AU-09.6 ยท Read-only Access

Control Description

Authorize read-only access to audit information to {{ insert: param, au-09.06_odp }}.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
organization
Enhancement
Control Statement
The control requirements

Authorize read-only access to audit information to {{ insert: param, au-09.06_odp }}.

Supplemental Guidance

Restricting privileged user or role authorizations to read-only helps to limit the potential damage to organizations that could be initiated by such users or roles, such as deleting audit records to cover up malicious activity.