NIST 800-53 r5 · Controls catalogue · Family AU
AU-7Audit Record Reduction and Report Generation
Provide and implement an audit record reduction and report generation capability that: Supports on-demand audit record review, analysis, and reporting requirements and after-the-fact investigations of incidents; and Does not alter the original content or time ordering of audit records.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (2)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-778 | Insufficient Logging | 28 | The reduction and report generation capability directly enables usable on-demand review and incident investigation, mitigating insufficient logging by ensuring audit data can be effectively analyzed without loss of original records. |
CWE-779 | Logging of Excessive Data | 20 | Audit record reduction explicitly manages excessive log volumes for review and reporting while preserving original content and ordering, reducing the impact of logging excessive data. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-36072 UPD | 7.5 | 9.8 | 0.0101 | good |
CVE-2024-36416 UPD | 6.6 | 8.6 | 0.0195 | good |
CVE-2024-55628 UPD | 6.0 | 7.5 | 0.0069 | good |
CVE-2025-8696 UPD | 5.8 | 7.5 | 0.0044 | good |
CVE-2026-28718 | 5.8 | 7.5 | 0.0034 | good |
CVE-2025-51397 UPD | 4.4 | 5.4 | 0.0087 | good |
CVE-2025-69230 UPD | 4.4 | 5.3 | 0.0034 | good |
CVE-2025-53636 UPD | 4.3 | 5.4 | 0.0028 | good |
CVE-2024-1141 UPD | 4.2 | 5.5 | 0.0023 | good |
CVE-2026-20209 UPD | 4.2 | 5.4 | 0.0019 | good |
CVE-2026-20210 UPD | 4.2 | 5.4 | 0.0019 | good |