Skip to content

Evidence request lists

NIST SP 1800-32

Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Detect

DER-DE-01
Continuous Monitoring of DER Communications

Continuously monitor DER communications and operations to detect anomalies, unauthorized commands, or unexpected setpoint changes.

Artefacts an auditor will ask for
  • monitoring tool configuration (OT-aware IDS or NSM)
  • baseline behavior profiles
  • alert rules for unauthorized commands
  • setpoint change audit logs
  • anomaly investigation reports
Where this commonly fails
  • no OT-aware monitoring deployed
  • alerts not tuned to DER behavior
  • setpoint changes not audited
DER-DE-02
Logging and Audit Trail Collection

Collect and centralize logs from DER devices, gateways, aggregators, and utility systems for security analysis and forensics.

Artefacts an auditor will ask for
  • log collection architecture
  • log source coverage matrix
  • retention policy
  • log integrity controls
  • SIEM use case catalog for DER
Where this commonly fails
  • devices lack logging capability or capacity
  • logs not centralized due to bandwidth
  • retention shorter than incident detection cycle
DER-DE-03
Integrity Monitoring of DER Settings

Monitor the integrity of DER device settings, control logic, and configuration files to detect unauthorized changes.

Artefacts an auditor will ask for
  • configuration baselines per device class
  • hash or signature monitoring tool configuration
  • change detection alert rules
  • investigation procedure for unauthorized changes
Where this commonly fails
  • configurations not baselined
  • no automated drift detection
  • manual reviews instead of continuous monitoring

Governance

DER-GV-01
DER Cybersecurity Governance

Establish governance structures for DER cybersecurity that span utility operations, IT, OT, regulatory affairs, and third-party aggregators.

Artefacts an auditor will ask for
  • DER cybersecurity governance charter
  • cross-functional committee minutes
  • third-party oversight procedures
  • executive reporting cadence documentation
Where this commonly fails
  • DER cybersecurity siloed within IT or OT only
  • no formal committee
  • third-party aggregators not held to documented requirements
DER-GV-02
Supply Chain Risk Management for DER

Manage supply chain risk for DER components, including vendor risk assessments, contract requirements, and ongoing monitoring of vendor security postures.

Artefacts an auditor will ask for
  • vendor risk assessment results
  • contract clauses for DER vendors
  • software bill of materials where available
  • ongoing vendor monitoring records
  • vendor incident notification procedures
Where this commonly fails
  • no SBOM for DER firmware
  • vendor contracts lack security requirements
  • no ongoing monitoring of vendor advisories

Identify

DER-ID-01
DER Asset Inventory

Maintain an inventory of Distributed Energy Resources (DER) assets, including solar inverters, battery systems, smart meters, gateways, and supporting communication equipment.

Artefacts an auditor will ask for
  • DER asset inventory register
  • site topology diagrams
  • communication equipment inventory
  • firmware version baselines
  • vendor and model documentation
Where this commonly fails
  • customer-sited DER not inventoried by utility
  • firmware versions not tracked centrally
  • communication gateways missing from inventory
DER-ID-02
Data Flow Mapping for DER

Map the data flows between DER assets, aggregators, distribution operators, and grid operators, including command and telemetry channels.

Artefacts an auditor will ask for
  • DER data flow diagrams
  • protocol inventory (IEEE 2030.5, DNP3, Modbus, OpenADR)
  • interconnection point documentation
  • third-party aggregator data sharing documentation
Where this commonly fails
  • protocols not documented at the message level
  • aggregator-to-utility flows undocumented
  • telemetry retention not specified
DER-ID-03
DER Threat and Risk Assessment

Conduct threat and risk assessments specific to DER deployments, considering grid stability impacts, safety impacts, and cyber-physical attack scenarios.

Artefacts an auditor will ask for
  • DER threat model
  • risk register with grid impact ratings
  • attack tree analyses
  • scenario library covering false data injection and unauthorized commands
Where this commonly fails
  • threat model treats DER as standard IT asset
  • no grid impact severity scale
  • cyber-physical scenarios omitted

NIST SP 1800-32: Access Management

NIST1800-32-06
Physical and logical access controls

Physical and logical access controls. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.

Artefacts an auditor will ask for
  • Physical and logical access matrix for OT zones
  • Electronic access perimeter device configurations
  • Interactive remote access approval and session logs
  • Personnel risk assessment outcomes for OT staff
Where this commonly fails
  • Shared engineering credentials remain in use
  • Remote access lacks two-factor or session recording
  • Vendor maintenance access without time-boxed approvals
  • Personnel risk reassessment skipped during role changes
NIST1800-32-07
Personnel risk assessment

Personnel risk assessment. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.

Artefacts an auditor will ask for
  • Physical and logical access matrix for OT zones
  • Electronic access perimeter device configurations
  • Interactive remote access approval and session logs
  • Personnel risk assessment outcomes for OT staff
Where this commonly fails
  • Shared engineering credentials remain in use
  • Remote access lacks two-factor or session recording
  • Vendor maintenance access without time-boxed approvals
  • Personnel risk reassessment skipped during role changes
NIST1800-32-08
Electronic access perimeter management

Electronic access perimeter management. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.

Artefacts an auditor will ask for
  • Physical and logical access matrix for OT zones
  • Electronic access perimeter device configurations
  • Interactive remote access approval and session logs
  • Personnel risk assessment outcomes for OT staff
Where this commonly fails
  • Shared engineering credentials remain in use
  • Remote access lacks two-factor or session recording
  • Vendor maintenance access without time-boxed approvals
  • Personnel risk reassessment skipped during role changes
NIST1800-32-09
Interactive remote access security

Interactive remote access security. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.

Artefacts an auditor will ask for
  • Physical and logical access matrix for OT zones
  • Electronic access perimeter device configurations
  • Interactive remote access approval and session logs
  • Personnel risk assessment outcomes for OT staff
Where this commonly fails
  • Shared engineering credentials remain in use
  • Remote access lacks two-factor or session recording
  • Vendor maintenance access without time-boxed approvals
  • Personnel risk reassessment skipped during role changes
NIST1800-32-10
Revocation of access procedures

Revocation of access procedures. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.

Artefacts an auditor will ask for
  • Physical and logical access matrix for OT zones
  • Electronic access perimeter device configurations
  • Interactive remote access approval and session logs
  • Personnel risk assessment outcomes for OT staff
Where this commonly fails
  • Shared engineering credentials remain in use
  • Remote access lacks two-factor or session recording
  • Vendor maintenance access without time-boxed approvals
  • Personnel risk reassessment skipped during role changes

NIST SP 1800-32: Asset Identification & Governance

NIST1800-32-01
Critical asset identification and inventory

Critical asset identification and inventory. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Operational technology asset inventory with criticality tags
  • System security categorisation worksheet for OT assets
  • OT security governance charter and steering minutes
  • Roles and responsibilities for OT cyber-physical systems
Where this commonly fails
  • Inventory captures IT assets only, omits PLCs and RTUs
  • Categorisation does not reflect safety impact ratings
  • Governance forum lacks engineering or operations attendance
  • OT-specific security policy missing or copied from IT
NIST1800-32-02
System security categorization

System security categorization. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Operational technology asset inventory with criticality tags
  • System security categorisation worksheet for OT assets
  • OT security governance charter and steering minutes
  • Roles and responsibilities for OT cyber-physical systems
Where this commonly fails
  • Inventory captures IT assets only, omits PLCs and RTUs
  • Categorisation does not reflect safety impact ratings
  • Governance forum lacks engineering or operations attendance
  • OT-specific security policy missing or copied from IT
NIST1800-32-03
Security governance structure

Security governance structure. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Operational technology asset inventory with criticality tags
  • System security categorisation worksheet for OT assets
  • OT security governance charter and steering minutes
  • Roles and responsibilities for OT cyber-physical systems
Where this commonly fails
  • Inventory captures IT assets only, omits PLCs and RTUs
  • Categorisation does not reflect safety impact ratings
  • Governance forum lacks engineering or operations attendance
  • OT-specific security policy missing or copied from IT
NIST1800-32-04
Roles and responsibilities for critical systems

Roles and responsibilities for critical systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Operational technology asset inventory with criticality tags
  • System security categorisation worksheet for OT assets
  • OT security governance charter and steering minutes
  • Roles and responsibilities for OT cyber-physical systems
Where this commonly fails
  • Inventory captures IT assets only, omits PLCs and RTUs
  • Categorisation does not reflect safety impact ratings
  • Governance forum lacks engineering or operations attendance
  • OT-specific security policy missing or copied from IT
NIST1800-32-05
Security policy for operational technology

Security policy for operational technology. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Operational technology asset inventory with criticality tags
  • System security categorisation worksheet for OT assets
  • OT security governance charter and steering minutes
  • Roles and responsibilities for OT cyber-physical systems
Where this commonly fails
  • Inventory captures IT assets only, omits PLCs and RTUs
  • Categorisation does not reflect safety impact ratings
  • Governance forum lacks engineering or operations attendance
  • OT-specific security policy missing or copied from IT

NIST SP 1800-32: Incident Response & Recovery

NIST1800-32-16
Incident response plan for operational disruptions

Incident response plan for operational disruptions. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT-specific incident response plan with safety triggers
  • Recovery plan including manual operations fallback
  • Reporting evidence to sector regulators
  • Exercise records for blended IT/OT scenarios
Where this commonly fails
  • Response plan untested with engineering on-call rotation
  • Recovery time objectives lack safety case validation
  • Reporting channels to sector ISACs unconfirmed
  • Exercises focus on IT scenarios without process impact
NIST1800-32-17
Recovery plan for critical systems

Recovery plan for critical systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT-specific incident response plan with safety triggers
  • Recovery plan including manual operations fallback
  • Reporting evidence to sector regulators
  • Exercise records for blended IT/OT scenarios
Where this commonly fails
  • Response plan untested with engineering on-call rotation
  • Recovery time objectives lack safety case validation
  • Reporting channels to sector ISACs unconfirmed
  • Exercises focus on IT scenarios without process impact
NIST1800-32-18
Reporting obligations to authorities

Reporting obligations to authorities. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT-specific incident response plan with safety triggers
  • Recovery plan including manual operations fallback
  • Reporting evidence to sector regulators
  • Exercise records for blended IT/OT scenarios
Where this commonly fails
  • Response plan untested with engineering on-call rotation
  • Recovery time objectives lack safety case validation
  • Reporting channels to sector ISACs unconfirmed
  • Exercises focus on IT scenarios without process impact
NIST1800-32-19
Coordination with sector-specific agencies

Coordination with sector-specific agencies. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT-specific incident response plan with safety triggers
  • Recovery plan including manual operations fallback
  • Reporting evidence to sector regulators
  • Exercise records for blended IT/OT scenarios
Where this commonly fails
  • Response plan untested with engineering on-call rotation
  • Recovery time objectives lack safety case validation
  • Reporting channels to sector ISACs unconfirmed
  • Exercises focus on IT scenarios without process impact
NIST1800-32-20
Exercises and drills for OT incidents

Exercises and drills for OT incidents. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT-specific incident response plan with safety triggers
  • Recovery plan including manual operations fallback
  • Reporting evidence to sector regulators
  • Exercise records for blended IT/OT scenarios
Where this commonly fails
  • Response plan untested with engineering on-call rotation
  • Recovery time objectives lack safety case validation
  • Reporting channels to sector ISACs unconfirmed
  • Exercises focus on IT scenarios without process impact

NIST SP 1800-32: Supply Chain & Configuration

NIST1800-32-21
Supply chain risk management for critical components

Supply chain risk management for critical components. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supply chain risk register for critical OT components
  • Configuration management database for OT assets
  • Change management approvals for OT modifications
  • Vulnerability assessment reports with operational impact
Where this commonly fails
  • Component obsolescence not tracked against vendor roadmaps
  • Configuration baselines not version controlled
  • Emergency changes bypass risk assessment steps
  • Vulnerability findings lack OT-aware compensating controls
NIST1800-32-22
Configuration management for OT systems

Configuration management for OT systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supply chain risk register for critical OT components
  • Configuration management database for OT assets
  • Change management approvals for OT modifications
  • Vulnerability assessment reports with operational impact
Where this commonly fails
  • Component obsolescence not tracked against vendor roadmaps
  • Configuration baselines not version controlled
  • Emergency changes bypass risk assessment steps
  • Vulnerability findings lack OT-aware compensating controls
NIST1800-32-23
Change management procedures

Change management procedures. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supply chain risk register for critical OT components
  • Configuration management database for OT assets
  • Change management approvals for OT modifications
  • Vulnerability assessment reports with operational impact
Where this commonly fails
  • Component obsolescence not tracked against vendor roadmaps
  • Configuration baselines not version controlled
  • Emergency changes bypass risk assessment steps
  • Vulnerability findings lack OT-aware compensating controls
NIST1800-32-24
Vulnerability assessment for critical systems

Vulnerability assessment for critical systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supply chain risk register for critical OT components
  • Configuration management database for OT assets
  • Change management approvals for OT modifications
  • Vulnerability assessment reports with operational impact
Where this commonly fails
  • Component obsolescence not tracked against vendor roadmaps
  • Configuration baselines not version controlled
  • Emergency changes bypass risk assessment steps
  • Vulnerability findings lack OT-aware compensating controls

NIST SP 1800-32: Systems Security

NIST1800-32-11
Security patch management for OT

Security patch management for OT. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.

Artefacts an auditor will ask for
  • Patch management runbook with maintenance windows
  • Network monitoring deployment with OT protocol awareness
  • Hardening configuration baseline per device class
  • Allow-list inventory for ports and services on OT assets
Where this commonly fails
  • Patches deferred indefinitely citing vendor support
  • Monitoring lacks visibility into serial or proprietary buses
  • Hardening baseline not validated after firmware updates
  • Unused services remain enabled on legacy controllers
NIST1800-32-12
Malware prevention for operational systems

Malware prevention for operational systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.

Artefacts an auditor will ask for
  • Patch management runbook with maintenance windows
  • Network monitoring deployment with OT protocol awareness
  • Hardening configuration baseline per device class
  • Allow-list inventory for ports and services on OT assets
Where this commonly fails
  • Patches deferred indefinitely citing vendor support
  • Monitoring lacks visibility into serial or proprietary buses
  • Hardening baseline not validated after firmware updates
  • Unused services remain enabled on legacy controllers
NIST1800-32-13
Network security monitoring

Network security monitoring. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.

Artefacts an auditor will ask for
  • Patch management runbook with maintenance windows
  • Network monitoring deployment with OT protocol awareness
  • Hardening configuration baseline per device class
  • Allow-list inventory for ports and services on OT assets
Where this commonly fails
  • Patches deferred indefinitely citing vendor support
  • Monitoring lacks visibility into serial or proprietary buses
  • Hardening baseline not validated after firmware updates
  • Unused services remain enabled on legacy controllers
NIST1800-32-14
System security hardening

System security hardening. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.

Artefacts an auditor will ask for
  • Patch management runbook with maintenance windows
  • Network monitoring deployment with OT protocol awareness
  • Hardening configuration baseline per device class
  • Allow-list inventory for ports and services on OT assets
Where this commonly fails
  • Patches deferred indefinitely citing vendor support
  • Monitoring lacks visibility into serial or proprietary buses
  • Hardening baseline not validated after firmware updates
  • Unused services remain enabled on legacy controllers
NIST1800-32-15
Ports and services management

Ports and services management. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.

Artefacts an auditor will ask for
  • Patch management runbook with maintenance windows
  • Network monitoring deployment with OT protocol awareness
  • Hardening configuration baseline per device class
  • Allow-list inventory for ports and services on OT assets
Where this commonly fails
  • Patches deferred indefinitely citing vendor support
  • Monitoring lacks visibility into serial or proprietary buses
  • Hardening baseline not validated after firmware updates
  • Unused services remain enabled on legacy controllers

Protect

DER-PR-01
Authentication for DER Communications

Authenticate all communications between DER assets, aggregators, and utility systems using certificate-based or equivalent strong authentication mechanisms.

Artefacts an auditor will ask for
  • certificate issuance procedures for DER assets
  • PKI hierarchy diagram
  • mutual TLS configuration on aggregator and utility endpoints
  • certificate revocation procedure
  • device enrollment records
Where this commonly fails
  • shared symmetric keys still in use
  • no certificate revocation tested
  • device enrollment relies on default credentials
DER-PR-02
Secure Configuration of DER Devices

Apply secure configuration baselines to DER devices, including disabling unused services, removing default credentials, and enabling secure protocols only.

Artefacts an auditor will ask for
  • DER hardening baseline documents
  • configuration audit reports
  • default credential removal evidence
  • service inventory per device class
  • configuration drift detection results
Where this commonly fails
  • vendor default credentials remain on field devices
  • hardening baseline not enforced post-deployment
  • telnet or HTTP still enabled on legacy gateways
DER-PR-03
Network Segmentation for DER Operations

Segment DER operational networks from corporate IT networks and from public networks using firewalls, VLANs, and access control lists.

Artefacts an auditor will ask for
  • network segmentation diagrams
  • firewall rulesets between zones
  • VLAN configuration
  • data diode design where applicable
  • zone-conduit model documentation
Where this commonly fails
  • flat network with DER on corporate VLAN
  • firewall rules overly permissive
  • no enforced separation between aggregator and utility zones
DER-PR-04
Cryptographic Protection of DER Communications

Apply cryptographic protections to DER communications including confidentiality and integrity of commands, settings, and telemetry.

Artefacts an auditor will ask for
  • protocol-level encryption configuration (TLS, IPsec)
  • integrity check mechanism documentation
  • cipher suite policy
  • key rotation procedures
Where this commonly fails
  • plaintext Modbus or DNP3 still in use
  • TLS versions outdated
  • no key rotation policy for embedded devices
DER-PR-05
Identity and Access Management for DER Operators

Manage operator and administrator access to DER management systems with role-based access controls and multi-factor authentication.

Artefacts an auditor will ask for
  • role catalog and permission mapping
  • MFA enforcement evidence for operator consoles
  • access review reports
  • privileged access management logs
  • joiner-mover-leaver records for DER operators
Where this commonly fails
  • shared operator accounts on SCADA HMIs
  • MFA bypassed via local consoles
  • access reviews missed for DER systems
DER-PR-06
Secure Firmware Update Process

Implement a secure firmware update process for DER devices that verifies authenticity and integrity of firmware images before installation.

Artefacts an auditor will ask for
  • firmware signing key management procedure
  • update verification procedure
  • firmware update logs
  • rollback capability documentation
  • vendor signing chain validation
Where this commonly fails
  • firmware images not validated cryptographically
  • no rollback procedure for failed updates
  • vendor signing keys not pinned

Recover

DER-RC-01
Recovery Planning for DER

Develop recovery plans for DER incidents that restore normal operations and verify integrity of devices and configurations before reconnection.

Artefacts an auditor will ask for
  • DER recovery plan
  • configuration restoration procedures
  • device re-onboarding checklist
  • integrity verification procedure post-recovery
  • recovery time objective documentation
Where this commonly fails
  • recovery focused only on availability, not integrity
  • no re-onboarding checklist
  • RTO not defined for DER classes
DER-RC-02
Backup and Configuration Restoration

Maintain backups of DER device configurations, control logic, and supporting system data to enable timely recovery.

Artefacts an auditor will ask for
  • backup procedures and schedules
  • configuration version control
  • restoration test reports
  • secure backup storage documentation
Where this commonly fails
  • device configurations not backed up
  • restoration never tested
  • backups stored on same network as production
DER-RC-03
Lessons Learned and Continuous Improvement

Capture lessons learned from DER security incidents and feed them into program improvements, training, and updated procedures.

Artefacts an auditor will ask for
  • post-incident review reports
  • lessons learned register
  • training updates based on incidents
  • shared learnings with industry information sharing bodies
Where this commonly fails
  • lessons learned recorded but not implemented
  • no sharing with E-ISAC or peer utilities
  • training content not updated post-incident

Respond

DER-RS-01
Incident Response for DER

Maintain incident response procedures specific to DER, including coordination with utility operations centers, aggregators, and emergency response authorities.

Artefacts an auditor will ask for
  • DER-specific incident response plan
  • coordination procedures with aggregators and operations centers
  • tabletop exercise reports
  • communication templates for grid operators
  • regulatory notification procedure
Where this commonly fails
  • IR plan ignores OT and grid stability constraints
  • no tested coordination with aggregators
  • regulatory notification timing unclear
DER-RS-02
Isolation and Containment Procedures

Define isolation and containment procedures for compromised DER assets that balance security response with grid stability and safety requirements.

Artefacts an auditor will ask for
  • containment playbooks for compromised DER scenarios
  • safe-state procedures for affected devices
  • decision authority matrix during incidents
  • post-incident analysis of containment actions
Where this commonly fails
  • isolation procedures may destabilize grid if executed blindly
  • no documented decision authority for isolation calls
  • safe-state procedures not tested
DER-RS-03
Communication with External Stakeholders

Communicate effectively with regulators, customers, aggregators, and vendors during DER security incidents.

Artefacts an auditor will ask for
  • external communication plan
  • regulator contact list
  • customer notification templates
  • vendor escalation contacts
  • press and public communication policy
Where this commonly fails
  • no pre-approved templates for customer or regulator notification
  • vendor escalation contacts outdated
  • media response strategy missing
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 1800-32 framework page.