NIST SP 800-171
Evidence request list. 88 controls, 88 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access Control
Limit access to authorised users, processes acting on behalf of users, and devices and document the rules that govern those limits across systems handling controlled unclassified information.
- Access control policy
- Account management procedure
- Authorisation records sampled across systems
- Periodic access reviews
- Policy not maintained
- Authorisations not recorded
- Reviews skipped
Apply least privilege and separation of duties to user accounts, administrative roles, and system processes that act on controlled unclassified information.
- Role definitions
- Privileged access management records
- Separation of duty matrices
- Periodic privilege reviews
- Shared admin accounts
- No separation between dev and prod
- Privilege creep
Authorise, monitor, and control remote access sessions and mobile device connections that handle controlled unclassified information.
- Remote access policy
- VPN and gateway configuration
- Mobile device management records
- Session monitoring logs
- Personal devices used without controls
- Session monitoring absent
- VPN does not enforce posture
Access Control Assessment
Assess that the organization verifies and controls connections to and use of external systems.
- List of external connections
- Interconnection security agreements
- Verification procedures
- Examine connection approvals
- Test connection enforcement
- SaaS connections not enumerated
- Vendor managed services missing ISA
- Personal device connections unverified
- No periodic verification of connections
Assess that the organization defines and manages account types, conditions for group and role membership, account approval, account creation, modification, enabling, disabling, and removal actions consistent with 800-171 R3 03.01.01.
- Account management procedure
- Account inventory export with attributes
- Role assignment records
- Approval ticket samples
- Joiner mover leaver evidence
- Assessor interview log
- Examine list of authorized users
- Sampling not documented
- Privileged accounts not separated from standard accounts during assessment
- No evidence of periodic recertification
- Service and shared accounts excluded from sample
Assess that the organization employs the principle of least privilege, allowing only authorized accesses for users and processes acting on behalf of users that are necessary to accomplish assigned organizational tasks.
- Privilege assignment matrix
- Recertification campaign output
- Sample of denied access requests
- Role to permission mapping
- Examine results for privileged roles
- Test results for elevation pathways
- Standing admin rights not justified
- Break glass accounts undocumented
- Cloud IAM roles not in assessment scope
- No test of segregation between duties
Assess that the organization establishes usage restrictions, configuration and connection requirements, and implementation guidance for each type of remote access permitted.
- VPN configuration
- MFA enforcement evidence
- Session logs sample
- Split tunneling policy
- Examine remote access types inventory
- Test results for connection encryption
- Vendor remote access not enumerated
- Always on VPN not tested
- Bastion host bypass paths missed
- No evidence of session termination after inactivity
Audit and Accountability
Create, protect, and retain system audit records to the extent necessary to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorised activity.
- Audit event catalogue
- Log protection configuration
- Retention schedule
- Storage architecture
- Events not selected based on risk
- Logs writable by admins
- Retention shorter than required
Review and analyse system audit records at a defined cadence for indications of inappropriate or unusual activity and report findings.
- Review schedule
- SIEM or log analytics configuration
- Sample review records
- Reports of findings
- Reviews not performed
- SIEM not tuned
- Findings not actioned
Audit and Accountability Assessment
Assess that the organization identifies the types of events that the system is capable of logging, specifies the events to be logged within the system, and reviews and updates the list of logged events.
- Loggable event matrix per system
- SIEM source list
- Periodic review minutes
- Examine log retention configuration
- Test sample log entries for required fields
- Cloud workload logs missing
- SaaS audit logs not enumerated
- No documented justification for excluded events
- Time synchronization not assessed
Authenticate (or verify) the identities of users, processes, or devices as a prerequisite to allowing access to organizational information systems.
- Authentication configuration
- Evidence identities are verified before access
- Shared accounts in use
- Weak verification for non-person entities
Awareness and Training
Provide basic security awareness to all users and role-based training to those with significant security responsibilities affecting controlled unclassified information.
- Training curriculum
- Completion records by role
- Role-based content modules
- Effectiveness measures
- Generic training only
- No role-based content
- Effectiveness untested
Configuration Management
Establish and maintain baseline configurations and inventories of systems that process, store, or transmit controlled unclassified information.
- Baseline configurations
- Inventory reports
- Change records
- Drift detection reports
- Baselines undocumented
- Inventory inaccurate
- Drift not detected
Identify information system users, processes acting on behalf of users, or devices.
- Identity inventory of users, processes, and devices
- Account management records
- Service/process accounts not inventoried
- Devices unidentified on the network
Configuration Management Assessment
Assess that the organization employs the principle of least functionality by configuring organizational systems to provide only essential capabilities.
- Service and port lists per system class
- Hardening guides applied
- Compliance scan output
- Examine disabled services
- Test for unnecessary functions
- Default services not disabled
- Cloud features enabled by default not reviewed
- Mobile app installations not restricted
- No allowlist for software
Assess that the organization develops, documents, and maintains under configuration control a current baseline configuration of the system.
- Approved baseline per platform
- Baseline review records
- Drift report sample
- Examine baseline content
- Test for unauthorized changes
- Container image baselines absent
- Workstation baseline outdated
- Baseline for hypervisors missing
- No version control over baseline artifacts
Assess that the organization establishes and documents configuration settings for system components that reflect the most restrictive mode consistent with operational requirements.
- CIS or DISA STIG benchmark
- Compliance scan results
- Exception register
- Examine hardening for sampled hosts
- Test against benchmark
- Exceptions without expiry dates
- Cloud platform baselines not benchmarked
- Mobile device hardening not assessed
- Network device configuration not tested
Identification and Authentication
Identify users, processes, and devices and authenticate their identities as a prerequisite to allowing access to systems handling controlled unclassified information.
- Identity directory configuration
- Authenticator policy
- Account lifecycle records
- Lockout configuration
- Weak password policy
- No account expiration
- Shared accounts present
Use multi-factor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
- MFA policy
- Coverage report for privileged and non-privileged accounts
- Authenticator type inventory
- Bypass records
- MFA not enforced for legacy systems
- SMS only authenticators
- Bypass not justified
Identification and Authentication Assessment
Assess that the organization uses multi factor authentication for local and network access to privileged accounts and for network access to non privileged accounts.
- MFA enforcement evidence
- Privileged account coverage report
- Authenticator type list
- Examine MFA scope
- Test for MFA bypass
- Legacy protocols bypass MFA
- Service accounts not addressed
- MFA not required for VPN admin
- SMS based authenticators still in use for privileged access
Assess that the organization implements multi factor authentication for access to privileged accounts and for network access to non privileged accounts.
- MFA enforcement policy export
- Privileged account MFA report
- Authenticator inventory
- Examine MFA configuration
- Test for bypass paths
- Legacy authentication protocols still enabled
- Service accounts excluded without justification
- Phishing resistant authenticator not used for high risk
- Recovery codes not protected
Incident Response
Establish an operational incident handling capability that includes preparation, detection, analysis, containment, recovery, and user response activities.
- Incident response plan
- Detection use cases
- Containment and recovery playbooks
- Tabletop exercise records
- No tested playbooks
- Detection limited to malware
- No after-action reviews
Track, document, and report incidents to designated officials and external authorities as required by contract and regulation.
- Internal reporting workflow
- External reporting obligations register
- Sample incident records
- Reporting timeliness metrics
- External reporting missed
- Documentation thin
- No timeliness measurement
Incident Response Assessment
Assess that the organization implements an incident handling capability that includes preparation, detection and analysis, containment, eradication, and recovery.
- IR plan with phases mapped
- Tabletop exercise after action
- Sample incident tickets
- Examine playbooks
- Test detection to containment timeline
- No CUI specific scenarios in exercises
- Vendor breach notification path untested
- Forensic readiness lacking
- Reporting timelines not measured
Maintenance
Perform maintenance on systems and require that maintenance activities are authorised, monitored, and conducted by appropriately cleared personnel.
- Maintenance procedure
- Personnel clearance or vetting records
- Maintenance activity logs
- Tool authorisation records
- Maintenance unrecorded
- Vendors not vetted
- Tools unmanaged
Maintenance Assessment
Assess that the organization approves, controls, and monitors maintenance tools used to maintain the system that processes CUI.
- Maintenance tool register
- Approval workflow output
- Tool scanning evidence
- Examine media check process
- Test for unauthorized tool introduction
- Vendor laptops not inventoried
- Diagnostic tools allowed over network without controls
- Removable media not scanned
- No record of tool removal
Media Protection
Protect system media that contain controlled unclassified information during storage, transport, and disposal, including marking, sanitisation, and access controls.
- Media handling procedure
- Marking standards and samples
- Transport logs
- Sanitisation records and certificates
- Marking inconsistent
- No transport logs
- Sanitisation certificates missing
Media Protection Assessment
Assess that the organization sanitizes or destroys system media containing CUI before disposal or release for reuse.
- Sanitization log per asset
- Certificate of destruction
- Method matrix mapped to media type
- Examine sanitization method selection
- Test residual data sampling
- Cloud tenant data sanitization not documented
- Verification step missing
- Mobile device wipe not validated
- Decommissioned media inventory incomplete
Assess that the organization sanitizes or destroys system media containing CUI before disposal or release for reuse.
- Sanitization log per asset
- Certificates of destruction
- NIST 800-88 verification
- Examine sanitization method matrix
- Test residual data on sample media
- Cloud tenant offboarding sanitization undocumented
- Mobile devices wiped without verification
- Decommissioned servers tracked manually
- Method not aligned to media type
NIST SP 800-171: Access Control & Identity
Store and transmit only cryptographically-protected representations of passwords.
- Password storage/transmission standard
- Evidence of hashing/encryption in transit
- Cleartext or reversible password storage
- Credentials transmitted unencrypted
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
- Replay-resistant mechanism configuration
- Legacy protocols vulnerable to replay still enabled
Establish an operational incident-handling capability including preparation, detection, analysis, containment, recovery, and user response activities.
- Incident response plan
- Evidence of preparation, detection, analysis, containment, recovery
- Plan exists but untested
- No defined roles for response
Track, document, and report incidents to appropriate officials and authorities both internal and external to the organization.
- Incident tracking records
- Internal and external reporting evidence
- Incidents not reported to required authorities
- No tracking/ticketing of incidents
Test the organizational incident response capability.
- Tabletop or live IR test reports
- No periodic IR testing
- Test findings not remediated
Perform maintenance on organizational information systems.
- Maintenance schedule and records
- Ad hoc maintenance without records
NIST SP 800-171: Audit & Accountability
Protect the confidentiality of CUI at rest.
- Encryption-at-rest configuration for CUI
- CUI at rest unencrypted
- Key management weaknesses
Identify, report, and correct information and information system flaws in a timely manner.
- Patch management records and timelines
- Flaws not corrected timely
- No flaw identification process
Provide protection from malicious code at appropriate locations within organizational information systems.
- Endpoint protection deployment and coverage
- Endpoints without malware protection
- Outdated signatures/engines
Monitor information system security alerts and advisories and take appropriate actions in response.
- Process for consuming and acting on alerts/advisories
- Advisories received but not actioned
Monitor the information system, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
- Network/host monitoring coverage for attack detection
- Inbound/outbound traffic not monitored
- No detection use cases
NIST SP 800-171: Configuration Management
Monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.
- Continuous monitoring strategy and reports
- Point-in-time only, no ongoing monitoring
Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of information systems.
- Network boundary architecture
- Firewall/proxy configurations
- Key internal boundaries unmonitored
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
- FIPS-validated module certificate references
- Non-FIPS crypto protecting CUI
- Validation certificates not tracked
Deny network communications traffic by default and allow network communications traffic by exception (deny all, permit by exception).
- Deny-by-default firewall rule base
- Permissive default-allow rules
- Unjustified exceptions
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
- Encryption-in-transit standard and coverage
- CUI transmitted unencrypted internally
- Weak cipher suites
NIST SP 800-171: Incident Response
Periodically assess the risk to organizational operations, assets, and individuals resulting from the operation of systems that process, store, or transmit CUI.
- Periodic risk assessment reports
- Risk assessments stale or not performed
- Scope excludes CUI systems
Scan for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified.
- Vulnerability scan reports and cadence
- Infrequent scanning
- Scan coverage gaps
Remediate vulnerabilities in accordance with assessments of risk.
- Remediation tracking tied to risk
- Vulnerabilities unremediated past SLA
- No risk-based prioritization
Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.
- Control assessment reports
- Controls assumed effective without assessment
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
- Plan of action and milestones (POA&M)
- POA&M not maintained or tracked to closure
NIST SP 800-171: Risk Assessment & Management
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
- Physical access control list and records
- Unescorted access to controlled areas
- Stale physical access lists
Escort visitors and monitor visitor activity.
- Visitor logs and escort procedures
- Visitors not escorted or logged
Enforce safeguarding measures for CUI at alternate work sites such as telework sites.
- Telework/alternate site safeguarding policy
- No safeguards defined for remote work sites
Screen individuals prior to authorizing access to information systems containing CUI.
- Pre-access screening records
- Access granted before screening completes
Ensure that CUI and information systems containing CUI are protected during and after personnel actions such as terminations and transfers.
- Termination/transfer checklists
- Access revocation evidence
- Access not revoked promptly on termination
NIST SP 800-171: System & Communications Protection
Provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
- Controls over maintenance tools, personnel, and techniques
- Maintenance tools not inspected
- Uncontrolled maintenance personnel access
Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when complete.
- MFA config for nonlocal maintenance sessions
- Session termination evidence
- Remote maintenance without MFA
- Sessions not terminated when complete
Protect (physically control and securely store) information system media containing CUI, both paper and digital.
- Media handling and storage procedures
- Paper CUI uncontrolled
- Media stored without physical security
Sanitize or destroy information system media containing CUI before disposal or release for reuse.
- Sanitization/destruction records and methods
- Media reused without sanitization
- No certificate of destruction
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected.
- Encryption config for media in transport
- Portable media unencrypted in transit
Control the use of removable media on information system components.
- Removable media control policy and technical enforcement
- USB ports unrestricted
- No device control software
Personnel Security Assessment
Assess that the organization ensures organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
- Termination checklist
- Access revocation timeline
- Asset retrieval log
- Examine transfer process
- Test for orphan accounts
- Contractor offboarding inconsistent
- SaaS account removal lag
- Privileged credentials not rotated post departure
- No formal transfer access review
Assess that on termination of individual employment the organization disables system access, terminates authenticators, and retrieves CUI assets.
- Termination ticket sample
- Access revocation timeline
- Asset return inventory
- Examine HR to IT integration
- Test for orphaned accounts
- Contractor terminations not tracked
- Same day access removal not consistent
- SaaS accounts orphaned after offboarding
- No exit interview record for CUI handlers
Physical Protection
Limit physical access to systems, equipment, and operating environments that handle controlled unclassified information to authorised individuals.
- Physical access policy
- Authorisation lists by area
- Visitor logs
- CCTV and access system records
- Authorisations not reviewed
- Visitor logs incomplete
- Monitoring not retained
Physical Protection Assessment
Assess that the organization enforces safeguarding measures for CUI at alternate work sites.
- Telework policy
- Acceptable use acknowledgment
- Physical control guidance for home offices
- Examine safeguard requirements
- Test compliance through attestation
- Home office safeguards not enforced
- Shared device use not addressed
- Lock and screen requirements absent
- No verification of alternate site controls
Physical and Environmental Protection Assessment
Assess that the organization limits physical access to the system, equipment, and the respective operating environments to authorized individuals.
- Authorized personnel list
- Badge access logs
- Visitor records
- Examine access list review evidence
- Test physical entry controls
- Colocation cage access not reviewed
- Visitor escort policy not enforced
- Cleaning crew access undocumented
- No tailgating mitigation tested
Planning
Assess that the organization develops a system security plan that describes the system boundary, environment of operation, security requirements, and relationships with other systems.
- Current SSP with version control
- Boundary and data flow diagrams
- CUI inventory by component
- Examine SSP completeness
- Test SSP accuracy against environment
- SSP not updated after architecture changes
- Cloud responsibility matrix absent
- External system connections undocumented
- CUI categorization not in SSP
Risk Assessment
Periodically assess risk to systems and the controlled unclassified information they process, store, and transmit, and update assessments after significant changes.
- Risk assessment methodology
- Periodic assessment reports
- Change-triggered reassessments
- Risk register entries
- Assessments overdue
- Methodology inconsistent
- No change triggers defined
Scan for vulnerabilities in systems and applications at a defined cadence and remediate identified vulnerabilities within risk-based timeframes.
- Scan coverage report
- Vulnerability backlog with SLAs
- Remediation records
- Verification scan results
- Coverage gaps
- SLAs missed without justification
- No verification of fixes
Assess that the organization periodically assesses the risk to organizational operations, organizational assets, and individuals resulting from the operation of systems and the associated processing, storage, or transmission of CUI.
- Annual risk assessment report
- Methodology documentation
- Risk register entries
- Examine threat catalog
- Test risk treatment evidence
- No CUI specific scope
- Risk register lacks owners
- Supply chain risks not assessed
- Frequency not documented
Assess that the organization scans for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
- Authenticated scan results
- Remediation tracking
- Scan schedule
- Examine scope completeness
- Test patch SLA
- Cloud images not scanned
- Authenticated scans not used consistently
- Web application scanning absent
- Patch backlog without justification
Assess that the organization periodically assesses the risk to organizational operations, organizational assets, and individuals resulting from the operation of systems and the associated processing, storage, or transmission of CUI.
- Annual risk assessment
- Threat catalog
- Risk register linked to CUI flows
- Examine methodology
- Test risk treatment evidence
- CUI specific scenarios absent
- Inherited risks from suppliers not assessed
- Risk acceptance lacks executive sign off
- Risk register stale
Assess that the organization monitors and scans for vulnerabilities in the system and hosted applications on a defined frequency and when new vulnerabilities affecting the system are identified.
- Authenticated scan results
- Patch SLA report
- Exception register
- Examine scan scope coverage
- Test remediation timelines
- Container images not scanned in registry
- Cloud workloads omitted
- False positives recycled without analyst review
- Patch backlog growing
Security Assessment
Assess that the organization periodically assesses the security controls in organizational systems to determine if the controls are effective in their application.
- Assessment plan
- Assessor independence statement
- Findings report
- Examine procedures
- Test evidence quality
- No defined frequency
- Plan of action not maintained
- Assessor independence unclear
- Procedures not tailored to environment
Assess that the organization periodically assesses the security requirements for organizational systems to determine if the requirements are effective in their application.
- Assessment plan with scope and procedures
- Assessor independence statement
- Findings report with evidence index
- Examine procedure mapping
- Test sampling rationale
- No defined assessment frequency
- Self assessment lacks evidence
- Plan of action and milestones stale
- Independence not documented for internal assessors
System and Communications Protection
Monitor and control communications at the external boundary of systems and at key internal boundaries that separate controlled unclassified information from other zones.
- Network architecture diagrams
- Firewall and gateway rule sets
- Monitoring configuration
- Rule review records
- Flat networks
- Rules not reviewed
- No internal segmentation
Implement validated encryption to protect the confidentiality of controlled unclassified information in transit and at rest where required.
- Encryption policy
- Validated module inventory
- Key management procedure
- Coverage matrix by data store and channel
- Unvalidated modules in use
- Keys stored alongside data
- Coverage gaps in backups
Assess that the organization employs FIPS validated cryptography when used to protect the confidentiality of CUI.
- FIPS module inventory with certificate numbers
- Module configuration evidence
- Key management policy
- Examine FIPS mode enablement
- Test cipher selection
- FIPS mode not enabled on endpoints
- Non FIPS libraries used in custom apps
- Cloud KMS settings not aligned
- Backup encryption module unclear
Assess that the organization implements subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
- Network diagrams
- Firewall rule sets
- Segmentation test results
- Examine DMZ design
- Test segmentation enforcement
- Flat networks remain in legacy environments
- Cloud network segmentation not validated
- East west traffic not restricted
- DMZ to internal exceptions
Assess that the organization implements cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
- TLS configuration scan
- VPN tunnel inventory
- FIPS module listings
- Examine encryption coverage
- Test for cleartext transmission
- Legacy SMB or FTP still active
- Internal traffic unencrypted
- Email transport encryption opportunistic
- FIPS validated module not used
Assess that the organization employs FIPS validated cryptography when used to protect the confidentiality of CUI.
- FIPS module list with certificate numbers
- Storage encryption coverage map
- Key management policy
- Examine database encryption
- Test for unencrypted CUI repositories
- Backup media not encrypted
- Key custodian roles unclear
- Cloud KMS key rotation gaps
- Object storage with public defaults
Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
- MFA enforcement policy and config
- Coverage report for privileged and network access
- MFA not enforced for all privileged access
- Exemptions without compensating controls
System and Information Integrity
Identify, report, and correct system flaws in a timely manner, including operating systems, applications, and firmware components.
- Patch management procedure
- Patch cadence schedule
- Exception register with risk acceptance
- Verification reports
- No firmware patching
- Exceptions never expire
- Verification absent
Provide protection from malicious code at appropriate locations in systems and update protections in response to new threats.
- Endpoint protection platform records
- Signature and engine update logs
- Detection response playbook
- Coverage reports
- Coverage gaps for servers
- Outdated signatures
- No response playbook
Assess that the organization identifies, reports, and corrects system flaws in a timely manner.
- Patch deployment reports
- Emergency patch records
- Patch testing evidence
- Examine SLA adherence
- Test missing patches sample
- Firmware not in scope
- Patch testing not documented
- Cloud images outdated
- Rollback procedures absent
Assess that the organization monitors organizational systems including inbound and outbound communications traffic to detect attacks and indicators of potential attacks.
- IDS or IPS configuration
- SIEM detection content
- EDR coverage report
- Examine traffic monitoring scope
- Test alert handling
- Outbound traffic monitoring absent
- Cloud egress visibility limited
- DNS monitoring not in place
- Endpoint coverage gaps
Assess that the organization identifies, reports, and corrects system flaws in a timely manner.
- Patch deployment reports
- Vulnerability to patch mapping
- Emergency patch evidence
- Examine SLA adherence
- Test patch verification
- Firmware updates not tracked
- OT and IoT excluded
- Patch testing not documented
- No rollback procedure tested
Assess that the organization monitors the system to detect attacks and indicators of potential attacks and unauthorized connections.
- SIEM detection content list
- EDR coverage report
- Alert triage records
- Examine detection efficacy metrics
- Test sample alerts to closure
- Cloud control plane events not monitored
- Lateral movement detections missing
- Coverage gaps on remote endpoints
- Alert fatigue documented but not addressed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-171 framework page.