NIST SP 800-150
Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Establishing Sharing Relationships
Define and document the organisational goals, objectives, and intended outcomes for participating in cyber threat information sharing, including alignment with the broader cybersecurity programme and risk tolerance.
- Threat information sharing strategy document
- Programme charter approved by CISO or equivalent
- Mapping of sharing objectives to enterprise cybersecurity goals
- Risk register entries citing threat sharing dependencies
- Objectives undocumented or assumed
- No traceability to enterprise risk register
- Charter never refreshed after team changes
Identify and assign roles for producing, consuming, and coordinating cyber threat information, including primary points of contact, analyst leads, and legal or privacy reviewers.
- Roles and responsibilities matrix
- Named threat sharing coordinator
- Backup contact list
- Legal and privacy review designations
- Single person dependency
- No legal reviewer named
- Roles defined but not communicated to participants
Document a sharing plan that describes participating communities, types of information to be exchanged, frequency, channels, and conditions for participation.
- Approved sharing plan
- List of sharing communities and ISACs joined
- Information type taxonomy used
- Cadence schedule
- Plan exists but not maintained
- No defined cadence
- Ad hoc sharing without scope boundaries
Information Acquisition
Identify, evaluate, and document the sources of cyber threat information used by the organisation, including commercial, open, sector, and government feeds.
- Source register with provenance
- Vendor due diligence files
- Refresh and onboarding records
- Cost and value evaluation
- No formal vetting
- Stale or duplicate feeds
- Source list undocumented
Produce and curate threat information for internal use and external sharing, including indicators, tactics, techniques, procedures, and contextual analysis.
- Analyst production workflow
- Style and quality guide
- Published threat reports
- Curation tooling configuration
- No quality guide
- Reports lack context
- Indicators shared without observables
Capture, validate, and manage indicators of compromise and observables across their lifecycle, including expiration, confidence, and source attribution.
- Threat intelligence platform configuration
- Confidence and scoring policy
- Sample indicator records with full metadata
- Expiration and retirement logs
- No expiration on stale indicators
- Confidence not scored
- No source attribution retained
Information Dissemination
Use defined channels and formats for sharing cyber threat information, including standardised formats such as STIX and protocols such as TAXII where appropriate.
- Approved channel list
- STIX or equivalent format documentation
- TAXII server or client configuration
- Interoperability test logs
- Sharing only via email attachments
- No standard format adopted
- Channels not tested
Establish and maintain trust relationships with sharing partners through vetting, agreements, and ongoing interaction to enable bidirectional exchange of sensitive information.
- Partner directory with vetting status
- Signed memoranda of understanding
- PGP or signing key inventories
- Participation history logs
- No vetting before exchange
- Trust based on assumption
- Keys not rotated
Apply controls that allow contributors to share without unintended attribution, including pseudonymisation, group sharing, and trusted intermediaries.
- Attribution policy document
- Records of intermediary use
- Tooling for pseudonymous submission
- Recipient confirmation of anonymity rules
- No anonymous channel offered
- Submitter identifiers leak in metadata
- Policy missing
Information Use
Integrate received threat information into security operations including detection content, hunting, vulnerability triage, and incident response.
- Detection content backlog driven by threat intel
- Hunting hypotheses linked to shared TTPs
- Incident response playbooks citing intel
- Coverage metrics
- Intel collected but not actioned
- No measurement of usage
- Detection content stale
Provide feedback to information producers and sharing communities regarding the relevance, timeliness, and accuracy of threat information received.
- Feedback templates
- Sent feedback log
- Community meeting attendance and notes
- Producer responses captured
- No structured feedback
- Quality issues not raised
- One-way consumption only
NIST SP 800-150: Access Control
Consume security alerts and advisories from sharing partners and respond by applying mitigations to the organization's environment.
- Process to consume and respond to alerts/advisories
- Alerts received but not actioned
Engage in continuous communication with sharing partners to build trust and maintain timely information exchange.
- Ongoing communication with sharing partners
- No continuous partner engagement
Consume and operationalize threat indicators by integrating them into detection and prevention tools.
- Integration of indicators into detection/prevention tools
- Indicators not operationalized
Join one or more sharing communities (such as an ISAC or ISAO) to exchange threat information with trusted partners.
- Membership in sharing communities (ISAC/ISAO)
- Not participating in any sharing community
Plan to provide the ongoing resources, infrastructure, and personnel needed to sustain information sharing activities.
- Resourcing plan for ongoing sharing
- No sustained resourcing for sharing
NIST SP 800-150: Asset Management
Use sharing designations (for example the Traffic Light Protocol) to communicate handling and redistribution restrictions for shared information.
- Use of sharing designations (e.g., TLP)
- No handling designations applied
Identify and evaluate external sources and sharing communities that can provide relevant cyber threat information.
- Evaluated external sources and communities
- External sources not vetted
Define procedures for cyber threat information sharing and tracking, including what is shared, with whom, and how it is recorded.
- Sharing and tracking procedures
- Sharing ad hoc and untracked
Establish rules that control the publication and distribution of threat information, addressing sensitivity, privacy, and designations.
- Information sharing rules and handling controls
- No rules governing what is shared
Apply handling rules that protect sensitive and personally identifiable information before threat information is shared.
- Sensitivity/PII handling rules before sharing
- Sensitive/PII data shared without controls
NIST SP 800-150: Cryptography
Produce, enrich, and publish indicators in standard data formats, protecting sensitive data before distribution to partners.
- Production/publishing of indicators in standard formats with data protection
- No outbound indicator production
- Sensitive data not protected before publishing
Organize, store, and manage collected cyber threat information to support analysis, correlation, and retrieval.
- Organized storage/management of threat information
- No structured storage for correlation
NIST SP 800-150: Information Security Policies
Recognize the benefits of sharing, including shared situational awareness, improved defensive posture, and greater defensive agility.
- Documented sharing benefits tied to objectives
- Sharing value not articulated to leadership
Address challenges including establishing trust, protecting sensitive information, achieving interoperability, and managing the volume of information.
- Identified sharing challenges and mitigations
- Trust/privacy challenges unaddressed
Define information sharing goals and objectives that support the organization's overall mission and cybersecurity strategy.
- Defined sharing goals and objectives
- No defined sharing objectives
Identify the categories of cyber threat information (indicators, tactics/techniques/procedures, security alerts, threat intelligence reports, and tool configurations) relevant to the organization.
- Inventory of relevant threat information types (indicators, TTPs, alerts, reports)
- Threat information types not defined
Identify existing internal sources of cyber threat information such as logs, sensors, and incident reports that can be shared and analyzed.
- Inventory of internal threat information sources
- Internal sources not identified
Pre-Sharing Considerations
Review legal, regulatory, and contractual obligations that affect threat information sharing, including privacy laws, sector regulations, and non-disclosure terms.
- Legal review memo
- Privacy impact assessment for sharing activities
- Mapping of regulatory obligations
- Non-disclosure agreements with sharing partners
- No documented legal review
- Privacy not assessed before sharing
- Contractual restrictions overlooked
Apply handling rules and sensitivity markings such as the Traffic Light Protocol to shared cyber threat information so recipients understand redistribution constraints.
- Documented TLP or equivalent handling guide
- Examples of marked artefacts
- Training records on handling rules
- Acknowledgement of handling by recipients
- TLP applied inconsistently
- No training on handling
- Markings stripped during re-sharing
Sanitise and minimise threat information before sharing to remove sensitive personal data, proprietary content, or attribution that exceeds the operational need.
- Sanitisation checklist
- Before and after samples
- Reviewer sign-off log
- Tooling configuration for redaction
- No checklist for sanitisation
- PII shared inadvertently
- No second-person review
Programme Operations
Protect the confidentiality and integrity of threat sharing activities, including secure access to platforms, protected communications, and protection of analyst identities.
- Access control records for sharing platforms
- Encryption configuration for communications
- OPSEC training records for analysts
- Account review logs
- Shared analyst accounts
- Unencrypted exchanges
- No OPSEC training
Define and report metrics that measure the value, performance, and maturity of the threat information sharing programme to leadership.
- Metrics catalogue
- Sample dashboards and reports
- Maturity self-assessment
- Executive briefing decks
- No metrics defined
- Only volume metrics reported
- No maturity assessment
Share information arising from incidents with appropriate partners and communities while protecting investigation integrity and sensitive details.
- Incident response playbook with sharing steps
- Release approval records
- Sample post-incident shared artefacts
- Timing logs from detection to share
- Sharing too late to help others
- No release approval
- Sensitive details leaked
Review and improve the threat information sharing programme at a defined cadence, incorporating lessons learned and changes to the threat landscape.
- Annual programme review
- Lessons learned register
- Action plan with owners and dates
- Closure evidence for prior actions
- Reviews missed
- Actions never closed
- No lessons captured
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-150 framework page.