NIST SP 800-53 Rev. 5 · Audit and Accountability

AU-9 — Protection of Audit Information

Audit logging disabled or deleted. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.

Why this matters

Someone switched off the recording of what happens on the system

Systems keep a record of significant events, and that record is how anyone reconstructs what happened after an incident. It is also the first thing an intruder turns off, because everything they do afterwards goes unrecorded. Switching it off is a legitimate administrative action, so it does not look like an attack — which is why it works.

Why this check earns its place. The check does not decide whether the person was allowed to do it. It surfaces that it happened, so a human can ask, which is the only correct handling for an action that is sometimes routine and sometimes the first move of a break-in.

What it reads
The organization's own record of administrative actions taken on its systems.
What it reports
Occasions when the recording of system events was stopped, deleted, or altered.

See related public disclosures on the Signals page →

The requirement

The organization must protect audit information and audit logging tools from unauthorized access, modification, and deletion.

NIST SP 800-53 Rev. 5 — AU-9 (Protection of Audit Information).

NIST requires protection of audit information. Which logging surfaces are in scope, which identities may legitimately modify logging configuration, and the expected response time are organization-defined.

What a check finds

Audit logging configuration stopped, deleted, or modified; the reviewer determines whether the actor was authorized.

Choose your platform

CISA performance goals

  • 3.Q — Maintain log collection & storage

Full coverage map →

What a result does not prove

A logging configuration change is not automatically malicious. It is, however, one of the few conditions where the cost of a slow review is high enough to justify treating it as urgent by default.