AU-12.4 ยท Query Parameter Audits of Personally Identifiable Information

Control Description

Provide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
system
Enhancement
Control Statement
The control requirements

Provide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.

Supplemental Guidance

Query parameters are explicit criteria that an individual or automated system submits to a system to retrieve data. Auditing of query parameters for datasets that contain personally identifiable information augments the capability of an organization to track and understand the access, usage, or sharing of personally identifiable information by authorized personnel.