NIST SP 800-123
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Authentication and Access
Implement Section 5.1-5.2 authentication and access control including: strong authentication per NIST SP 800-63 (AAL2 minimum for sensitive systems + MFA where appropriate + risk-based authentication) + identity management + role-based access control (RBAC) per NIST SP 800-178 + attribute-based access control (ABAC) per NIST SP 800-162 + privileged access management (PAM) with session recording + just-in-time access + access reviews quarterly + account lifecycle management. Implement least privilege + separation of duties + need-to-know principles.
- MFA deployment
- RBAC/ABAC matrices
- PAM with session recording
- Quarterly access reviews
- Account lifecycle records
- Weak authentication
- No PAM
- No quarterly reviews
- Missing MFA
Cryptography
Apply Section 5.3 cryptography including: encryption of data at rest (AES-256 + FIPS 140-3 validated modules + full disk encryption + file-level encryption + database encryption) + data in transit (TLS 1.3 + IPsec + SSH 2.0 + S/MIME + PGP) + key management per NIST SP 800-57 + NIST SP 800-152 + key lifecycle (generation + storage + distribution + rotation + revocation + escrow + destruction) + certificate management (X.509 + ACME + Let's Encrypt + DigiCert + private CA) + Post-Quantum Cryptography migration per FIPS 203/204/205 (ML-KEM + ML-DSA + SLH-DSA).
- Encryption inventory
- FIPS 140-3 validated modules
- Key management procedures
- Certificate inventory
- PQC migration plan
- Weak encryption
- No key management
- Expired certificates
- No PQC plan
Governance and ISMS
Establish governance per supporting controls including: information security policy framework + management direction and commitment + policy review and update procedures + roles and responsibilities (CISO + Server Administrator + System Owner + System Security Officer + Privileged User) + contact with authorities and special interest groups (CISA + FBI + ISACs + ISAOs) + integration with information security management system (ISMS) per ISO/IEC 27001 + Annex A controls + Information classification and labeling + asset inventory + acceptable use policies + audit considerations + administrative + technical + physical controls coverage.
- Security policies
- Roles matrix
- Authority contact register
- ISMS integration
- Asset inventory
- Annual review
- Outdated policies
- Unclear roles
- No authority contacts
- Disconnected from ISMS
IR and Decommissioning
Implement Section 7.1 incident response for servers per NIST SP 800-61 covering preparation + detection + analysis + containment + eradication + recovery + post-incident review + coordination with CSIRT + US-CERT + CISA + Cyber Threat Intelligence (CTI) sharing per STIX/TAXII. Apply Section 7.2 server decommissioning including: data sanitisation per NIST SP 800-88 (clear + purge + destroy based on confidentiality categorisation) + media handling + secure disposal + asset removal from inventory + license recovery + DR plan updates + documentation. Maintain chain of custody for evidence and asset disposal.
- IR plan
- NIST SP 800-88 sanitisation
- Chain of custody
- Decommissioning checklist
- CTI sharing
- No IR plan
- Improper sanitisation
- No chain of custody
- Missing CTI
Installation and Configuration
Apply Section 3 secure installation including: server selection per organizational requirements + OS hardening per CIS Benchmarks + DISA STIGs + NSA SecGuide + vendor security guides (Microsoft + Red Hat + SUSE + Ubuntu + macOS) + remove unnecessary services + features + components + install only required software + apply security patches + enable secure default settings + disable default accounts + change default passwords. Configure per Section 4 secure baselines including: enable secure boot + UEFI + TPM 2.0 + disk encryption (BitLocker + LUKS + FileVault) + secure SSH/RDP + restrict remote management + audit log configuration + firewall enabled + IDS/IPS enabled where applicable.
- CIS Benchmark compliance
- STIG compliance
- Patch tracking
- Secure boot enabled
- Configuration baselines
- Annual audit
- No CIS/STIG
- Missing patches
- No secure boot
- Default credentials
Network Security
Apply Section 6.3 network security including: network segmentation per NIST SP 800-207 Zero Trust + microsegmentation + DMZ + jump servers + bastion hosts + perimeter firewalls + host-based firewalls + IDS/IPS + DDoS protection + DNS security (DNSSEC + DoH) + secure email (SPF + DKIM + DMARC + ARC + BIMI) + secure file transfer (SFTP + FTPS + SCP) + secure remote access (VPN + IPsec + SD-WAN + zero trust network access ZTNA) + network monitoring + traffic analysis + flow records (NetFlow + sFlow + IPFIX).
- Network architecture
- ZTNA deployment
- SPF/DKIM/DMARC
- Bastion hosts
- NetFlow monitoring
- Flat networks
- No ZTNA
- Missing email auth
- Insecure remote access
Operations
Apply Section 6.1-6.2 server operations including: vulnerability and patch management per NIST SP 800-40 (Critical 7 days + High 30 days + Medium 90 days + scheduled monthly + automatic patching where appropriate) + malware prevention (signature-based antivirus + EDR + XDR + EDR-NG + sandboxing + application whitelisting) + comprehensive logging per NIST SP 800-92 (security events + system events + application events + administrator actions + with appropriate retention 1+ year for SECRET + 7+ year for compliance) + log aggregation to SIEM + 24x7 monitoring + backup per NIST SP 800-34 (3-2-1 rule + immutable backups + regular testing + RTO/RPO targets).
- Patch metrics + SLA tracking
- EDR deployment
- SIEM with retention
- Backup tested with 3-2-1
- Annual review
- Patches exceed SLA
- No EDR
- Inadequate logging
- No backup testing
Planning
Apply NIST SP 800-123 Guide to General Server Security published July 2008 + foundational reference for server hardening + complement to NIST SP 800-53 + NIST CSF 2.0 PROTECT function + NIST SP 800-44 Public Web Servers + NIST SP 800-45 Email Servers + NIST SP 800-95 Web Services Security. Plan server security per Section 2 including: server selection + cost-benefit analysis + security categorisation per FIPS 199 + threat modelling + secure development lifecycle + integration with broader information security programme + identification of required services + system roles + sensitivity of data processed.
- Server security plan
- FIPS 199 categorisation
- Threat model
- System role documentation
- Annual review
- No security plan
- Missing categorisation
- No threat model
- Unclear roles
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-123 framework page.