AU-5 Audit and Accountability

Response to Audit Processing Failures

High Risk Moderate Low Cost

AU-5 requires alerting designated personnel within an organization-defined time period in the event of an audit logging process failure, and taking additional organization-defined actions (such as shutting down, overwriting oldest records, or stopping system functions). In healthcare, a quiet log pipeline during a ransomware event or insider browsing spree is itself an incident.

Control Objective

Detect audit generation, transport, or storage failures quickly; notify the right people; and execute predefined actions so ePHI activity is not invisibly unlogged.

Implementation Guidance

  1. Define failure modes: agent crash, API audit disabled, disk full, SIEM ingest reject, clock skew breaking pipelines, permission errors on log shares.
  2. Implement heartbeat/silence detection per critical source (EHR audit feed, IdP, VPN, privileged jump hosts).
  3. Alert SOC/on-call within minutes for tier-1 ePHI sources; define escalation if unacked.
  4. Document authorized responses: page storage, failover to secondary collector, degrade noncritical verbosity, or — only if risk-accepted — overwrite oldest with explicit policy.
  5. Never choose overwrite of ePHI investigation logs casually; prefer expanding capacity (AU-4).
  6. Test failure injection in nonprod and tabletop the prod response annually.
  7. Include cloud admin audit export failures.
  8. Record AU-5 incidents and feed lessons into AU-12 monitoring.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR upgrade disables audit API

Ingest volume drops to zero at 02:00. AU-5 silence alert pages on-call; settings restored before morning clinics open — avoiding a full day of unlogged chart access.

SIEM license/ingest cap hit

Collectors reject events. AU-5 triggers capacity response and temporary filter of low-value noise while preserving ePHI access and admin events.

Ransomware wipes local logs

Forwarding had failed for 12 hours unnoticed historically. New AU-5 heartbeats would have exposed the gap before encryption started.

Best Practices

  • Heartbeat monitors per critical log source.
  • Named on-call owners and time-to-alert SLAs.
  • Pre-approved failure playbooks.
  • Prefer capacity expansion over destructive overwrite.
  • Test after every major SIEM/EHR change.
  • Track mean time to detect logging failure.

Common Gaps & Violations

  • Logging fails with no alert.
  • Alerts go to a dead distribution list.
  • Overwrite oldest forever with no policy.
  • Only disk-full OS alerts — not application audit disable.
  • No testing of silence detection.

Required Documentation

  • Audit failure response procedure (AU-5)
  • Alert routing and SLA definitions
  • Authorized actions on failure (including any overwrite rules)
  • Silence/heartbeat monitor configurations
  • Incident tickets from real or test failures

How to Test & Validate

  1. Stop a test forwarder; confirm alert within SLA.
  2. Review last real AU-5 event for correct escalation.
  3. Verify playbook actions are still accurate after tool changes.
  4. Confirm tier-1 ePHI sources all have heartbeat coverage.
  5. Ensure overwrite behavior — if any — matches written policy.

Audit Considerations

Auditors increasingly ask how you know logging is working today. AU-5 evidence is alerts, on-call records, and playbooks — not a hope that disks never fill.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — mechanisms must actually function to record activity.
  • 164.308(a)(1)(ii)(D) Information System Activity Review — cannot review during silent outages.
  • 164.308(a)(6) Security Incident Procedures — logging failure may itself require incident handling.
  • 164.308(a)(8) Evaluation — evaluations should confirm audit mechanisms still operate.

Compliance Tips

  • Add audit-pipeline health to the same dashboard as EHR uptime.
  • Require a logging-health sign-off in go-live checklists.
  • Treat multi-hour silence on EHR audit as a security incident.

Frequently Asked Questions

Should we shut down the EHR if auditing fails?

Rarely practical for patient care. Define proportionate actions — alert, failover, restrict admin functions — and document clinical safety tradeoffs.

Is disk-full alerting enough for AU-5?

No. Include application-level audit disable and shipping failures.

Who must be alerted?

Organization-defined personnel — typically SOC plus system owners for tier-1 clinical systems.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-5
  • Related controls: AU-4, AU-9, AU-12, SI-4, IR-4

Need Help Implementing AU-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.