DroneUp Compliance Docs

CBI // INFORMATION SECURITY · Document ID: DU-1-POL-911-001 · Classification: CBI

Security Audit and Accountability Policy

DU-1-POL-911-001 · owner: infosec · QMS clause: 09.01.01

Confidential Business Information (CBI) — do not distribute. This document contains proprietary information of DroneUp, LLC. It is intended solely for the information and use of parties operating on behalf of DroneUp, LLC and its affiliates. Such proprietary information may not be used, reproduced, or disclosed to any other parties for any other purpose without express written permission. The information contained in this document is effective as of the revision date in the document control record.

Revision history

VersionDateDescriptionUpdated by
12021-09-23Initial publication.Infosec Manager
22026-06-19Full rewrite for NIST 800-171 Rev 3Sybil Melton

1. Purpose

This policy establishes DroneUp’s management direction for audit and accountability: the generation, content, protection, retention, and review of audit records sufficient to detect, investigate, and recover from security incidents and to attribute every recorded event to an accountable individual. It directs the responsible functional roles to operate an audit program that protects the integrity, confidentiality, and availability of DroneUp’s information systems and the data entrusted to DroneUp by clients, partners, and the U.S. Government.

2. Scope

This Security Audit and Accountability Policy [DU-1-POL-911-001] operates under the authority of the Information Security Program Policy [DU-1-POL-521-001], which governs DroneUp’s Information Compliance Program. It establishes the audit and accountability requirements for DroneUp’s organizational systems and is operationalized by the following subordinate documents:

  • Logging and Audit Subpolicy [DU-2-SUB-911-001]
  • Time Synchronization Subpolicy [DU-2-SUB-911-002]
  • Event Logging Procedure [DU-2-PRO-911-001]
  • Audit Record Content Procedure [DU-2-PRO-911-002]
  • Audit Record Generation Procedure [DU-2-PRO-911-003]
  • Response to Audit Logging Process Failures Procedure [DU-2-PRO-911-004]
  • Audit Record Review, Analysis, and Reporting Procedure [DU-2-PRO-911-005]
  • Audit Record Reduction and Report Generation Procedure [DU-2-PRO-911-006]
  • Time Stamps Procedure [DU-2-PRO-911-007]
  • Protection of Audit Information Procedure [DU-2-PRO-911-008]

Who this applies to: all DroneUp employees, contractors, and consultants, and all users of DroneUp systems, who are subject to monitoring as a condition of access.

What this covers: all DroneUp organizational systems, data, and operations that create, receive, process, store, or transmit information on behalf of DroneUp, or information entrusted to DroneUp by clients, partners, suppliers, or the U.S. Government. The systems and boundaries in scope are identified in the NIST SP 800-171 System Security Plan (SSP) [DU-1-PLN-710-039].

Review and update this policy at least annually and upon Significant Change, in accordance with the document control record. Non-compliance may result in disciplinary action up to and including termination, as defined in Section 12. Direct questions to the Information Security team through designated support channels.

Compliance and control framework alignment

This policy is designed to address the NIST SP 800-171 Rev. 3 Audit and Accountability control family (03.03). DroneUp has not completed a formal audit against this framework. The specific requirements addressed are recorded in the control mapping for this document rather than in the section headings.

3. Event Logging

The Accountable Security Authority must:

  • Define and approve the categories of security-relevant events that DroneUp systems must log — sufficient to detect unauthorized access, misuse of elevated privileges, unauthorized handling of CUI, and tampering with data or security controls — in accordance with the Event Logging Procedure [DU-2-PRO-911-001].
  • Review and update the set of logged event types on a defined cadence, and whenever changes in the threat environment or DroneUp systems warrant, so that logging coverage stays aligned with current risk, in accordance with the Event Logging Procedure [DU-2-PRO-911-001].

4. Audit Record Content

Information Systems and Security Personnel must:

  • Ensure each audit record establishes what event occurred, when and where it occurred, the source, the outcome, and the identity of the associated user or subject, in accordance with the Audit Record Content Procedure [DU-2-PRO-911-002].

5. Audit Record Generation and Retention

Information Systems and Security Personnel must:

  • Ensure DroneUp systems generate audit records for every approved event category across all in-scope systems, so that security-relevant activity is captured wherever it occurs, in accordance with the Audit Record Generation Procedure [DU-2-PRO-911-003].
  • Retain audit records for at least the minimum retention period defined in the Audit Record Generation Procedure [DU-2-PRO-911-003], and not reduce that period without written authorization from the Accountable Security Authority.
  • Place audit records relevant to a security incident, federal investigation, or legal proceeding on a litigation or investigation hold, in coordination with Legal, and retain them beyond the standard period until the hold is released, in accordance with the Audit Record Generation Procedure [DU-2-PRO-911-003].

6. Response to Audit Logging Process Failures

Information Systems and Security Personnel must:

  • Ensure DroneUp systems alert Information Systems and Security Personnel and the Accountable Security Authority when an audit subsystem fails, becomes unavailable, or reaches a storage threshold that threatens continued log collection, in accordance with the Response to Audit Logging Process Failures Procedure [DU-2-PRO-911-004].
  • Assess whether an audit-subsystem failure constitutes a reportable security incident and notify the Accountable Security Authority within the notification timeframe defined in the Response to Audit Logging Process Failures Procedure [DU-2-PRO-911-004], handling a confirmed incident in accordance with the Event Response Plan [DU-3-WI-940-002].

7. Audit Record Review, Analysis, and Reporting

Information Systems and Security Personnel must:

  • Actively review audit logs on the schedule defined in the Audit Record Review, Analysis, and Reporting Procedure [DU-2-PRO-911-005] to identify suspicious activity, policy violations, and potential security incidents, and escalate suspicious activity to the Accountable Security Authority for triage and, where warranted, activation of incident handling in accordance with the Event Response Plan [DU-3-WI-940-002].
  • Configure automated alerting to notify Information Systems and Security Personnel and the Accountable Security Authority of high-priority events in real time where technically feasible, using the alert thresholds defined in the Audit Record Review, Analysis, and Reporting Procedure [DU-2-PRO-911-005].
  • Analyze and correlate audit records across DroneUp’s separate log sources and systems, rather than reviewing each in isolation, so the organization gains the situational awareness to recognize activity that is only visible when events are seen together, in accordance with the Audit Record Review, Analysis, and Reporting Procedure [DU-2-PRO-911-005].

8. Audit Record Reduction and Report Generation

Information Systems and Security Personnel must:

  • Provide the capability to consolidate and summarize collected audit records into reports that support review and investigation, without altering the original records, in accordance with the Audit Record Reduction and Report Generation Procedure [DU-2-PRO-911-006].

9. Time Stamps

Information Systems and Security Personnel must:

  • Ensure DroneUp systems draw audit time stamps from internal system clocks synchronized to an authoritative time source, so that recorded events can be accurately ordered and correlated across systems during an investigation, in accordance with the Time Stamps Procedure [DU-2-PRO-911-007].
  • Ensure each audit time stamp is recorded either in Coordinated Universal Time (UTC), or in local time with the offset from UTC included, so that events captured across systems and time zones can be reconciled to a single timeline, in accordance with the Time Stamps Procedure [DU-2-PRO-911-007].

10. Protection of Audit Information

The Accountable Security Authority must:

  • Ensure audit logs are protected against unauthorized access, modification, and deletion, such that no user — including a system administrator — can alter or delete audit records for events in which they participated without a second authorized reviewer and a documented change record, in accordance with the Protection of Audit Information Procedure [DU-2-PRO-911-008].
  • Authorize the ability to manage audit logging functionality — enabling or disabling logging, changing what is logged, and administering log storage — to only a designated subset of privileged roles, rather than to all administrators, in accordance with the Protection of Audit Information Procedure [DU-2-PRO-911-008].
  • Require every user to hold a unique account identifier and prohibit account sharing and the use of shared service accounts for interactive sessions, establishing the technical basis for non-repudiation, in accordance with the Protection of Audit Information Procedure [DU-2-PRO-911-008].
  • Require all changes to audit-log configuration — what events are logged, retention periods, and access controls on log storage — to be authorized and recorded in accordance with the Security Configuration Management Policy [DU-1-POL-631-001].

11. Exceptions

Exceptions to this policy are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].

12. Enforcement and Sanctions

Enforcement and sanctions are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].

Document control

Document numberDU-1-POL-911-001
TitleSecurity Audit and Accountability Policy
ClassificationCBI
OwnerVP of Operations
Approval authorityAccountable Security Authority
Effective date2026-06-24
Revision2
Review cycleAnnual; and upon Significant Change
Parent documentDU-1-POL-521-001
Reviewed byE. Bremer (2026-06-19)
CBI // INFORMATION SECURITY · Document ID: DU-1-POL-911-001 · Classification: CBI