Skip to content

Evidence request lists

NIST SP 800-123

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Authentication and Access

NISTSP123-3
Authentication, Access Control, and Account Management

Implement Section 5.1-5.2 authentication and access control including: strong authentication per NIST SP 800-63 (AAL2 minimum for sensitive systems + MFA where appropriate + risk-based authentication) + identity management + role-based access control (RBAC) per NIST SP 800-178 + attribute-based access control (ABAC) per NIST SP 800-162 + privileged access management (PAM) with session recording + just-in-time access + access reviews quarterly + account lifecycle management. Implement least privilege + separation of duties + need-to-know principles.

Artefacts an auditor will ask for
  • MFA deployment
  • RBAC/ABAC matrices
  • PAM with session recording
  • Quarterly access reviews
  • Account lifecycle records
Where this commonly fails
  • Weak authentication
  • No PAM
  • No quarterly reviews
  • Missing MFA

Cryptography

NISTSP123-4
Server Cryptography - Encryption, Key Management, Certificates

Apply Section 5.3 cryptography including: encryption of data at rest (AES-256 + FIPS 140-3 validated modules + full disk encryption + file-level encryption + database encryption) + data in transit (TLS 1.3 + IPsec + SSH 2.0 + S/MIME + PGP) + key management per NIST SP 800-57 + NIST SP 800-152 + key lifecycle (generation + storage + distribution + rotation + revocation + escrow + destruction) + certificate management (X.509 + ACME + Let's Encrypt + DigiCert + private CA) + Post-Quantum Cryptography migration per FIPS 203/204/205 (ML-KEM + ML-DSA + SLH-DSA).

Artefacts an auditor will ask for
  • Encryption inventory
  • FIPS 140-3 validated modules
  • Key management procedures
  • Certificate inventory
  • PQC migration plan
Where this commonly fails
  • Weak encryption
  • No key management
  • Expired certificates
  • No PQC plan

Governance and ISMS

NISTSP123-8
Governance, Policies, and ISMS Integration

Establish governance per supporting controls including: information security policy framework + management direction and commitment + policy review and update procedures + roles and responsibilities (CISO + Server Administrator + System Owner + System Security Officer + Privileged User) + contact with authorities and special interest groups (CISA + FBI + ISACs + ISAOs) + integration with information security management system (ISMS) per ISO/IEC 27001 + Annex A controls + Information classification and labeling + asset inventory + acceptable use policies + audit considerations + administrative + technical + physical controls coverage.

Artefacts an auditor will ask for
  • Security policies
  • Roles matrix
  • Authority contact register
  • ISMS integration
  • Asset inventory
  • Annual review
Where this commonly fails
  • Outdated policies
  • Unclear roles
  • No authority contacts
  • Disconnected from ISMS

IR and Decommissioning

NISTSP123-7
Incident Response and Server Decommissioning

Implement Section 7.1 incident response for servers per NIST SP 800-61 covering preparation + detection + analysis + containment + eradication + recovery + post-incident review + coordination with CSIRT + US-CERT + CISA + Cyber Threat Intelligence (CTI) sharing per STIX/TAXII. Apply Section 7.2 server decommissioning including: data sanitisation per NIST SP 800-88 (clear + purge + destroy based on confidentiality categorisation) + media handling + secure disposal + asset removal from inventory + license recovery + DR plan updates + documentation. Maintain chain of custody for evidence and asset disposal.

Artefacts an auditor will ask for
  • IR plan
  • NIST SP 800-88 sanitisation
  • Chain of custody
  • Decommissioning checklist
  • CTI sharing
Where this commonly fails
  • No IR plan
  • Improper sanitisation
  • No chain of custody
  • Missing CTI

Installation and Configuration

NISTSP123-2
Secure Server Installation and Configuration

Apply Section 3 secure installation including: server selection per organizational requirements + OS hardening per CIS Benchmarks + DISA STIGs + NSA SecGuide + vendor security guides (Microsoft + Red Hat + SUSE + Ubuntu + macOS) + remove unnecessary services + features + components + install only required software + apply security patches + enable secure default settings + disable default accounts + change default passwords. Configure per Section 4 secure baselines including: enable secure boot + UEFI + TPM 2.0 + disk encryption (BitLocker + LUKS + FileVault) + secure SSH/RDP + restrict remote management + audit log configuration + firewall enabled + IDS/IPS enabled where applicable.

Artefacts an auditor will ask for
  • CIS Benchmark compliance
  • STIG compliance
  • Patch tracking
  • Secure boot enabled
  • Configuration baselines
  • Annual audit
Where this commonly fails
  • No CIS/STIG
  • Missing patches
  • No secure boot
  • Default credentials

Network Security

NISTSP123-6
Network Security and Server Communications

Apply Section 6.3 network security including: network segmentation per NIST SP 800-207 Zero Trust + microsegmentation + DMZ + jump servers + bastion hosts + perimeter firewalls + host-based firewalls + IDS/IPS + DDoS protection + DNS security (DNSSEC + DoH) + secure email (SPF + DKIM + DMARC + ARC + BIMI) + secure file transfer (SFTP + FTPS + SCP) + secure remote access (VPN + IPsec + SD-WAN + zero trust network access ZTNA) + network monitoring + traffic analysis + flow records (NetFlow + sFlow + IPFIX).

Artefacts an auditor will ask for
  • Network architecture
  • ZTNA deployment
  • SPF/DKIM/DMARC
  • Bastion hosts
  • NetFlow monitoring
Where this commonly fails
  • Flat networks
  • No ZTNA
  • Missing email auth
  • Insecure remote access

Operations

NISTSP123-5
Server Operations - Patching, Malware, Logging, Backup

Apply Section 6.1-6.2 server operations including: vulnerability and patch management per NIST SP 800-40 (Critical 7 days + High 30 days + Medium 90 days + scheduled monthly + automatic patching where appropriate) + malware prevention (signature-based antivirus + EDR + XDR + EDR-NG + sandboxing + application whitelisting) + comprehensive logging per NIST SP 800-92 (security events + system events + application events + administrator actions + with appropriate retention 1+ year for SECRET + 7+ year for compliance) + log aggregation to SIEM + 24x7 monitoring + backup per NIST SP 800-34 (3-2-1 rule + immutable backups + regular testing + RTO/RPO targets).

Artefacts an auditor will ask for
  • Patch metrics + SLA tracking
  • EDR deployment
  • SIEM with retention
  • Backup tested with 3-2-1
  • Annual review
Where this commonly fails
  • Patches exceed SLA
  • No EDR
  • Inadequate logging
  • No backup testing

Planning

NISTSP123-1
Server Security Planning and Lifecycle Considerations

Apply NIST SP 800-123 Guide to General Server Security published July 2008 + foundational reference for server hardening + complement to NIST SP 800-53 + NIST CSF 2.0 PROTECT function + NIST SP 800-44 Public Web Servers + NIST SP 800-45 Email Servers + NIST SP 800-95 Web Services Security. Plan server security per Section 2 including: server selection + cost-benefit analysis + security categorisation per FIPS 199 + threat modelling + secure development lifecycle + integration with broader information security programme + identification of required services + system roles + sensitivity of data processed.

Artefacts an auditor will ask for
  • Server security plan
  • FIPS 199 categorisation
  • Threat model
  • System role documentation
  • Annual review
Where this commonly fails
  • No security plan
  • Missing categorisation
  • No threat model
  • Unclear roles
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-123 framework page.