AU-15 Audit and Accountability

Alternate Audit Logging Capability

High Risk Moderate Medium Cost

AU-15 provides an alternate audit logging capability when the primary logging capability is unavailable. Hospitals that lose the SIEM or EHR audit pipeline during outages still need a way to retain security-relevant events for systems handling ePHI.

Control Objective

Maintain an alternate audit logging path so defined ePHI-related auditable events are still captured if primary logging fails.

Implementation Guidance

  1. Define primary vs alternate logging targets (local secure store, secondary SIEM, cloud sink).
  2. Configure failover or dual-write for critical EHR, IdP, and boundary devices.
  3. Test failover during maintenance windows.
  4. Protect alternate stores equally (AU-9).
  5. Alert when primary logging is down—not only when disks fill.
  6. Include alternate path in CP/DR runbooks.
  7. Reconcile events after primary restoration.
  8. Document capacity of alternate path.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

SIEM outage during ransomware hunt

Primary SIEM is offline; domain controllers and EHR keep writing to alternate collectors so investigators retain auth and admin events.

EHR audit DB maintenance

During vendor maintenance, alternate file-based audit spool captures security console actions until primary resumes.

Cloud IdP regional issue

IdP audit API fails over to secondary region sink defined under AU-15.

Best Practices

  • Dual-write or automatic failover for critical sources.
  • Equal protection for alternate stores.
  • Alert on primary logging failure.
  • Include in DR tests.
  • Reconcile after restore.
  • Size alternate capacity realistically.

Common Gaps & Violations

  • Single SIEM with no backup path.
  • Alternate logs on the same failing host.
  • No alert when forwarding stops.
  • Alternate path never tested.
  • Claiming AU-15 with only screenshots of primary.

Required Documentation

  • Alternate audit logging design (AU-15)
  • Primary/alternate matrix by system
  • Failover test records
  • Protection/retention for alternate stores
  • CP/DR references

How to Test & Validate

  1. Stop primary forwarder in test; confirm alternate receipt.
  2. Verify alerts on primary failure.
  3. Confirm alternate retention and access controls.
  4. Review last DR test for logging steps.
  5. Sample reconciliation after a real outage if available.

Audit Considerations

AU-15 is resilience for audit—assessors want a second path, not a promise to rebuild logs later.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — continuous ability to record activity.
  • 164.308(a)(7) Contingency Plan — audit capability during disruptions.
  • 164.308(a)(1)(ii)(D) Activity Review — reviews need surviving logs.
  • 164.308(a)(6) Incident Response — investigations during crises need events.

Compliance Tips

  • Prioritize IdP, EHR security, and firewall logs for alternate paths.
  • Treat logging outage as a security incident.
  • Document RPO for audit data.

Frequently Asked Questions

Is a longer local buffer enough?

It can be part of an alternate capability if it survives primary failure and is protected/reviewed.

Required in low baseline?

Confirm overlay; highly valuable for ePHI systems even when optional.

Related to AU-5?

AU-5 addresses audit processing failures/response; AU-15 provides alternate logging capability.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-15
  • Related controls: AU-5, AU-9, AU-4, CP-2

Need Help Implementing AU-15?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.