What AU-6 Requires, and Who Owns It
Most agencies that have addressed audit logging believe they have addressed AU-6. They have a SIEM. Logs are being collected. Events are being stored.
AU-6 requires something else.
The control requires review and analysis of audit records, at defined frequencies, for indications of inappropriate or unusual activity. Collected logs that are not reviewed do not satisfy the control. The evidence an auditor looks for is not the log. It is the review.
What the control actually requires
AU-6(a) asks the organization to review and analyze audit records at a defined frequency and for defined findings. The policy specifies at least weekly review of key event categories. AU-6(b) requires that review findings are reported to defined personnel.
Those are two separate obligations. An agency that collects logs and generates automated alerts has addressed some of AU-6. An agency that has not defined the frequency of its review, documented that reviews are occurring, and established a reporting path for findings has not demonstrated the control operates.
The distinction matters to an auditor because AU-6 is one of the twenty metrics enumerated in CA-7. The continuous monitoring obligation that took effect on October 1, 2024 requires an active monitoring strategy — not a log storage strategy. An agency cannot demonstrate CA-7 compliance with a SIEM deployment alone. It needs evidence that AU-6 reviews are occurring, at the defined interval, and that findings are being reported.
The split between what agencies own and what their providers own
In a hosted or cloud environment, the audit log review obligation does not automatically transfer to the service provider. The Requirement Companion Document is specific about this: AU-6 responsibility in IaaS, PaaS, and SaaS models splits between the agency and the provider depending on the specific sub-requirement.
For an agency using a cloud-hosted system, the starting question is which party reviews which logs. The service provider may retain infrastructure logs. The agency is responsible for application-layer and access logs. In most deployments, both exist, and the review obligation applies to the logs within the agency's sphere of control regardless of where those logs are hosted.
The SA-9 external service provider audit requirement intersects here. An agency that relies entirely on a provider's assurance that logs are being reviewed has not demonstrated its own AU-6 compliance. The agency owns the obligation to verify, or to obtain documentation that verifies, that the review is occurring.
What the CA-7 connection means operationally
CA-7 enumerates AU-6(a) account management as one of the system-level metrics the continuous monitoring strategy must cover. That reference is not to the control in isolation. It ties the log review activity — who reviews, at what frequency, against what criteria — directly into the broader monitoring posture.
An agency whose monitoring strategy consists of a list of tools without a defined review cadence, named reviewers, and a documented finding-and-report path is not satisfying CA-7 any more than it is satisfying AU-6. The two controls operate together. Evidence for one is partial evidence for the other.
The common failure mode is treating the SIEM as both the monitoring system and the evidence of monitoring. The SIEM is infrastructure. The evidence of monitoring is the log review record — who looked at what, when, and what they found.
What adequate evidence looks like
An auditor reviewing AU-6 compliance is looking for: a defined review frequency; a record that reviews occurred at that frequency during the period under examination; named personnel or roles responsible for the review; a reporting path for findings; and evidence that findings were acted upon or documented as closed.
A SIEM deployment addresses log collection. None of those five items is automatically satisfied by having a SIEM.
If your agency has logs but no record that anyone reviews them on a defined schedule with documented findings, you have storage. You do not have AU-6.
Sources: CJIS Security Policy v6.1, 06/25/2026 — AU-6 Audit Record Review, Analysis, and Reporting; CA-7 Continuous Monitoring; SA-9 External System Services; §1.4 Terminology Used in This Document. Requirement Companion Document v6.1.