AU-10(1)—Non-Repudiation
Technical
>Control Description
NON-REPUDIATION | ASSOCIATION OF IDENTITIES (a) The information system binds the identity of the information producer with the information to ⚙organization-defined strength of binding; and (b) The information system provides the means for authorized individuals to determine the identity of the producer of the information.
>Supplemental Guidance
This control enhancement supports audit requirements that provide organizational personnel with the means to identify who produced specific information in the event of an information transfer. Organizations determine and approve the strength of the binding between the information producer and the information based on the security category of the information and relevant risk factors. Related controls: AC-4, AC-16.
Ask AI
Configure your API key to use AI features.