AU-1 - Policy and Procedures

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] audit and accountability policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the audit and accountability policy and the associated audit and accountability controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the audit and accountability policy and procedures; and c. Review and update the current audit and accountability: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].


ID: AU-1
Enhancements: 

Space Segment Guidance

When defining audit and accountability policy for spacecraft, consider how records will be produced, preserved, and correlated across space and ground despite intermittent links. Useful elements include phase/mode awareness (LEOP, nominal, safe), AOS/LOS boundaries that mark session start/stop, and time synchronization assumptions for cross-segment correlation. It can be helpful to describe buffering and retention on-board, downlink prioritization, minimal logging that persists in safe or low-power states, and how audit evidence is cryptographically bound to sessions, images, and configuration so post-event analysis is trustworthy.