Audit and Accountability Policy and Procedures | AU-1

Audit and Accountability Policy

MCC recognizes that information system auditing policies and procedures are vital to reducing information security risks.

Purpose

The Audit and Accountability Policy and associated controls document the requirements for ensuring there are adequate event and transaction logs to account for, respond to, and minimize the impact of incidents that can impact MCC Information Resources.

Scope and Roles

This policy applies to information resources owned or managed by MCC. The intended audience includes the Cybersecurity Manager, Information Resource Owners and Custodians.

Compliance

Audit and Accountability controls are implemented to ensure compliance with the Texas Department of Information Resources (DIR) Security Control Standards Catalog as required by Title 1 Texas Administrative Code §202.76.

Implementation

The Cybersecurity Manager or their designee is responsible for ensuring that this policy and supporting procedures are periodically reviewed and updated.

Last updated: 5/13/2026

Contact Hours or Questions?