AU-10(2)—Non-Repudiation
Technical
>Control Description
NON-REPUDIATION | VALIDATE BINDING OF INFORMATION PRODUCER IDENTITY (a) The information system validates the binding of the information producer identity to the information at ⚙organization-defined frequency; and (b) The information system performs ⚙organization-defined actions in the event of a validation error.
>Supplemental Guidance
This control enhancement prevents the modification of information between production and review. The validation of bindings can be achieved, for example, by the use of cryptographic checksums. Organizations determine if validations are in response to user requests or generated automatically.
Related controls: AC-3, AC-4, AC-16.
Ask AI
Configure your API key to use AI features.