SIEM outage during ransomware hunt
Primary SIEM is offline; domain controllers and EHR keep writing to alternate collectors so investigators retain auth and admin events.
AU-15 provides an alternate audit logging capability when the primary logging capability is unavailable. Hospitals that lose the SIEM or EHR audit pipeline during outages still need a way to retain security-relevant events for systems handling ePHI.
Maintain an alternate audit logging path so defined ePHI-related auditable events are still captured if primary logging fails.
How this control shows up in healthcare and HIPAA-covered environments.
Primary SIEM is offline; domain controllers and EHR keep writing to alternate collectors so investigators retain auth and admin events.
During vendor maintenance, alternate file-based audit spool captures security console actions until primary resumes.
IdP audit API fails over to secondary region sink defined under AU-15.
AU-15 is resilience for audit—assessors want a second path, not a promise to rebuild logs later.
How this NIST control supports HIPAA Security Rule expectations.
It can be part of an alternate capability if it survives primary failure and is protected/reviewed.
Confirm overlay; highly valuable for ePHI systems even when optional.
AU-5 addresses audit processing failures/response; AU-15 provides alternate logging capability.
Related controls that commonly accompany AU-15.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.