Skip to content

Evidence request lists

NIST SP 800-160

Evidence request list. 49 controls, 49 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Agreement and Organisational Project Enabling Processes

SE-BC
Business or Mission Analysis

Define the problem space, mission needs, stakeholders, and constraints that drive the engineering of a trustworthy secure system, including security and resilience needs traceable to mission outcomes.

Artefacts an auditor will ask for
  • Business and mission analysis report
  • Stakeholder register with security interests
  • Security and resilience needs statement
  • Traceability to mission outcomes
Where this commonly fails
  • Security needs not traced to mission
  • Stakeholder register missing security stakeholders
  • Constraints undocumented

Assurance

SE-AC
Assurance Case Development

Develop and maintain an assurance case that argues, with evidence, that the system possesses claimed security properties.

Artefacts an auditor will ask for
  • Assurance case document
  • Claim and argument structure
  • Evidence references
  • Update log as system evolves
Where this commonly fails
  • No assurance case
  • Claims without evidence
  • Not updated after changes
SE-IA
Information Assurance and Security Engineering Trade-offs

Document trade-offs among security objectives, system performance, cost, and schedule, ensuring decisions are informed and approved by an appropriate authority.

Artefacts an auditor will ask for
  • Trade-off study reports
  • Decision logs with authority
  • Approval signatures
  • Rationale for each decision
Where this commonly fails
  • Trade-offs decided informally
  • No approval
  • Decisions not communicated to operators

Cross-cutting

SE-HF
Human Factors in Secure Systems Engineering

Address human factors during engineering, including usability of security controls, error tolerance, and operator workload, to reduce the likelihood of human-induced compromise.

Artefacts an auditor will ask for
  • Usability test reports for security functions
  • Workload assessments
  • Error analysis
  • Design changes resulting from human factors review
Where this commonly fails
  • No usability testing of security functions
  • Operators bypass controls due to friction
  • Errors not analysed

NIST SP 800-160: Access Control

SP800-160-TM-CONFIG
Configuration Management Process

Manage and control system elements and configurations over the life cycle, preserving security-relevant configuration integrity.

Artefacts an auditor will ask for
  • Configuration management preserving security integrity
Where this commonly fails
  • Security-relevant configurations uncontrolled
SP800-160-TM-DECISION
Decision Management Process

Provide a structured framework for selecting a course of action among alternatives, accounting for security implications.

Artefacts an auditor will ask for
  • Decision records accounting for security implications
Where this commonly fails
  • Decisions ignore security trade-offs
SP800-160-TM-INFO
Information Management Process

Generate, obtain, manage, and protect designated information, including security-relevant information, throughout the life cycle.

Artefacts an auditor will ask for
  • Protection of security-relevant information
Where this commonly fails
  • Sensitive engineering info unprotected
SP800-160-TM-MEASURE
Measurement Process

Collect, analyze, and report data, including security measures, to support effective management and demonstrate product and process quality.

Artefacts an auditor will ask for
  • Security measures and reporting
Where this commonly fails
  • No security measurement
SP800-160-TM-RISK
Risk Management Process

Identify, analyze, treat, and monitor risks continually, including security risks to the system and its assets.

Artefacts an auditor will ask for
  • Security risk register and treatment
Where this commonly fails
  • Security risks not managed continually

NIST SP 800-160: Asset Management

SP800-160-OPE-HR
Human Resource Management Process

Provide the organization with necessary skilled and security-competent human resources and maintain their competencies.

Artefacts an auditor will ask for
  • Security competency management records
Where this commonly fails
  • Security skills not maintained
SP800-160-OPE-KM
Knowledge Management Process

Create the capability and assets to reuse knowledge, including security knowledge, across the organization.

Artefacts an auditor will ask for
  • Security knowledge reuse assets
Where this commonly fails
  • Security knowledge not captured/reused
SP800-160-OPE-QM
Quality Management Process

Assure that products, services, and processes, including their security characteristics, meet organizational quality objectives.

Artefacts an auditor will ask for
  • Quality objectives including security characteristics
Where this commonly fails
  • Security excluded from quality management
SP800-160-TM-ASSESS
Project Assessment and Control Process

Assess whether plans are aligned and feasible, and direct execution to meet objectives including security objectives.

Artefacts an auditor will ask for
  • Assessment/control records covering security objectives
Where this commonly fails
  • Security objectives not tracked in project control
SP800-160-TM-PLAN
Project Planning Process

Produce and coordinate effective and workable project plans that incorporate security activities and resources.

Artefacts an auditor will ask for
  • Project plans incorporating security activities/resources
Where this commonly fails
  • Security activities not planned/resourced

NIST SP 800-160: Communications Security

SP800-160-TE-DISPOSAL
Disposal Process

End the existence of a system element or system, securely handling data sanitization and residual security risks.

Artefacts an auditor will ask for
  • Secure disposal and data sanitization records
Where this commonly fails
  • Residual data/risk on disposal
SP800-160-TE-MAINTAIN
Maintenance Process

Sustain the capability of the system to provide a secure service, including security patching and configuration control.

Artefacts an auditor will ask for
  • Security patching and configuration control in maintenance
Where this commonly fails
  • Maintenance erodes security posture
SP800-160-TE-OPERATE
Operation Process

Use the system to deliver its services, including sustaining secure operation and managing operational security risks.

Artefacts an auditor will ask for
  • Secure operation and operational risk management
Where this commonly fails
  • Operational security risks unmanaged

NIST SP 800-160: Cryptography

SP800-160-TE-ARCH
Architecture Definition Process

Generate system architecture alternatives and select an architecture that frames security concerns and protection capabilities.

Artefacts an auditor will ask for
  • Architecture addressing security/protection capabilities
Where this commonly fails
  • Security not framed in architecture
SP800-160-TE-DESIGN
Design Definition Process

Provide sufficient detailed data and information about the system and its elements to enable secure implementation.

Artefacts an auditor will ask for
  • Design detail enabling secure implementation
Where this commonly fails
  • Security design detail insufficient
SP800-160-TE-STAKE
Stakeholder Needs and Requirements Definition Process

Define stakeholder protection needs and security requirements that the system must satisfy in its operational environment.

Artefacts an auditor will ask for
  • Stakeholder protection needs and security requirements
Where this commonly fails
  • Protection needs undefined
SP800-160-TE-SYSREQ
System Requirements Definition Process

Transform stakeholder protection needs into a technical view of security requirements for the system.

Artefacts an auditor will ask for
  • System security requirements traceable to needs
Where this commonly fails
  • Security requirements not derived/traceable
SP800-160-TM-QA
Quality Assurance Process

Assure the effective application of the organization's quality and security processes to the project.

Artefacts an auditor will ask for
  • Quality assurance of security processes
Where this commonly fails
  • Security processes not assured

NIST SP 800-160: Information Security Policies

SP800-160-AGR-ACQ
Acquisition Process

Obtain a product or service in accordance with the acquirer's security requirements, including expressing security needs in the agreement.

Artefacts an auditor will ask for
  • Acquisition agreements expressing security requirements
Where this commonly fails
  • Security needs absent from acquisition agreements
SP800-160-AGR-SUP
Supply Process

Provide an acquirer with a product or service that meets agreed security requirements.

Artefacts an auditor will ask for
  • Supplier deliverables meeting agreed security requirements
Where this commonly fails
  • Supplied products not evidenced against security requirements
SP800-160-OPE-INFRA
Infrastructure Management Process

Provide and maintain the secure infrastructure and services needed to support the organization and projects.

Artefacts an auditor will ask for
  • Secure infrastructure provisioning records
Where this commonly fails
  • Project infrastructure not secured
SP800-160-OPE-LCM
Life Cycle Model Management Process

Define, maintain, and assure the availability of policies, processes, models, and procedures, including their security aspects, across the organization.

Artefacts an auditor will ask for
  • Life cycle models/policies including security aspects
Where this commonly fails
  • Security not embedded in life cycle models
SP800-160-OPE-PORTFOLIO
Portfolio Management Process

Initiate, sustain, and direct projects and ensure the necessary investment, including security investment, to meet organizational objectives.

Artefacts an auditor will ask for
  • Security investment in portfolio decisions
Where this commonly fails
  • Security not funded in portfolio

NIST SP 800-160: Operations Security

SP800-160-TE-ANALYSIS
System Analysis Process

Provide a rigorous basis of data and information, including security analyses, for technical understanding and decision making.

Artefacts an auditor will ask for
  • Security analyses supporting decisions
Where this commonly fails
  • No security analysis basis for decisions
SP800-160-TE-IMPL
Implementation Process

Realize a specified system element, incorporating secure development and supply chain considerations.

Artefacts an auditor will ask for
  • Secure implementation and supply chain evidence
Where this commonly fails
  • Implementation not following secure practices
SP800-160-TE-INTEG
Integration Process

Synthesize a set of system elements into a realized system that satisfies security requirements and architecture.

Artefacts an auditor will ask for
  • Integration preserving security requirements
Where this commonly fails
  • Integration introduces unmitigated risk
SP800-160-TE-TRANS
Transition Process

Establish a capability for the system to provide services, including security services, in the operational environment.

Artefacts an auditor will ask for
  • Secure transition to operations evidence
Where this commonly fails
  • Security services not established at transition
SP800-160-TE-VALIDATE
Validation Process

Provide objective evidence that the system, when in use, fulfills its stakeholder protection needs in the intended environment.

Artefacts an auditor will ask for
  • Validation that protection needs are met in use
Where this commonly fails
  • Protection needs not validated operationally
SP800-160-TE-VERIFY
Verification Process

Provide objective evidence that the system fulfills its specified security requirements and characteristics.

Artefacts an auditor will ask for
  • Verification evidence against security requirements
Where this commonly fails
  • Security requirements not verified

Technical Management Processes

SE-CM
Configuration Management Process

Establish configuration management to identify, control, and account for the configuration of system elements that influence security properties.

Artefacts an auditor will ask for
  • Configuration management plan
  • Baseline documentation
  • Change control board records
  • Configuration item register
Where this commonly fails
  • Plan exists but not used
  • Baselines stale
  • CCB does not review security changes
SE-QA
Quality Assurance Process

Provide independent quality assurance over engineering activities including security engineering tasks, with corrective action when deviations are found.

Artefacts an auditor will ask for
  • QA plan
  • Independent review reports
  • Corrective action register
  • QA closure evidence
Where this commonly fails
  • QA not independent
  • Findings not closed
  • Security tasks excluded from QA scope
SE-RM
Risk Management Process

Manage risks across the system life cycle including identification, analysis, treatment, monitoring, and communication of security and resilience risks.

Artefacts an auditor will ask for
  • Risk management plan
  • Risk register entries with security context
  • Treatment decisions with rationale
  • Monitoring and reporting records
Where this commonly fails
  • Risks not updated as system evolves
  • Treatment decisions undocumented
  • Communications to authorities missing

Technical Processes

SE-ARCH
Architecture Definition

Define a system architecture that realises required security properties through identified principles, structures, and patterns, including trust boundaries and dependencies.

Artefacts an auditor will ask for
  • Architecture description document
  • Trust boundary diagrams
  • Security pattern catalogue applied
  • Dependency analysis
Where this commonly fails
  • No documented trust boundaries
  • Security properties not realised in architecture
  • Dependencies hidden
SE-DES
Design Definition

Develop a design that implements the architecture and specifies the components, interfaces, and security mechanisms required to satisfy system requirements.

Artefacts an auditor will ask for
  • Design specification
  • Component design documents
  • Interface control documents with security parameters
  • Mechanism selection rationale
Where this commonly fails
  • Security mechanisms unspecified
  • Interfaces lack contract
  • Design diverges from architecture
SE-DIS
Disposal

Dispose of the system and its data securely, ensuring that residual information cannot be recovered and that dependencies are addressed.

Artefacts an auditor will ask for
  • Disposal plan
  • Certificates of sanitisation or destruction
  • Dependency closure records
  • Final audit of decommission
Where this commonly fails
  • Sanitisation certificates not retained
  • Dependencies left active
  • No final audit
SE-IMP
Implementation

Implement the system in accordance with design and architecture using secure development practices that protect against introduction of weaknesses.

Artefacts an auditor will ask for
  • Secure development standards
  • Static and dynamic analysis results
  • Build pipeline configuration with integrity controls
  • Code review records
Where this commonly fails
  • No code review for security
  • Build pipeline lacks integrity controls
  • Standards not followed
SE-INT
Integration

Integrate system elements and verify that security properties hold across interfaces and that integration does not introduce new weaknesses.

Artefacts an auditor will ask for
  • Integration plan
  • Interface test results
  • Regression test suite results
  • Issue log from integration
Where this commonly fails
  • Interfaces tested only for function not security
  • No regression suite
  • Integration issues unresolved at release
SE-MNT
Maintenance

Maintain the system to sustain security properties through patching, configuration management, and corrective and adaptive changes.

Artefacts an auditor will ask for
  • Patch management procedure and records
  • Configuration baselines
  • Change records linked to risk assessments
  • Maintenance log
Where this commonly fails
  • Patches delayed without risk review
  • Baselines drift
  • Change records lack security review
SE-OP
Operation

Operate the system under defined security policies, monitor security state, and respond to events that may affect trustworthy operation.

Artefacts an auditor will ask for
  • Operations manual with security policy
  • Monitoring configuration and dashboards
  • Event response records
  • Operational readiness reviews
Where this commonly fails
  • No security monitoring in operations
  • Policies not followed
  • Events ignored
SE-SA
System Analysis

Perform analyses including security, dependability, and assurance analyses to evaluate design alternatives, trade-offs, and residual risk.

Artefacts an auditor will ask for
  • Security analysis reports
  • Trade-off study documents
  • Residual risk acceptance records
  • Assurance case fragments
Where this commonly fails
  • No trade-off rationale captured
  • Residual risk not accepted by an authority
  • Assurance evidence missing
SE-SN
Stakeholder Needs and Requirements Definition

Elicit, analyse, and document stakeholder needs and translate them into validated stakeholder requirements that capture protection needs and acceptable risk.

Artefacts an auditor will ask for
  • Stakeholder needs document
  • Requirements matrix with security entries
  • Validation records
  • Risk-informed acceptance criteria
Where this commonly fails
  • Security needs not elicited from operational stakeholders
  • No validation step
  • Acceptance criteria absent
SE-SR
System Requirements Definition

Transform stakeholder requirements into system requirements that specify the protections, properties, and behaviours necessary for trustworthy secure operation.

Artefacts an auditor will ask for
  • System requirements specification
  • Security properties catalogue
  • Verification criteria for each requirement
  • Traceability to stakeholder needs
Where this commonly fails
  • Security requirements vague
  • No verification criteria
  • Broken traceability
SE-TR
Transition

Transition the system from development to operation with secure deployment, training, and handover, ensuring security properties are preserved.

Artefacts an auditor will ask for
  • Deployment plan with security checks
  • Operator training records
  • Handover documents
  • Go-live security review
Where this commonly fails
  • Operators untrained
  • Security review skipped at go-live
  • No handover record
SE-VAL
Validation

Provide objective evidence that the system, when deployed in its operational environment, satisfies stakeholder needs including protection of mission and assets.

Artefacts an auditor will ask for
  • Validation plan
  • Operational test results
  • Stakeholder acceptance records
  • Evidence summary linked to needs
Where this commonly fails
  • No operational test
  • Acceptance signed without evidence
  • Evidence not retained
SE-VER
Verification

Confirm that the system meets specified security requirements through inspection, analysis, demonstration, and testing.

Artefacts an auditor will ask for
  • Verification plan
  • Test cases mapped to requirements
  • Verification results
  • Tool qualification records
Where this commonly fails
  • Coverage gaps between requirements and tests
  • Tools not qualified
  • Results not reviewed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-160 framework page.