AU-12(3) - Audit Record Generation | Changes by Authorized Individuals

Provide and implement the capability for [Assignment: organization-defined individuals or roles] to change the logging to be performed on [Assignment: organization-defined system components] based on [Assignment: organization-defined selectable event criteria] within [Assignment: organization-defined time thresholds].


ID: AU-12(3)
Enhancement of : AU-12

Space Segment Guidance

Adjusting what gets audited can be a high risk in a space platform since toggling audit parameters might mask unauthorized or anomalous activity.  To mitigate that, only authorized personnel, identified via strong credentials or digital signatures, should be able to modify audit selections and thresholds.  In effect, the spacecraft or its ground segment logs any changes to these settings and then transmits a notification to mission control.  This ensures that the chain of custody for security-relevant logs remains intact, even if an adversary attempts to suppress or dilute critical evidence of tampering.