Skip to content

Evidence request lists

NIST SP 800-128

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Controlling Configuration Changes

SecCM-CHANGE-1
Configuration Change Control Process

Establish a formal change control process requiring submission, review, approval, implementation, verification, and closure of all configuration changes through a Configuration Control Board or equivalent authority.

Artefacts an auditor will ask for
  • Change request register
  • CCB meeting minutes
  • Approved change records with timestamps
  • Closed change verification records
Where this commonly fails
  • Emergency changes never reconciled
  • CCB minutes missing
  • Verification step skipped
  • Backout plans absent
SecCM-CHANGE-3
Access Restrictions for Change

Define, document, and enforce physical and logical access restrictions associated with changes to information systems including privileged role separation, change tooling authentication, and audit logging of all change actions.

Artefacts an auditor will ask for
  • Privileged account list
  • Access review records for change tools
  • Audit logs of configuration commits
  • Role assignment evidence
Where this commonly fails
  • Shared admin accounts
  • Audit logs not retained
  • No access review for IaC repositories
  • Developers can push to production
SecCM-CHANGE-4
Testing and Validation

Test configuration changes in a representative non-production environment to validate functionality and security before deployment to production, and document test results as part of the change record.

Artefacts an auditor will ask for
  • Test environment architecture
  • Test plans per change type
  • Test results attached to change record
  • Promotion approval records
Where this commonly fails
  • No representative test environment
  • Test results not archived
  • Security tests omitted
  • Direct-to-production changes
SecCM-CHANGE-5
Retention of Configuration Records

Retain previous versions of baseline configurations and change records for a defined period to support rollback, forensic analysis, audit, and trend analysis of configuration drift over time.

Artefacts an auditor will ask for
  • Retention schedule
  • Baseline version history
  • Change record archive
  • Rollback test evidence
Where this commonly fails
  • No retention policy
  • Versions overwritten in repo
  • Records purged early
  • No rollback drill
SecCM-CHANGE-6
Automated Change Control Tools

Use automated tools such as configuration management databases, version control systems, and SCAP-enabled scanners to enforce change workflows, detect unauthorized changes, and record an audit trail of all configuration modifications.

Artefacts an auditor will ask for
  • CMDB screenshots
  • Version control commit logs
  • SCAP scan integration evidence
  • Unauthorized-change alert records
Where this commonly fails
  • Manual change spreadsheets
  • Detection alerts not actioned
  • No integration between ticketing and CMDB
  • SCAP tooling absent
SecCM-CHANGE-7
Emergency Change Handling

Define an expedited process for emergency configuration changes that bypasses routine CCB review but requires retrospective documentation, security impact analysis, and CCB ratification within a defined timeframe.

Artefacts an auditor will ask for
  • Emergency change procedure
  • Emergency change log
  • Retrospective SIA records
  • CCB ratification minutes
Where this commonly fails
  • Emergency path overused
  • No retrospective review
  • Emergency changes not flagged in CMDB
  • No metrics on emergency volume

Identifying & Implementing Configurations

SecCM-ID-1
Configuration Item Identification

Identify and document the configuration items subject to SecCM including hardware, operating systems, applications, firmware, network devices, and virtual components, with sufficient granularity to support baseline management and change tracking.

Artefacts an auditor will ask for
  • CI inventory database
  • CI naming convention document
  • CI hierarchy or relationship map
  • Inventory reconciliation reports
Where this commonly fails
  • Virtual assets missing
  • Firmware not tracked as CIs
  • Shadow IT not inventoried
  • Inventory stale by months
SecCM-ID-2
Baseline Configuration Development

Develop, document, and maintain a current baseline configuration for each configuration item that records approved settings, software versions, patch levels, network topology, and authorized accounts forming the known-good state from which changes are measured.

Artefacts an auditor will ask for
  • Baseline configuration documents per CI type
  • Version history
  • Approval records
  • Comparison reports between baseline and live state
Where this commonly fails
  • No baselines for cloud workloads
  • Baselines not version-controlled
  • No comparison against live systems
  • Baselines never updated after major changes
SecCM-ID-3
Common Secure Configurations

Adopt common secure configurations from authoritative sources such as USGCB, DISA STIGs, CIS Benchmarks, or vendor security guides as the starting point for baselines, and tailor them with documented justification for deviations.

Artefacts an auditor will ask for
  • Mapping of baselines to USGCB or CIS Benchmark version
  • Tailoring justification log
  • Deviation register
  • SCAP benchmark content references
Where this commonly fails
  • No documented benchmark source
  • Deviations not justified
  • Old benchmark versions in use
  • Tailoring decisions not approved
SecCM-ID-4
Least Functionality

Configure systems to provide only essential capabilities by disabling unused services, ports, protocols, and software, and document the rationale for enabled functions within the baseline.

Artefacts an auditor will ask for
  • Approved services and ports list
  • Disabled-features evidence per CI
  • Port scan results
  • Software allow lists
Where this commonly fails
  • Default services left enabled
  • Allow list not enforced
  • No periodic port scans
  • Justification missing for enabled services
SecCM-ID-5
Implementation and Provisioning

Implement approved baselines through automated provisioning, golden images, infrastructure-as-code templates, or scripted deployment so that new systems receive secure configurations consistently from initial build.

Artefacts an auditor will ask for
  • Golden image inventory
  • IaC repositories
  • Provisioning playbooks
  • Build verification scan results
Where this commonly fails
  • Manual provisioning
  • Golden images not patched
  • IaC not security-reviewed
  • No verification scan after build

Monitoring

SecCM-MONITOR-1
Continuous Monitoring of Configurations

Establish continuous monitoring of configuration items to detect deviations from approved baselines using automated scanning, agent-based reporting, and SCAP content aligned with the organization's monitoring strategy.

Artefacts an auditor will ask for
  • Monitoring strategy document
  • Scan schedule
  • Tool coverage report by CI type
  • Sample scan output
Where this commonly fails
  • Monitoring limited to servers
  • Cloud and OT excluded
  • Scans run quarterly not continuously
  • No agent on endpoints
SecCM-MONITOR-2
Configuration Drift Detection

Compare actual system configurations against approved baselines on a defined cadence to identify drift, unauthorized changes, or degradation of secure settings, and feed findings into incident response and remediation workflows.

Artefacts an auditor will ask for
  • Drift report samples
  • Baseline-vs-actual diff outputs
  • Drift remediation ticket trail
  • Trend dashboard
Where this commonly fails
  • Drift reports generated but not actioned
  • No SLA for remediation
  • Drift detection blind to firmware
  • False positive rate not tuned
SecCM-MONITOR-3
Vulnerability Identification and Remediation

Identify vulnerabilities arising from configuration weaknesses, missing patches, or end-of-life software through scanning and threat intelligence, and remediate within risk-based timeframes documented in policy.

Artefacts an auditor will ask for
  • Vulnerability scan reports
  • Patch deployment records
  • SLA metrics by severity
  • Exception register
Where this commonly fails
  • Critical vulns past SLA
  • Exceptions never expire
  • EOL software undetected
  • No re-scan after patch
SecCM-MONITOR-4
Compliance Reporting

Produce regular compliance reports showing configuration posture against baselines, benchmark scores, drift counts, and remediation timeliness, and distribute to system owners, authorizing officials, and executive stakeholders.

Artefacts an auditor will ask for
  • Monthly or quarterly compliance reports
  • Distribution list
  • Executive dashboard screenshots
  • Authorizing official acknowledgments
Where this commonly fails
  • Reports delivered but not reviewed
  • Metrics inconsistent month over month
  • No executive visibility
  • Reports lack remediation status
SecCM-MONITOR-5
Unauthorized Change Detection

Detect and respond to unauthorized configuration changes through file integrity monitoring, registry monitoring, change correlation with approved tickets, and alerting on deviations not tied to an approved change record.

Artefacts an auditor will ask for
  • FIM alert logs
  • Ticket correlation reports
  • Incident records for unauthorized changes
  • Response runbook
Where this commonly fails
  • FIM disabled on critical hosts
  • No correlation to change tickets
  • Alerts go to unmonitored mailbox
  • Repeat offenders not tracked
SecCM-MONITOR-6
Metrics and Measurement

Define and collect SecCM metrics covering baseline adoption rate, change approval cycle time, drift volume, vulnerability remediation SLA, and unauthorized change incidents to drive continuous improvement.

Artefacts an auditor will ask for
  • Metrics catalog
  • Quarterly metrics report
  • Trend charts
  • Improvement action register
Where this commonly fails
  • Metrics defined but not collected
  • No baseline targets
  • Metrics not reviewed at CCB
  • No corrective action for missed targets
SecCM-MONITOR-7
Feedback into Baselines

Use monitoring findings to refine baseline configurations, update common secure configurations, retire obsolete settings, and incorporate lessons learned into the SecCM Plan and procedures.

Artefacts an auditor will ask for
  • Baseline revision history tied to findings
  • Lessons learned log
  • Updated SecCM Plan versions
  • Retirement records for obsolete settings
Where this commonly fails
  • Findings never update baselines
  • Lessons learned not captured
  • SecCM Plan static for years
  • Obsolete settings linger
SecCM-MONITOR-8
Audit and Independent Assessment

Subject SecCM activities to periodic independent assessment to verify policy adherence, baseline accuracy, change record completeness, and effectiveness of monitoring controls, with findings tracked to closure.

Artefacts an auditor will ask for
  • Audit reports
  • Assessment plan
  • Finding tracker
  • Closure evidence per finding
Where this commonly fails
  • No independent assessment
  • Findings open for years
  • Same findings repeat
  • Assessor not independent of CCB

NIST SP 800-128: Access Control

SP800-128-ACCESS-RESTRICT
Access Restrictions for Change

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system.

Artefacts an auditor will ask for
  • Access restrictions for change (logical/physical)
Where this commonly fails
  • Unrestricted change access
  • No enforcement of change privileges
SP800-128-BASELINE
Baseline Configuration

Develop, document, and maintain an approved baseline configuration of the information system as a basis for future builds and changes.

Artefacts an auditor will ask for
  • Approved baseline configuration documentation
Where this commonly fails
  • No maintained baseline
SP800-128-CHANGE-CONTROL
Configuration Change Control

Control changes to the baseline configuration through documented requests, approvals, testing, and tracking.

Artefacts an auditor will ask for
  • Change requests, testing, approvals, tracking
Where this commonly fails
  • Changes not tested or tracked
SP800-128-MONITORING
Configuration Monitoring

Assess and report on the configuration of the information system and identify and address unauthorized or undesirable configuration changes.

Artefacts an auditor will ask for
  • Configuration assessment/reporting and remediation
Where this commonly fails
  • Unauthorized changes undetected
SP800-128-SIA
Security Impact Analysis

Analyze changes to the information system to determine potential security impacts prior to change implementation.

Artefacts an auditor will ask for
  • Security impact analysis records prior to change
Where this commonly fails
  • No security impact analysis before changes

NIST SP 800-128: Asset Management

SP800-128-CCB
Configuration Control Board

A board with responsibility for reviewing and approving proposed changes to the configuration baseline, including their security impact.

Artefacts an auditor will ask for
  • Configuration control board charter and minutes
Where this commonly fails
  • No CCB or change authority
SP800-128-CONFIG-ITEMS
Configuration Items

Identify the configuration items, the system components placed under configuration management and treated as a single entity for control.

Artefacts an auditor will ask for
  • Defined configuration items under management
Where this commonly fails
  • Configuration items not identified
SP800-128-INVENTORY
Component Inventory

Develop and maintain an inventory of the information system components that comprise the system and are subject to configuration management.

Artefacts an auditor will ask for
  • Component inventory
Where this commonly fails
  • Incomplete component inventory
SP800-128-PLAN-DOC
Configuration Management Plan

A comprehensive plan describing the SecCM roles, responsibilities, processes, and procedures applied to a system throughout its lifecycle.

Artefacts an auditor will ask for
  • Configuration management plan
Where this commonly fails
  • No CM plan for the system
SP800-128-SECURE-CONFIG
Secure Configurations of Information Systems

Establish secure configuration settings that reflect the most restrictive mode consistent with operational requirements.

Artefacts an auditor will ask for
  • Secure configuration settings (e.g., benchmarks)
Where this commonly fails
  • Default/insecure configurations in use

NIST SP 800-128: Information Security Policies

SP800-128-PH-CONTROL
SecCM Phase: Controlling Configuration Changes

Manage changes to the baseline configuration through an analyzed, documented, and approved change control process.

Artefacts an auditor will ask for
  • Change control process and approval records
Where this commonly fails
  • Undocumented or unapproved changes
SP800-128-PH-IDENTIFY
SecCM Phase: Identifying and Implementing Configurations

Develop, review, approve, and implement secure baseline configurations for information systems and their components.

Artefacts an auditor will ask for
  • Approved secure baseline configurations
Where this commonly fails
  • No documented secure baselines
SP800-128-PH-MONITOR
SecCM Phase: Monitoring

Validate that the system is adhering to organizational policies, procedures, and the approved secure baseline configuration.

Artefacts an auditor will ask for
  • Baseline compliance monitoring reports
Where this commonly fails
  • No drift detection from baseline
SP800-128-PH-PLAN
SecCM Phase: Planning

Develop a configuration management plan, policy, and procedures, and establish the configuration control board to govern security-focused configuration management.

Artefacts an auditor will ask for
  • SecCM plan, policy, and CCB establishment
Where this commonly fails
  • No SecCM planning artifacts
SP800-128-POLICY
Configuration Management Policy and Procedures

Establish the SecCM policy and procedures that address purpose, scope, roles, responsibilities, and compliance.

Artefacts an auditor will ask for
  • Configuration management policy and procedures
Where this commonly fails
  • CM policy missing or outdated

Planning

SecCM-PLAN-1
SecCM Policy and Procedures

Establish, document, and disseminate organization-wide security-focused configuration management policy and supporting procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among entities, and compliance.

Artefacts an auditor will ask for
  • SecCM policy document
  • SecCM procedures
  • Approval signatures and dates
  • Annual review records
  • Distribution acknowledgments
Where this commonly fails
  • Policy not separated from generic CM policy
  • No review cadence
  • Roles undefined
  • Procedures missing for each SecCM phase
SecCM-PLAN-2
SecCM Plan

Develop a SecCM Plan documenting the strategy, roles and responsibilities, configuration items in scope, baseline configuration definition approach, change control board structure, monitoring approach, and tools used to enforce secure configurations across the system lifecycle.

Artefacts an auditor will ask for
  • SecCM Plan
  • System boundary diagram
  • CI inventory scope statement
  • Tool inventory
  • Plan approval record
Where this commonly fails
  • No SecCM Plan distinct from system security plan
  • CIs not enumerated
  • Tools not mapped to phases
  • Plan never updated
SecCM-PLAN-3
Roles and Responsibilities

Define and assign SecCM roles including Information System Owner, Information System Security Officer, Configuration Control Board members, Configuration Manager, and SecCM analysts with documented authorities and separation of duties.

Artefacts an auditor will ask for
  • RACI matrix
  • Role appointment letters
  • CCB charter
  • Separation of duties matrix
  • Training records for SecCM roles
Where this commonly fails
  • CCB charter missing
  • Same person approves and implements changes
  • ISSO not on CCB
  • Roles documented but not staffed
SecCM-PLAN-4
Integration with Organizational CM

Coordinate SecCM activities with broader enterprise configuration management, asset management, change management, and risk management processes to avoid duplication and ensure security considerations are embedded in CM workflows.

Artefacts an auditor will ask for
  • Process integration diagram
  • Cross-reference of SecCM to ITIL or CMMI processes
  • Joint procedure documents
  • Tool integration records
Where this commonly fails
  • SecCM operates in isolation from IT CM
  • Duplicate CCBs
  • Asset register and CI register inconsistent
  • No handoff between change and security teams
SecCM-PLAN-5
Tools, Techniques, and Resources

Identify and document the automated tools, repositories, and resources required to support SecCM activities including configuration scanners, change management ticketing, software inventory, and SCAP-validated content sources.

Artefacts an auditor will ask for
  • Tool catalog with SCAP capability flags
  • Resource allocation budget
  • Vendor SLAs
  • Tool authorization records
Where this commonly fails
  • Tools selected without SCAP support
  • No funding for ongoing licenses
  • Tools not authorized to operate
  • Duplicate tools across teams
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-128 framework page.