AU-9 - Protection of Audit Information [FSv1.1]
This control is based on IBM Cloud Framework for Financial Services v1.1.
Control requirements
- AU-9 - 0
- The information system protects audit information and audit tools from unauthorized access, modification, and deletion.
NIST supplemental guidance
Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity. This control focuses on technical protection of audit information. Physical protection of audit information is addressed by media protection controls and physical and environmental protection controls.