Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family AU

AU-15Alternate Audit Logging Capability

Alternate Audit Logging Capability

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (2)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-636Not Failing Securely ('Failing Open')27Ensures audit logging continues on primary failure instead of failing open with no logging capability.
CWE-778Insufficient Logging23Provides alternate logging mechanism to maintain audit trails when primary capability fails, directly reducing insufficient logging.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family AU

AU-1 AU-10 AU-11 AU-12 AU-13 AU-14 AU-16 AU-2 AU-3 AU-4 AU-5 AU-6 AU-7 AU-8 AU-9