NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Execution Phase
Execute Section 7 execution phase including: discovery phase (network mapping + system fingerprinting + vulnerability identification) + attack phase (Gaining Access + Escalating Privileges + System Browsing + Installing Additional Tools + Loss of Confidentiality demonstration + Loss of Integrity demonstration + Loss of Availability test) + reporting phase (factual findings + business impact analysis + risk-based prioritisation + recommendations + remediation guidance + executive summary + technical detail). Maintain audit trail of all activities + chain of custody for evidence.
- Discovery findings
- Attack chain documentation
- Final assessment report
- Executive summary
- Technical detail report
- Activity audit trail
- Evidence chain of custody
- No discovery report
- No attack chain documentation
- Missing executive summary
- No audit trail
Operations Support
Apply Appendix A operational considerations including: assessment tool ecosystem (Kali Linux + Metasploit + Nmap + Wireshark + Burp Suite + OWASP ZAP + custom scripts) + tool validation and configuration management + report templates and content standards + integration with information security management system (ISMS) per ISO/IEC 27001 + integration with broader security assessment per NIST SP 800-53A + supporting controls covering governance + access management + crypto + operations + network + transfer + cross-walk with SP 800-171 3.14.7 for vulnerability scanning. Maintain testing programme + scheduling + tracking + reporting cadence + executive visibility.
- Tool inventory + configuration
- Report templates
- ISMS integration evidence
- Cross-walk with SP 800-53A + 800-171
- Annual assessment programme review
- No tool inventory
- Inconsistent reports
- Disconnected from ISMS
- No cross-walk
Planning
Apply NIST SP 800-115 Technical Guide to Information Security Testing and Assessment published September 2008 + still operative for security testing methodology + complement to NIST SP 800-53A + NIST SP 800-30. Define assessment scope + objectives + roles and responsibilities + rules of engagement (RoE) per Section 2 and Section 3.1 including type of testing (review + identification + validation) + targets + boundaries + sensitivity + impact assessment + escalation procedures + assessment plan documentation. Coordinate with risk management framework + system owner + system security officer + ISSO + CISO + authorising official.
- Assessment plan
- Rules of Engagement
- Roles and responsibilities matrix
- Authorising official sign-off
- Annual review
- No assessment plan
- Missing RoE
- Unclear roles
- No AO sign-off
Planning Phase Operations
Implement Section 6 planning phase operations including: development of legal documentation (statement of work + non-disclosure agreement + indemnification + insurance + liability + data handling agreements per state and federal law) + logistical coordination (timing windows + business hours considerations + change freeze respect + critical period avoidance + backup verification before assessment) + system owner notification + ITSM coordination + tooling preparation (assessment platform + isolated network + secure communications + encrypted storage of artifacts).
- SoW + NDA + indemnification
- Timing windows + change freeze coordination
- System owner notification
- Tooling inventory
- Secure artifact storage
- Missing legal docs
- No business coordination
- Inadequate tooling
- No secure storage
Post-Test Phase
Conduct Section 8 post-test activities: remediation tracking + verification of mitigations + re-testing (targeted scope re-assessment after remediation) + lessons learned documentation + assessment programme improvement + integration with continuous monitoring per NIST SP 800-137 + NIST SP 800-53 CM family + NIST SP 800-53A automated assessment + IDS/IPS rule tuning based on findings + vulnerability management programme integration per NIST SP 800-40.
- Remediation tracker
- Mitigation verification
- Re-test report
- Lessons learned
- Continuous monitoring integration
- Programme improvement plan
- No remediation tracking
- No re-testing
- No lessons learned
- No continuous monitoring
Review Techniques
Apply Section 3 review techniques: documentation review (security policies + procedures + plans + system documentation + diagrams) + log review (security event logs + system logs + audit logs + change management logs) + ruleset review (firewall rules + IDS rules + ACLs) + system configuration review (hardening compliance + secure baselines + configuration files) + network sniffing (when authorised + observing traffic patterns + protocol use) + file integrity checking (HIDS + checksums + signatures).
- Documentation review findings
- Log analysis reports
- Ruleset audit
- Configuration compliance reports
- Network sniffing logs (where authorised)
- Integrity check results
- No documentation review
- Missing log analysis
- No ruleset audit
- Weak configuration review
Target Identification
Apply Section 4 target identification and analysis techniques: network discovery using passive (DNS lookups + interrogation of databases + WHOIS + Shodan) + active (port scans + ping sweeps + ICMP + traceroute) + network port and service identification (TCP/UDP scanning + service version detection + banner grabbing) + vulnerability scanning (Nessus + OpenVAS + Qualys + Rapid7 + Tenable) + wireless scanning (rogue AP detection + signal strength mapping + war driving for authorised assessments).
- Network discovery report
- Port and service inventory
- Vulnerability scan reports
- Wireless assessment report
- Tool inventory and configuration
- Incomplete discovery
- Missing vuln scanning
- No wireless assessment
- Unauthorised scanning
Vulnerability Validation
Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + attack + reporting phases with exploitation + post-exploitation + privilege escalation + lateral movement) + social engineering (Section 5.4 covering phishing + vishing + pretexting + physical impersonation only per explicit RoE + Federal Trade Commission Section 5 risk evaluation).
- Password cracking results (within RoE)
- Penetration test report
- Social engineering test report (per RoE)
- Exploitation evidence
- Privilege escalation analysis
- Out-of-scope testing
- No pen test
- Social engineering without authorisation
- Missing post-exploitation
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) framework page.