audit information
163574·updated Sep 1, 2026A category of security-sensitive data comprising everything an organization generates and relies upon to document, verify, and reconstruct system activity for accountability purposes. It includes audit records, audit log settings, audit reports, and personally identifiable information captured in the course of logging — in other words, not just the raw log entries but the configuration and tooling that shapes them. Because this data can itself be attacked, the field treats it as a protection target: access and execution rights over audit logging tools are restricted to authorized individuals, with additional technical, media, physical, and environmental controls applied. In operational use, "audit information" also appears as the input to downstream processes — for example, it is collected and then manipulated into summary formats more meaningful to analysts.
Source
, and managing audit information.the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- – AU-9 PROTECTION OF AUDIT INFORMATION | NIST SP 800-53
- AU-9: Protection of Audit Information - CSF Tools
- audit record reduction - Glossary - NIST CSRC
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A collective body of recorded data — comprising audit logs, audit records, audit trails, and associated metadata — generated or collected by systems and processes to document security-relevant events, transactions, and user actions for purposes of accountability, compliance verification, and forensic investigation. It is distinguished from the audit *process* itself by being the evidentiary substrate that process relies on: the raw material that enables review of who did what, when, and with what effect. In practice, authoritative frameworks such as NIST SP 800-53 (control AU-9, "Protection of Audit Information") treat it as an asset requiring its own integrity, availability, and access controls, because its trustworthiness is a precondition for any meaningful security audit or accountability finding.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- audit informations
- possessive
- audit information's
- pluralpossessive
- audit informations'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A category of security-sensitive data comprising everything an organization generates and relies upon to document, verify, and reconstruct system activity for accountability purposes. It includes audit records, audit log settings, audit reports, and personally identifiable information captured in the course of logging — in other words, not just the raw log entries but the configuration and tooling that shapes them. Because this data can itself be attacked, the field treats it as a protection target: access and execution rights over audit logging tools are restricted to authorized individuals, with additional technical, media, physical, and environmental controls applied. In operational use, "audit information" also appears as the input to downstream processes — for example, it is collected and then manipulated into summary formats more meaningful to analysts.DR-088 backfill from the noun definition column