Skip to content

Evidence request lists

NIST SP 800-137

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

IR and Authorisation

NISTSP137-7
Incident Response Integration and Ongoing Authorization

Integrate ISCM with Incident Response per Section 4.7 including: SIEM alerts feeding IR + threat hunting + playbook automation per SOAR (Cortex XSOAR + Splunk SOAR + Tines + Swimlane + Microsoft Sentinel Playbooks) + Continuous Adversary Emulation per MITRE Caldera or AttackIQ. Support Ongoing Authorization per Section 4.8 + NIST SP 800-37 RMF including event-driven authorisation reviews + system risk monitoring + control effectiveness assessment + authorisation decision support + Authorisation to Operate (ATO) reviews and Type Authorizations. Apply Asset Inventory Currency monitoring including HW + SW + Cloud + IoT + OT asset discovery + classification + ownership.

Artefacts an auditor will ask for
  • SIEM-IR integration
  • SOAR playbooks
  • Ongoing authorisation evidence
  • Asset inventory currency
  • Threat hunting reports
Where this commonly fails
  • Disconnected IR
  • No SOAR
  • No ongoing authorisation
  • Stale asset inventory

ISCM Strategy

NISTSP137-1
ISCM Strategy, Governance, and Volatility Assessment

Establish Information Security Continuous Monitoring (ISCM) per NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations published September 2011 + companion to NIST SP 800-37 Risk Management Framework + NIST SP 800-53/53A controls + NIST Privacy Framework continuous monitoring. Define ISCM strategy per Section 3.1 covering organisational and system-level objectives + assumptions + constraints + risk tolerance. Conduct security control volatility assessment to identify rapidly-changing controls requiring more frequent monitoring (vulnerability + patching + configuration vs stable controls like physical access). Establish governance structure with Authorising Official + System Owner + ISSO + ISCM Manager.

Artefacts an auditor will ask for
  • ISCM strategy document
  • Volatility assessment
  • Roles and responsibilities
  • Annual strategy review
  • AO sign-off
Where this commonly fails
  • No ISCM strategy
  • Missing volatility assessment
  • Unclear roles
  • Stale strategy

Malware and Access Monitoring

NISTSP137-6
Malware, Identity Access, and Network Boundary Monitoring

Monitor malware per Section 4.4 including signature-based AV + behavioral EDR + sandboxing + threat intel feed integration + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs). Monitor identity and access per Section 4.5 including failed authentications + anomalous access + privilege escalations + after-hours access + UEBA (User and Entity Behavior Analytics) + impossible travel + dormant account use. Monitor network boundary per Section 4.6 including firewall logs + IDS/IPS + DLP + DNS + proxy + VPN + zero trust network access (ZTNA) + east-west traffic + microsegmentation effectiveness.

Artefacts an auditor will ask for
  • EDR coverage
  • UEBA deployment
  • IDS/IPS metrics
  • DLP alerts
  • ZTNA enforcement
Where this commonly fails
  • Gaps in EDR
  • No UEBA
  • Network blind spots
  • Weak DLP

Metrics and Frequencies

NISTSP137-2
Monitoring Metrics, Measures, and Frequencies

Define ISCM metrics per Section 3.2 covering security control effectiveness + system + organizational metrics + leading and lagging indicators + Cyber-Resilience metrics + KPIs (Mean Time to Detect MTTD + Mean Time to Respond MTTR + Mean Time to Remediate MTTR + Mean Time Between Failures MTBF). Establish monitoring and assessment frequencies based on control volatility + system categorisation + risk tolerance + threat environment + resource constraints. Apply continuous (real-time + near-real-time) for high-volatility controls + periodic (daily/weekly/monthly/quarterly) for lower volatility + annual for stable controls.

Artefacts an auditor will ask for
  • Metrics framework
  • KPI dashboard
  • Frequency matrix per control
  • Quarterly review
  • Continuous monitoring evidence
Where this commonly fails
  • No metrics
  • Missing KPIs
  • No frequency rationale
  • Stale dashboards

Programme Management

NISTSP137-8
Programme Review, Training, and Third-Party ISCM

Conduct ISCM Programme Review per Section 4.9 annually + capability maturity assessment + gap analysis + improvement planning aligned with NIST CSF 2.0 implementation tiers. Train workforce for ISCM per Section 4.10 including ISCM concepts + tool usage + analytical skills + interpretation of metrics + role-based training. Apply Third-Party Monitoring Coverage per Section 4.11 covering MSSPs + MDRs + cloud security providers + outsourced SOC + sub-processor monitoring + SCRM + supply chain risk management per NIST SP 800-161 + ICT SCRM + FedRAMP + StateRAMP + DoD CMMC.

Artefacts an auditor will ask for
  • Annual programme review
  • Maturity assessment
  • Training programme
  • Third-party monitoring coverage
  • MSSP/MDR SLAs
Where this commonly fails
  • No programme review
  • Missing training
  • Third-party gaps
  • Weak SCRM

Reporting and Risk Scoring

NISTSP137-4
Security Status Reporting and Risk Score Aggregation

Provide security status reporting per Section 3.6 to System Owners + ISSO + AO + CISO + senior leadership. Apply risk score aggregation including: vulnerability scoring (CVSS v4.0 + EPSS + KEV catalog) + asset criticality scoring + threat intelligence overlay + business impact analysis. Use ATT&CK MITRE coverage scoring + NIST Cybersecurity Framework profile scoring + RMF system risk score per NIST SP 800-39 + Continuous Diagnostics and Mitigation (CDM) Federal Dashboard. Apply Federal Information Security Modernization Act (FISMA) reporting + OMB CyberStat reviews + annual FISMA report.

Artefacts an auditor will ask for
  • Security dashboards
  • Risk scoring methodology
  • CDM Federal Dashboard
  • Annual FISMA report
  • Monthly executive reports
Where this commonly fails
  • No reporting
  • Missing risk scoring
  • No FISMA report
  • No CDM

Technical Architecture

NISTSP137-3
ISCM Technical Architecture and Automation

Architect ISCM technology stack per Section 3.3 + 3.4 including: SIEM (Splunk + QRadar + Elastic Security + Sentinel + Chronicle + Sumo Logic) + EDR/XDR (CrowdStrike + SentinelOne + Microsoft Defender + Palo Alto Cortex) + vulnerability scanners (Tenable + Qualys + Rapid7) + configuration management (Ansible + Puppet + Chef + Salt + Microsoft Configuration Manager) + identity governance (SailPoint + Saviynt + Okta + Ping) + GRC platforms (ServiceNow + RSA Archer + LogicGate + AuditBoard) + integration via APIs + SCAP + OSCAL + ASCII-Armor + STIX/TAXII. Apply data collection automation per Section 3.5 minimising manual data collection + leveraging configuration and vulnerability data + CMDB integration.

Artefacts an auditor will ask for
  • ISCM architecture
  • Tool inventory
  • Automation rate metrics
  • SCAP/OSCAL integration
  • API integration
Where this commonly fails
  • Manual monitoring
  • Tool silos
  • No automation
  • Missing API integration

Vulnerability and Configuration

NISTSP137-5
Vulnerability + Patch + Configuration Status Monitoring

Monitor vulnerability per Section 4.1 continuously: scanning + assessment + risk prioritisation + remediation tracking aligned with NIST SP 800-40 + NIST SP 800-126 SCAP + Tenable + Qualys + Rapid7 + open-source OpenVAS. Monitor patch management status per Section 4.2 including Critical 7 days + High 30 days + Medium 90 days + emergency patching processes + WSUS + SCCM + JAMF + automated patching pipelines. Monitor configuration status per Section 4.3 including baseline compliance per CIS Benchmarks + DISA STIGs + custom baselines + drift detection + configuration management database (CMDB) currency.

Artefacts an auditor will ask for
  • Vulnerability scans + KPIs
  • Patch SLA tracking
  • Configuration baseline compliance
  • CMDB currency
  • Drift detection alerts
Where this commonly fails
  • Patches exceed SLA
  • No baseline
  • Drift not detected
  • Stale CMDB
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-137 framework page.