AU-9(2) - Protection of Audit Information | Store on Separate Physical Systems or Components

Store audit records [Assignment: organization-defined frequency] in a repository that is part of a physically different system or system component than the system or component being audited.


ID: AU-9(2)
Enhancement of : AU-9

Space Segment Guidance

To support non-repudiation, consider cryptographic binding of records to their origin (e.g., per-record MACs/signatures or sequence-linked hashes), with verification logged on the ground. Including station/operator identity and key/certificate identifiers in the record makes later validation and revocation analysis straightforward, even when logs traverse relays or are downlinked in segments.