NIST 800-53 Rev. 5

AU-3(3): Content of Audit Records | Limit Personally Identifiable Information Elements

Control Text:

Limit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: [Assignment: organization-defined elements].

Limiting personally identifiable information in audit records when such information is not needed for operational purposes helps reduce the level of privacy risk created by a system.

Related Controls