audit information
A category of security-sensitive data comprising everything an organization generates and relies upon to document, verify, and reconstruct system activity for accountability purposes. It includes audit records, audit log settings, audit reports, and personally identifiable information captured in the course of logging — in other words, not just the raw log entries but the configuration and tooling that shapes them. Because this data can itself be attacked, the field treats it as a protection target: access and execution rights over audit logging tools are restricted to authorized individuals, with additional technical, media, physical, and environmental controls applied. In operational use, "audit information" also appears as the input to downstream processes — for example, it is collected and then manipulated into summary formats more meaningful to analysts.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- audit informations
- possessive
- audit information's
- pluralpossessive
- audit informations'