Control: The organisational locates audit record storage capacity in accordance with [Assignment: organisation-defined audit record storage requirements].
Supplemental Guidance: Organisations consider the types of auditing to be performed and the audit processing requirements when allocating audit storage capacity. Allocating sufficient audit storage capacity reduces the likelihood of such capacity being exceeded and resulting in the potential loss or reduction of auditing capability.
Audit Storage Capacity Control Enhancements:
AU4 (1) Audit Storage Capacity - Transfer to alternative storage
The information system off-loads audit records [Assignment: organisation-defined frequency] onto a different system or media than the system being audited.
Supplemental Guidance: Off-loading is a process designed to preserve the confidentiality and integrity of audit records by moving the records from the primary information system to a secondary or alternate system. It is a common process in information systems with limited audit storage capacity; the audit storage is used only in a transitory fashion until the system can communicate with the secondary or alternate system designated for storing the audit records, at which point the information is transferred.