Skip to content

Evidence request lists

NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Execution Phase

NISTSP115-6
Execution Phase - Discovery, Attack, and Reporting

Execute Section 7 execution phase including: discovery phase (network mapping + system fingerprinting + vulnerability identification) + attack phase (Gaining Access + Escalating Privileges + System Browsing + Installing Additional Tools + Loss of Confidentiality demonstration + Loss of Integrity demonstration + Loss of Availability test) + reporting phase (factual findings + business impact analysis + risk-based prioritisation + recommendations + remediation guidance + executive summary + technical detail). Maintain audit trail of all activities + chain of custody for evidence.

Artefacts an auditor will ask for
  • Discovery findings
  • Attack chain documentation
  • Final assessment report
  • Executive summary
  • Technical detail report
  • Activity audit trail
  • Evidence chain of custody
Where this commonly fails
  • No discovery report
  • No attack chain documentation
  • Missing executive summary
  • No audit trail

Operations Support

NISTSP115-8
Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

Apply Appendix A operational considerations including: assessment tool ecosystem (Kali Linux + Metasploit + Nmap + Wireshark + Burp Suite + OWASP ZAP + custom scripts) + tool validation and configuration management + report templates and content standards + integration with information security management system (ISMS) per ISO/IEC 27001 + integration with broader security assessment per NIST SP 800-53A + supporting controls covering governance + access management + crypto + operations + network + transfer + cross-walk with SP 800-171 3.14.7 for vulnerability scanning. Maintain testing programme + scheduling + tracking + reporting cadence + executive visibility.

Artefacts an auditor will ask for
  • Tool inventory + configuration
  • Report templates
  • ISMS integration evidence
  • Cross-walk with SP 800-53A + 800-171
  • Annual assessment programme review
Where this commonly fails
  • No tool inventory
  • Inconsistent reports
  • Disconnected from ISMS
  • No cross-walk

Planning

NISTSP115-1
Scope, Methodology, and Assessment Planning

Apply NIST SP 800-115 Technical Guide to Information Security Testing and Assessment published September 2008 + still operative for security testing methodology + complement to NIST SP 800-53A + NIST SP 800-30. Define assessment scope + objectives + roles and responsibilities + rules of engagement (RoE) per Section 2 and Section 3.1 including type of testing (review + identification + validation) + targets + boundaries + sensitivity + impact assessment + escalation procedures + assessment plan documentation. Coordinate with risk management framework + system owner + system security officer + ISSO + CISO + authorising official.

Artefacts an auditor will ask for
  • Assessment plan
  • Rules of Engagement
  • Roles and responsibilities matrix
  • Authorising official sign-off
  • Annual review
Where this commonly fails
  • No assessment plan
  • Missing RoE
  • Unclear roles
  • No AO sign-off

Planning Phase Operations

NISTSP115-5
Planning Phase - Engagement Coordination and Logistics

Implement Section 6 planning phase operations including: development of legal documentation (statement of work + non-disclosure agreement + indemnification + insurance + liability + data handling agreements per state and federal law) + logistical coordination (timing windows + business hours considerations + change freeze respect + critical period avoidance + backup verification before assessment) + system owner notification + ITSM coordination + tooling preparation (assessment platform + isolated network + secure communications + encrypted storage of artifacts).

Artefacts an auditor will ask for
  • SoW + NDA + indemnification
  • Timing windows + change freeze coordination
  • System owner notification
  • Tooling inventory
  • Secure artifact storage
Where this commonly fails
  • Missing legal docs
  • No business coordination
  • Inadequate tooling
  • No secure storage

Post-Test Phase

NISTSP115-7
Post-Test Activities - Remediation, Mitigation, and Re-testing

Conduct Section 8 post-test activities: remediation tracking + verification of mitigations + re-testing (targeted scope re-assessment after remediation) + lessons learned documentation + assessment programme improvement + integration with continuous monitoring per NIST SP 800-137 + NIST SP 800-53 CM family + NIST SP 800-53A automated assessment + IDS/IPS rule tuning based on findings + vulnerability management programme integration per NIST SP 800-40.

Artefacts an auditor will ask for
  • Remediation tracker
  • Mitigation verification
  • Re-test report
  • Lessons learned
  • Continuous monitoring integration
  • Programme improvement plan
Where this commonly fails
  • No remediation tracking
  • No re-testing
  • No lessons learned
  • No continuous monitoring

Review Techniques

NISTSP115-2
Review Techniques - Documentation, Logs, Rulesets, Configurations

Apply Section 3 review techniques: documentation review (security policies + procedures + plans + system documentation + diagrams) + log review (security event logs + system logs + audit logs + change management logs) + ruleset review (firewall rules + IDS rules + ACLs) + system configuration review (hardening compliance + secure baselines + configuration files) + network sniffing (when authorised + observing traffic patterns + protocol use) + file integrity checking (HIDS + checksums + signatures).

Artefacts an auditor will ask for
  • Documentation review findings
  • Log analysis reports
  • Ruleset audit
  • Configuration compliance reports
  • Network sniffing logs (where authorised)
  • Integrity check results
Where this commonly fails
  • No documentation review
  • Missing log analysis
  • No ruleset audit
  • Weak configuration review

Target Identification

NISTSP115-3
Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning

Apply Section 4 target identification and analysis techniques: network discovery using passive (DNS lookups + interrogation of databases + WHOIS + Shodan) + active (port scans + ping sweeps + ICMP + traceroute) + network port and service identification (TCP/UDP scanning + service version detection + banner grabbing) + vulnerability scanning (Nessus + OpenVAS + Qualys + Rapid7 + Tenable) + wireless scanning (rogue AP detection + signal strength mapping + war driving for authorised assessments).

Artefacts an auditor will ask for
  • Network discovery report
  • Port and service inventory
  • Vulnerability scan reports
  • Wireless assessment report
  • Tool inventory and configuration
Where this commonly fails
  • Incomplete discovery
  • Missing vuln scanning
  • No wireless assessment
  • Unauthorised scanning

Vulnerability Validation

NISTSP115-4
Target Vulnerability Validation - Password Cracking, Pen Testing, Social Engineering

Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + attack + reporting phases with exploitation + post-exploitation + privilege escalation + lateral movement) + social engineering (Section 5.4 covering phishing + vishing + pretexting + physical impersonation only per explicit RoE + Federal Trade Commission Section 5 risk evaluation).

Artefacts an auditor will ask for
  • Password cracking results (within RoE)
  • Penetration test report
  • Social engineering test report (per RoE)
  • Exploitation evidence
  • Privilege escalation analysis
Where this commonly fails
  • Out-of-scope testing
  • No pen test
  • Social engineering without authorisation
  • Missing post-exploitation
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) framework page.