud-watch-logs-enabled Cloud Trail Cloud Watch Logs Enabled AWS::CloudTrail::Trail partial detect enforce
- aws-config-cloudtrail-s3-dataevents-enabled Cloudtrail S3 Dataevents Enabled AWS::CloudTrail::Trail partial detect enforce
- aws-config-elasticsearch-logs-to-cloudwatch Elasticsearch Logs To Cloudwatch AWS::OpenSearchService::Domain partial detect enforce
- aws-config-elb-logging-enabled Elb Logging Enabled AWS::ElasticLoadBalancing::LoadBalancer partial detect enforce
- aws-config-multi-region-cloudtrail-enabled Multi Region Cloudtrail Enabled AWS::CloudTrail::Trail partial detect enforce CIS §3.1Hub CloudTrail.1
- aws-config-opensearch-logs-to-cloudwatch Opensearch Logs To Cloudwatch AWS::OpenSearchService::Domain partial detect enforce
- aws-config-rds-logging-enabled Rds Logging Enabled AWS::RDS::DBInstance partial detect enforce
- aws-config-redshift-cluster-configuration-check Redshift Cluster Configuration Check AWS::Redshift::Cluster partial protect enforce
- aws-config-s3-bucket-logging-enabled S3 Bucket Logging Enabled AWS::S3::Bucket partial detect enforce CIS §3.4Hub CloudTrail.7
- aws-config-wafv2-logging-enabled Wafv2 Logging Enabled AWS::WAFv2::WebACL partial detect enforce
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (1)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-778 | Insufficient Logging | 28 | This control directly specifies the minimum content required in audit records to establish event details, attribution, and outcomes, thereby mitigating insufficient logging. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-48967 UPD | 7.5 | 10.0 | 0.0063 | good |
CVE-2026-76208 | 6.1 | 8.2 | 0.0025 | good |
CVE-2025-2562 UPD | 4.4 | 5.4 | 0.0041 | good |
CVE-2026-25598 UPD | 4.4 | 5.3 | 0.0031 | good |
CVE-2025-32967 UPD | 4.3 | 5.4 | 0.0026 | good |
CVE-2025-53498 UPD | 4.3 | 5.3 | 0.0025 | good |
CVE-2025-52644 | 4.3 | 5.8 | 0.0014 | good |
CVE-2025-62307 | 4.2 | 5.4 | 0.0018 | good |
CVE-2024-2291 UPD | 3.7 | 4.3 | 0.0039 | good |
CVE-2024-52813 UPD | 3.7 | 4.3 | 0.0048 | good |
CVE-2025-66552 | 3.6 | 4.3 | 0.0030 | good |
CVE-2026-22279 | 3.6 | 4.3 | 0.0024 | good |
CVE-2026-3494 UPD | 3.6 | 4.3 | 0.0027 | good |
CVE-2024-10863 UPD | 3.5 | 5.1 | 0.0044 | good |
CVE-2025-35987 | 3.5 | 4.3 | 0.0010 | good |
CVE-2026-32803 UPD | 2.7 | 3.3 | 0.0009 | good |
CVE-2026-41709 | 2.6 | 2.7 | 0.0038 | good |
CVE-2024-24901 UPD | 2.5 | 3.0 | 0.0014 | good |
CVE-2025-52926 UPD | 2.2 | 2.7 | 0.0014 | good |
CVE-2026-9247 UPD | 2.2 | 2.4 | 0.0022 | good |
CVE-2026-49426 | 0.0 | 0.0 | 0.0015 | good |
CVE-2026-32693 | 6.5 | 8.8 | 0.0030 | good |
CVE-2026-31890 UPD | 4.1 | 5.5 | 0.0014 | good |