Skip to content

Evidence request lists

NIST SP 800-150

Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Establishing Sharing Relationships

TIS-1
Threat Information Sharing Goals and Objectives

Define and document the organisational goals, objectives, and intended outcomes for participating in cyber threat information sharing, including alignment with the broader cybersecurity programme and risk tolerance.

Artefacts an auditor will ask for
  • Threat information sharing strategy document
  • Programme charter approved by CISO or equivalent
  • Mapping of sharing objectives to enterprise cybersecurity goals
  • Risk register entries citing threat sharing dependencies
Where this commonly fails
  • Objectives undocumented or assumed
  • No traceability to enterprise risk register
  • Charter never refreshed after team changes
TIS-2
Roles and Responsibilities for Threat Sharing

Identify and assign roles for producing, consuming, and coordinating cyber threat information, including primary points of contact, analyst leads, and legal or privacy reviewers.

Artefacts an auditor will ask for
  • Roles and responsibilities matrix
  • Named threat sharing coordinator
  • Backup contact list
  • Legal and privacy review designations
Where this commonly fails
  • Single person dependency
  • No legal reviewer named
  • Roles defined but not communicated to participants
TIS-3
Threat Information Sharing Plan

Document a sharing plan that describes participating communities, types of information to be exchanged, frequency, channels, and conditions for participation.

Artefacts an auditor will ask for
  • Approved sharing plan
  • List of sharing communities and ISACs joined
  • Information type taxonomy used
  • Cadence schedule
Where this commonly fails
  • Plan exists but not maintained
  • No defined cadence
  • Ad hoc sharing without scope boundaries

Information Acquisition

TIS-7
Threat Information Sources and Feeds

Identify, evaluate, and document the sources of cyber threat information used by the organisation, including commercial, open, sector, and government feeds.

Artefacts an auditor will ask for
  • Source register with provenance
  • Vendor due diligence files
  • Refresh and onboarding records
  • Cost and value evaluation
Where this commonly fails
  • No formal vetting
  • Stale or duplicate feeds
  • Source list undocumented
TIS-8
Threat Information Production and Curation

Produce and curate threat information for internal use and external sharing, including indicators, tactics, techniques, procedures, and contextual analysis.

Artefacts an auditor will ask for
  • Analyst production workflow
  • Style and quality guide
  • Published threat reports
  • Curation tooling configuration
Where this commonly fails
  • No quality guide
  • Reports lack context
  • Indicators shared without observables
TIS-9
Indicator and Observable Management

Capture, validate, and manage indicators of compromise and observables across their lifecycle, including expiration, confidence, and source attribution.

Artefacts an auditor will ask for
  • Threat intelligence platform configuration
  • Confidence and scoring policy
  • Sample indicator records with full metadata
  • Expiration and retirement logs
Where this commonly fails
  • No expiration on stale indicators
  • Confidence not scored
  • No source attribution retained

Information Dissemination

TIS-10
Threat Information Sharing Channels

Use defined channels and formats for sharing cyber threat information, including standardised formats such as STIX and protocols such as TAXII where appropriate.

Artefacts an auditor will ask for
  • Approved channel list
  • STIX or equivalent format documentation
  • TAXII server or client configuration
  • Interoperability test logs
Where this commonly fails
  • Sharing only via email attachments
  • No standard format adopted
  • Channels not tested
TIS-11
Trust Establishment with Sharing Partners

Establish and maintain trust relationships with sharing partners through vetting, agreements, and ongoing interaction to enable bidirectional exchange of sensitive information.

Artefacts an auditor will ask for
  • Partner directory with vetting status
  • Signed memoranda of understanding
  • PGP or signing key inventories
  • Participation history logs
Where this commonly fails
  • No vetting before exchange
  • Trust based on assumption
  • Keys not rotated
TIS-12
Anonymisation and Attribution Controls

Apply controls that allow contributors to share without unintended attribution, including pseudonymisation, group sharing, and trusted intermediaries.

Artefacts an auditor will ask for
  • Attribution policy document
  • Records of intermediary use
  • Tooling for pseudonymous submission
  • Recipient confirmation of anonymity rules
Where this commonly fails
  • No anonymous channel offered
  • Submitter identifiers leak in metadata
  • Policy missing

Information Use

TIS-13
Consumption and Integration of Threat Information

Integrate received threat information into security operations including detection content, hunting, vulnerability triage, and incident response.

Artefacts an auditor will ask for
  • Detection content backlog driven by threat intel
  • Hunting hypotheses linked to shared TTPs
  • Incident response playbooks citing intel
  • Coverage metrics
Where this commonly fails
  • Intel collected but not actioned
  • No measurement of usage
  • Detection content stale
TIS-14
Feedback to Producers and Communities

Provide feedback to information producers and sharing communities regarding the relevance, timeliness, and accuracy of threat information received.

Artefacts an auditor will ask for
  • Feedback templates
  • Sent feedback log
  • Community meeting attendance and notes
  • Producer responses captured
Where this commonly fails
  • No structured feedback
  • Quality issues not raised
  • One-way consumption only

NIST SP 800-150: Access Control

SP800-150-ALERTS
Consume and Respond to Security Alerts

Consume security alerts and advisories from sharing partners and respond by applying mitigations to the organization's environment.

Artefacts an auditor will ask for
  • Process to consume and respond to alerts/advisories
Where this commonly fails
  • Alerts received but not actioned
SP800-150-COMMUNICATE
Engage in Ongoing Communication

Engage in continuous communication with sharing partners to build trust and maintain timely information exchange.

Artefacts an auditor will ask for
  • Ongoing communication with sharing partners
Where this commonly fails
  • No continuous partner engagement
SP800-150-INDICATORS-USE
Consume and Use Indicators

Consume and operationalize threat indicators by integrating them into detection and prevention tools.

Artefacts an auditor will ask for
  • Integration of indicators into detection/prevention tools
Where this commonly fails
  • Indicators not operationalized
SP800-150-JOIN
Join a Sharing Community

Join one or more sharing communities (such as an ISAC or ISAO) to exchange threat information with trusted partners.

Artefacts an auditor will ask for
  • Membership in sharing communities (ISAC/ISAO)
Where this commonly fails
  • Not participating in any sharing community
SP800-150-SUPPORT
Plan for Ongoing Support

Plan to provide the ongoing resources, infrastructure, and personnel needed to sustain information sharing activities.

Artefacts an auditor will ask for
  • Resourcing plan for ongoing sharing
Where this commonly fails
  • No sustained resourcing for sharing

NIST SP 800-150: Asset Management

SP800-150-DESIGNATIONS
Sharing Designations

Use sharing designations (for example the Traffic Light Protocol) to communicate handling and redistribution restrictions for shared information.

Artefacts an auditor will ask for
  • Use of sharing designations (e.g., TLP)
Where this commonly fails
  • No handling designations applied
SP800-150-EXTERNAL
Identify External Sources of Cyber Threat Information

Identify and evaluate external sources and sharing communities that can provide relevant cyber threat information.

Artefacts an auditor will ask for
  • Evaluated external sources and communities
Where this commonly fails
  • External sources not vetted
SP800-150-PROCEDURES
Sharing and Tracking Procedures

Define procedures for cyber threat information sharing and tracking, including what is shared, with whom, and how it is recorded.

Artefacts an auditor will ask for
  • Sharing and tracking procedures
Where this commonly fails
  • Sharing ad hoc and untracked
SP800-150-RULES
Establish Information Sharing Rules

Establish rules that control the publication and distribution of threat information, addressing sensitivity, privacy, and designations.

Artefacts an auditor will ask for
  • Information sharing rules and handling controls
Where this commonly fails
  • No rules governing what is shared
SP800-150-SENSITIVITY
Information Sensitivity and Privacy

Apply handling rules that protect sensitive and personally identifiable information before threat information is shared.

Artefacts an auditor will ask for
  • Sensitivity/PII handling rules before sharing
Where this commonly fails
  • Sensitive/PII data shared without controls

NIST SP 800-150: Cryptography

SP800-150-PRODUCE
Produce and Publish Indicators

Produce, enrich, and publish indicators in standard data formats, protecting sensitive data before distribution to partners.

Artefacts an auditor will ask for
  • Production/publishing of indicators in standard formats with data protection
Where this commonly fails
  • No outbound indicator production
  • Sensitive data not protected before publishing
SP800-150-STORE
Organize and Store Cyber Threat Information

Organize, store, and manage collected cyber threat information to support analysis, correlation, and retrieval.

Artefacts an auditor will ask for
  • Organized storage/management of threat information
Where this commonly fails
  • No structured storage for correlation

NIST SP 800-150: Information Security Policies

SP800-150-BENEFITS
Benefits of Information Sharing

Recognize the benefits of sharing, including shared situational awareness, improved defensive posture, and greater defensive agility.

Artefacts an auditor will ask for
  • Documented sharing benefits tied to objectives
Where this commonly fails
  • Sharing value not articulated to leadership
SP800-150-CHALLENGES
Challenges to Information Sharing

Address challenges including establishing trust, protecting sensitive information, achieving interoperability, and managing the volume of information.

Artefacts an auditor will ask for
  • Identified sharing challenges and mitigations
Where this commonly fails
  • Trust/privacy challenges unaddressed
SP800-150-GOALS
Define Information Sharing Goals and Objectives

Define information sharing goals and objectives that support the organization's overall mission and cybersecurity strategy.

Artefacts an auditor will ask for
  • Defined sharing goals and objectives
Where this commonly fails
  • No defined sharing objectives
SP800-150-INFO-TYPES
Threat Information Types

Identify the categories of cyber threat information (indicators, tactics/techniques/procedures, security alerts, threat intelligence reports, and tool configurations) relevant to the organization.

Artefacts an auditor will ask for
  • Inventory of relevant threat information types (indicators, TTPs, alerts, reports)
Where this commonly fails
  • Threat information types not defined
SP800-150-INTERNAL
Identify Internal Sources of Cyber Threat Information

Identify existing internal sources of cyber threat information such as logs, sensors, and incident reports that can be shared and analyzed.

Artefacts an auditor will ask for
  • Inventory of internal threat information sources
Where this commonly fails
  • Internal sources not identified

Pre-Sharing Considerations

TIS-4
Legal, Regulatory, and Contractual Review

Review legal, regulatory, and contractual obligations that affect threat information sharing, including privacy laws, sector regulations, and non-disclosure terms.

Artefacts an auditor will ask for
  • Legal review memo
  • Privacy impact assessment for sharing activities
  • Mapping of regulatory obligations
  • Non-disclosure agreements with sharing partners
Where this commonly fails
  • No documented legal review
  • Privacy not assessed before sharing
  • Contractual restrictions overlooked
TIS-5
Information Handling and Sensitivity Marking

Apply handling rules and sensitivity markings such as the Traffic Light Protocol to shared cyber threat information so recipients understand redistribution constraints.

Artefacts an auditor will ask for
  • Documented TLP or equivalent handling guide
  • Examples of marked artefacts
  • Training records on handling rules
  • Acknowledgement of handling by recipients
Where this commonly fails
  • TLP applied inconsistently
  • No training on handling
  • Markings stripped during re-sharing
TIS-6
Data Minimisation and Sanitisation

Sanitise and minimise threat information before sharing to remove sensitive personal data, proprietary content, or attribution that exceeds the operational need.

Artefacts an auditor will ask for
  • Sanitisation checklist
  • Before and after samples
  • Reviewer sign-off log
  • Tooling configuration for redaction
Where this commonly fails
  • No checklist for sanitisation
  • PII shared inadvertently
  • No second-person review

Programme Operations

TIS-15
Operational Security of Sharing Activities

Protect the confidentiality and integrity of threat sharing activities, including secure access to platforms, protected communications, and protection of analyst identities.

Artefacts an auditor will ask for
  • Access control records for sharing platforms
  • Encryption configuration for communications
  • OPSEC training records for analysts
  • Account review logs
Where this commonly fails
  • Shared analyst accounts
  • Unencrypted exchanges
  • No OPSEC training
TIS-16
Threat Sharing Programme Metrics

Define and report metrics that measure the value, performance, and maturity of the threat information sharing programme to leadership.

Artefacts an auditor will ask for
  • Metrics catalogue
  • Sample dashboards and reports
  • Maturity self-assessment
  • Executive briefing decks
Where this commonly fails
  • No metrics defined
  • Only volume metrics reported
  • No maturity assessment
TIS-17
Incident-Driven Sharing

Share information arising from incidents with appropriate partners and communities while protecting investigation integrity and sensitive details.

Artefacts an auditor will ask for
  • Incident response playbook with sharing steps
  • Release approval records
  • Sample post-incident shared artefacts
  • Timing logs from detection to share
Where this commonly fails
  • Sharing too late to help others
  • No release approval
  • Sensitive details leaked
TIS-18
Continuous Improvement and Programme Review

Review and improve the threat information sharing programme at a defined cadence, incorporating lessons learned and changes to the threat landscape.

Artefacts an auditor will ask for
  • Annual programme review
  • Lessons learned register
  • Action plan with owners and dates
  • Closure evidence for prior actions
Where this commonly fails
  • Reviews missed
  • Actions never closed
  • No lessons captured
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-150 framework page.