Audit GPO edits


I am running in a DFL and FFL of Windows 2003 native mode. All of My DC's except one are running Windows 2008 sp2, the other DC is running Windows 2003 sp2. I understand some of the new auditing features of Windows 2008, I know that I will have to turn on auditing of directory service access to capture GPO creation or edits, but what else will I have to enable in order to audit someone creating a new GPO or editing an existing GPO?