FedRAMP-AU-2(H): Identify auditable events with expanded scope for high-impact systems
Vallum evidence mapping for FedRAMP FedRAMP-AU-2(H) — identify auditable events with expanded scope for high-impact systems. Documents evidence produced, gaps, and customer responsibilities.
Source Attribution
- Framework
- FedRAMP Rev 5 High
- Control ID
- FedRAMP-AU-2(H)
- Source Organization
- FedRAMP PMO
- Official Source
- FedRAMP Security Controls Baseline ↗
- Control Objective
- Identify auditable events with expanded scope for high-impact systems
Evidence Vallum Produces
Authorization receipts, evidence packages, and signed audit records documenting Vallum-managed operations relevant to this control
Evidence Vallum Does NOT Produce
FIPS validation certificates, physical security evidence, personnel security records, or infrastructure-level monitoring data
Known Limitations
Vallum provides evidence relevant to this FedRAMP requirement but does not constitute complete control implementation. Full compliance requires complementary controls at infrastructure, organizational, and procedural levels. Evidence covers Vallum-managed operations only and does not extend to customer applications, third-party systems, or physical infrastructure.
Your Responsibilities
Implement FedRAMP-required infrastructure controls, maintain authorization package, engage 3PAO for assessment, and manage POA&M items
External Controls Required
Identity provider, infrastructure security controls, organizational policies and procedures, third-party assessments, and legal/regulatory counsel
Residual Risk
Evidence gaps exist between Vallum-managed operations and full control implementation. Time-of-check to time-of-use windows, infrastructure-level vulnerabilities, and organizational process failures remain outside Vallum's evidence boundary.
Relevant Titan Components
Need a detailed evidence mapping for your specific compliance program?
Request a Control Evidence Mapping