home/glossary/audit information

audit information

nounid 163574·updated Sep 1, 2026
verified

A category of security-sensitive data comprising everything an organization generates and relies upon to document, verify, and reconstruct system activity for accountability purposes. It includes audit records, audit log settings, audit reports, and personally identifiable information captured in the course of logging — in other words, not just the raw log entries but the configuration and tooling that shapes them. Because this data can itself be attacked, the field treats it as a protection target: access and execution rights over audit logging tools are restricted to authorized individuals, with additional technical, media, physical, and environmental controls applied. In operational use, "audit information" also appears as the input to downstream processes — for example, it is collected and then manipulated into summary formats more meaningful to analysts.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0198
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
, and managing audit information.the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A collective body of recorded data — comprising audit logs, audit records, audit trails, and associated metadata — generated or collected by systems and processes to document security-relevant events, transactions, and user actions for purposes of accountability, compliance verification, and forensic investigation. It is distinguished from the audit *process* itself by being the evidentiary substrate that process relies on: the raw material that enables review of who did what, when, and with what effect. In practice, authoritative frameworks such as NIST SP 800-53 (control AU-9, "Protection of Audit Information") treat it as an asset requiring its own integrity, availability, and access controls, because its trustworthiness is a precondition for any meaningful security audit or accountability finding.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems7 citations · 7 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.d ¶ 103.03.06.b ¶ 103.03.0803.03.08.a03.03.08.b ¶ 103.03.08.b ¶ 103.03.08.b ¶ 2

Classifications

Entity Type

Data95%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5

Information Class

75%llm-generatedmulti_axis_classifier_queued.v1

Variants

plural
audit informations
possessive
audit information's
pluralpossessive
audit informations'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A category of security-sensitive data comprising everything an organization generates and relies upon to document, verify, and reconstruct system activity for accountability purposes. It includes audit records, audit log settings, audit reports, and personally identifiable information captured in the course of logging — in other words, not just the raw log entries but the configuration and tooling that shapes them. Because this data can itself be attacked, the field treats it as a protection target: access and execution rights over audit logging tools are restricted to authorized individuals, with additional technical, media, physical, and environmental controls applied. In operational use, "audit information" also appears as the input to downstream processes — for example, it is collected and then manipulated into summary formats more meaningful to analysts.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.