Bidda Sovereign Intelligence · 10,108 Verified Nodes · 39 Sovereign Pillars

Audit Event Logging (NIST 800-53)

NIST SP 800-53 Rev 5 Control AU-2 (Event Logging) requires organizations to identify the types of events that the system is capable of logging in support…

What Audit Event Logging (NIST 800-53) requires

NIST SP 800-53 Rev 5 Control AU-2 (Event Logging) requires organizations to identify the types of events that the system is capable of logging in support of the audit function, coordinate the event logging function with other organizations requiring audit-related information, and specify the types of events to be logged - establishing the foundational event taxonomy upon which all subsequent audit controls (AU-3 through AU-16) depend. AU-2 is a HIGH baseline control required for all federal systems at the MODERATE and HIGH impact levels, and FedRAMP and CMMC 2.0 both mandate AU-2 implementation. The control is critical for AI agent deployments because AI agents generate high volumes of events across multiple systems and APIs; without a comprehensive AU-2 event taxonomy that explicitly includes AI agent actions (tool calls, API invocations, data access, decision outputs), audit trails will be insufficient for forensic investigation of AI-related incidents, regulatory compliance, and attack reconstruction. Failure to implement AU-2 in AI systems undermines the detectability of MITRE T1562 (Impair Defenses) attacks targeting audit infrastructure and creates undetectable gaps in the audit trail.

Pillar: Cybersecurity · Authority: NIST (National Institute of Standards and Technology) · Version: 1.1.0 · Last updated:

Primary source: https://doi.org/10.6028/NIST.SP.800-53r5

SHA-256 integrity: 68811208d14cc52623c17bbe83e4adce0d47515e182436cf960d6c9f136f9eb4

Primary Citations — 6 traced to source

  • NIST Special Publication 800-53 Revision 5, Control AU-2 (Event Logging) and AU-5 (Response to Audit Logging Failures).
  • FedRAMP Rev. 5 High Baseline Security Controls (AU-2 mandates comprehensive event logging for cloud systems).

+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.