{
  "node_id": "nist-800-53-au2",
  "title": "Audit Event Logging (NIST 800-53)",
  "domain": "Cybersecurity",
  "version": "1.1.0",
  "last_updated": "2026-04-10",
  "bluf": "NIST SP 800-53 Rev 5 Control AU-2 (Event Logging) requires organizations to identify the types of events that the system is capable of logging in support of the audit function, coordinate the event logging function with other organizations requiring audit-related information, and specify the types of events to be logged - establishing the foundational event taxonomy upon which all subsequent audit controls (AU-3 through AU-16) depend. AU-2 is a HIGH baseline control required for all federal systems at the MODERATE and HIGH impact levels, and FedRAMP and CMMC 2.0 both mandate AU-2 implementation. The control is critical for AI agent deployments because AI agents generate high volumes of events across multiple systems and APIs; without a comprehensive AU-2 event taxonomy that explicitly includes AI agent actions (tool calls, API invocations, data access, decision outputs), audit trails will be insufficient for forensic investigation of AI-related incidents, regulatory compliance, and attack reconstruction. Failure to implement AU-2 in AI systems undermines the detectability of MITRE T1562 (Impair Defenses) attacks targeting audit infrastructure and creates undetectable gaps in the audit trail.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping",
      "mitre_attack_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-199-security-categorization",
    "nist-sp-800-53-r5",
    "nist-sp-800-92-log-management",
    "cyber-nist-csf-2",
    "nist-sp-800-39-managing-information-security-risk"
  ],
  "primary_citations_count": 6
}