AU-2 - Event Logging

a. Identify the types of events that the system is capable of logging in support of the audit function: [Assignment: organization-defined event types that the system is capable of logging]; b. Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged; c. Specify the following event types for logging within the system: [Assignment: organization-defined event types (subset of the event types defined in AU-2a.) along with the frequency of (or situation requiring) logging for each identified event type]; d. Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and e. Review and update the event types selected for logging [Assignment: organization-defined frequency].


ID: AU-2
Enhancements: 

Space Segment Guidance

Auditable events for spacecraft often center on command/telemetry control and vehicle state. Consider capturing command accept/reject with reason codes, mode transitions, software/FPGA loads and activations, key lifecycle events, operator/station session activity, and salient FDIR detections. Because bandwidth is scarce, it can help to tier events (e.g., essential, important, best-effort) and to align content with forensics value, so the most diagnostic signals survive long outages and delayed downlinks.