AU-1 Audit and Accountability

Audit and Accountability Policy and Procedures

Medium Priority Intermediate NIST CSF

The organization develops, documents, and disseminates audit and accountability policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.

Implementation Guidance

Develop comprehensive audit and accountability policies that define what events to log, how to protect audit logs, and how to review audit information.

Best Practices

Implement comprehensive logging, protect audit logs from tampering, conduct regular audit reviews, maintain audit trails

Quick Facts

Guideline ID AU-1
Category Audit and Accountability
Subcategory Policy and Procedures
Priority Medium
Level Intermediate
Last Updated Mar 6, 2026

Need Help Implementing This Guideline?

Our certified experts can help you align NIST guidelines with your HIPAA compliance program.