Skip to content

Evidence request lists

NIST SP 800-171

Evidence request list. 88 controls, 88 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access Control

171-AC-1
Access Control Policy and Procedures

Limit access to authorised users, processes acting on behalf of users, and devices and document the rules that govern those limits across systems handling controlled unclassified information.

Artefacts an auditor will ask for
  • Access control policy
  • Account management procedure
  • Authorisation records sampled across systems
  • Periodic access reviews
Where this commonly fails
  • Policy not maintained
  • Authorisations not recorded
  • Reviews skipped
171-AC-2
Least Privilege and Separation of Duties

Apply least privilege and separation of duties to user accounts, administrative roles, and system processes that act on controlled unclassified information.

Artefacts an auditor will ask for
  • Role definitions
  • Privileged access management records
  • Separation of duty matrices
  • Periodic privilege reviews
Where this commonly fails
  • Shared admin accounts
  • No separation between dev and prod
  • Privilege creep
171-AC-3
Remote Access and Mobile Devices

Authorise, monitor, and control remote access sessions and mobile device connections that handle controlled unclassified information.

Artefacts an auditor will ask for
  • Remote access policy
  • VPN and gateway configuration
  • Mobile device management records
  • Session monitoring logs
Where this commonly fails
  • Personal devices used without controls
  • Session monitoring absent
  • VPN does not enforce posture

Access Control Assessment

3.1.20
External Connections Control

Assess that the organization verifies and controls connections to and use of external systems.

Artefacts an auditor will ask for
  • List of external connections
  • Interconnection security agreements
  • Verification procedures
  • Examine connection approvals
  • Test connection enforcement
Where this commonly fails
  • SaaS connections not enumerated
  • Vendor managed services missing ISA
  • Personal device connections unverified
  • No periodic verification of connections
A.03.01.01
Account Management Assessment

Assess that the organization defines and manages account types, conditions for group and role membership, account approval, account creation, modification, enabling, disabling, and removal actions consistent with 800-171 R3 03.01.01.

Artefacts an auditor will ask for
  • Account management procedure
  • Account inventory export with attributes
  • Role assignment records
  • Approval ticket samples
  • Joiner mover leaver evidence
  • Assessor interview log
  • Examine list of authorized users
Where this commonly fails
  • Sampling not documented
  • Privileged accounts not separated from standard accounts during assessment
  • No evidence of periodic recertification
  • Service and shared accounts excluded from sample
A.03.01.05
Least Privilege Assessment

Assess that the organization employs the principle of least privilege, allowing only authorized accesses for users and processes acting on behalf of users that are necessary to accomplish assigned organizational tasks.

Artefacts an auditor will ask for
  • Privilege assignment matrix
  • Recertification campaign output
  • Sample of denied access requests
  • Role to permission mapping
  • Examine results for privileged roles
  • Test results for elevation pathways
Where this commonly fails
  • Standing admin rights not justified
  • Break glass accounts undocumented
  • Cloud IAM roles not in assessment scope
  • No test of segregation between duties
A.03.01.12
Remote Access Assessment

Assess that the organization establishes usage restrictions, configuration and connection requirements, and implementation guidance for each type of remote access permitted.

Artefacts an auditor will ask for
  • VPN configuration
  • MFA enforcement evidence
  • Session logs sample
  • Split tunneling policy
  • Examine remote access types inventory
  • Test results for connection encryption
Where this commonly fails
  • Vendor remote access not enumerated
  • Always on VPN not tested
  • Bastion host bypass paths missed
  • No evidence of session termination after inactivity

Audit and Accountability

171-AU-1
Audit Event Capture

Create, protect, and retain system audit records to the extent necessary to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorised activity.

Artefacts an auditor will ask for
  • Audit event catalogue
  • Log protection configuration
  • Retention schedule
  • Storage architecture
Where this commonly fails
  • Events not selected based on risk
  • Logs writable by admins
  • Retention shorter than required
171-AU-2
Audit Review and Analysis

Review and analyse system audit records at a defined cadence for indications of inappropriate or unusual activity and report findings.

Artefacts an auditor will ask for
  • Review schedule
  • SIEM or log analytics configuration
  • Sample review records
  • Reports of findings
Where this commonly fails
  • Reviews not performed
  • SIEM not tuned
  • Findings not actioned

Audit and Accountability Assessment

A.03.03.01
Event Logging Assessment

Assess that the organization identifies the types of events that the system is capable of logging, specifies the events to be logged within the system, and reviews and updates the list of logged events.

Artefacts an auditor will ask for
  • Loggable event matrix per system
  • SIEM source list
  • Periodic review minutes
  • Examine log retention configuration
  • Test sample log entries for required fields
Where this commonly fails
  • Cloud workload logs missing
  • SaaS audit logs not enumerated
  • No documented justification for excluded events
  • Time synchronization not assessed
SP800-171-3.5.2
Authenticate identities before access

Authenticate (or verify) the identities of users, processes, or devices as a prerequisite to allowing access to organizational information systems.

Artefacts an auditor will ask for
  • Authentication configuration
  • Evidence identities are verified before access
Where this commonly fails
  • Shared accounts in use
  • Weak verification for non-person entities

Awareness and Training

171-AT-1
Security Awareness and Role-Based Training

Provide basic security awareness to all users and role-based training to those with significant security responsibilities affecting controlled unclassified information.

Artefacts an auditor will ask for
  • Training curriculum
  • Completion records by role
  • Role-based content modules
  • Effectiveness measures
Where this commonly fails
  • Generic training only
  • No role-based content
  • Effectiveness untested

Configuration Management

171-CM-1
Baseline Configuration and Inventory

Establish and maintain baseline configurations and inventories of systems that process, store, or transmit controlled unclassified information.

Artefacts an auditor will ask for
  • Baseline configurations
  • Inventory reports
  • Change records
  • Drift detection reports
Where this commonly fails
  • Baselines undocumented
  • Inventory inaccurate
  • Drift not detected
SP800-171-3.5.1
Identify system users, processes, and devices

Identify information system users, processes acting on behalf of users, or devices.

Artefacts an auditor will ask for
  • Identity inventory of users, processes, and devices
  • Account management records
Where this commonly fails
  • Service/process accounts not inventoried
  • Devices unidentified on the network

Configuration Management Assessment

3.4.6
Least Functionality

Assess that the organization employs the principle of least functionality by configuring organizational systems to provide only essential capabilities.

Artefacts an auditor will ask for
  • Service and port lists per system class
  • Hardening guides applied
  • Compliance scan output
  • Examine disabled services
  • Test for unnecessary functions
Where this commonly fails
  • Default services not disabled
  • Cloud features enabled by default not reviewed
  • Mobile app installations not restricted
  • No allowlist for software
A.03.04.01
Baseline Configuration Assessment

Assess that the organization develops, documents, and maintains under configuration control a current baseline configuration of the system.

Artefacts an auditor will ask for
  • Approved baseline per platform
  • Baseline review records
  • Drift report sample
  • Examine baseline content
  • Test for unauthorized changes
Where this commonly fails
  • Container image baselines absent
  • Workstation baseline outdated
  • Baseline for hypervisors missing
  • No version control over baseline artifacts
A.03.04.02
Configuration Settings Assessment

Assess that the organization establishes and documents configuration settings for system components that reflect the most restrictive mode consistent with operational requirements.

Artefacts an auditor will ask for
  • CIS or DISA STIG benchmark
  • Compliance scan results
  • Exception register
  • Examine hardening for sampled hosts
  • Test against benchmark
Where this commonly fails
  • Exceptions without expiry dates
  • Cloud platform baselines not benchmarked
  • Mobile device hardening not assessed
  • Network device configuration not tested

Identification and Authentication

171-IA-1
Identification and Authentication

Identify users, processes, and devices and authenticate their identities as a prerequisite to allowing access to systems handling controlled unclassified information.

Artefacts an auditor will ask for
  • Identity directory configuration
  • Authenticator policy
  • Account lifecycle records
  • Lockout configuration
Where this commonly fails
  • Weak password policy
  • No account expiration
  • Shared accounts present
171-IA-2
Multi-Factor Authentication

Use multi-factor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

Artefacts an auditor will ask for
  • MFA policy
  • Coverage report for privileged and non-privileged accounts
  • Authenticator type inventory
  • Bypass records
Where this commonly fails
  • MFA not enforced for legacy systems
  • SMS only authenticators
  • Bypass not justified

Identification and Authentication Assessment

3.5.3
Multi Factor Authentication

Assess that the organization uses multi factor authentication for local and network access to privileged accounts and for network access to non privileged accounts.

Artefacts an auditor will ask for
  • MFA enforcement evidence
  • Privileged account coverage report
  • Authenticator type list
  • Examine MFA scope
  • Test for MFA bypass
Where this commonly fails
  • Legacy protocols bypass MFA
  • Service accounts not addressed
  • MFA not required for VPN admin
  • SMS based authenticators still in use for privileged access
A.03.05.03
Multi Factor Authentication Assessment

Assess that the organization implements multi factor authentication for access to privileged accounts and for network access to non privileged accounts.

Artefacts an auditor will ask for
  • MFA enforcement policy export
  • Privileged account MFA report
  • Authenticator inventory
  • Examine MFA configuration
  • Test for bypass paths
Where this commonly fails
  • Legacy authentication protocols still enabled
  • Service accounts excluded without justification
  • Phishing resistant authenticator not used for high risk
  • Recovery codes not protected

Incident Response

171-IR-1
Incident Handling Capability

Establish an operational incident handling capability that includes preparation, detection, analysis, containment, recovery, and user response activities.

Artefacts an auditor will ask for
  • Incident response plan
  • Detection use cases
  • Containment and recovery playbooks
  • Tabletop exercise records
Where this commonly fails
  • No tested playbooks
  • Detection limited to malware
  • No after-action reviews
171-IR-2
Incident Reporting

Track, document, and report incidents to designated officials and external authorities as required by contract and regulation.

Artefacts an auditor will ask for
  • Internal reporting workflow
  • External reporting obligations register
  • Sample incident records
  • Reporting timeliness metrics
Where this commonly fails
  • External reporting missed
  • Documentation thin
  • No timeliness measurement

Incident Response Assessment

A.03.06.01
Incident Handling Assessment

Assess that the organization implements an incident handling capability that includes preparation, detection and analysis, containment, eradication, and recovery.

Artefacts an auditor will ask for
  • IR plan with phases mapped
  • Tabletop exercise after action
  • Sample incident tickets
  • Examine playbooks
  • Test detection to containment timeline
Where this commonly fails
  • No CUI specific scenarios in exercises
  • Vendor breach notification path untested
  • Forensic readiness lacking
  • Reporting timelines not measured

Maintenance

171-MA-1
Maintenance Authorisation and Control

Perform maintenance on systems and require that maintenance activities are authorised, monitored, and conducted by appropriately cleared personnel.

Artefacts an auditor will ask for
  • Maintenance procedure
  • Personnel clearance or vetting records
  • Maintenance activity logs
  • Tool authorisation records
Where this commonly fails
  • Maintenance unrecorded
  • Vendors not vetted
  • Tools unmanaged

Maintenance Assessment

A.03.07.04
Maintenance Tools Assessment

Assess that the organization approves, controls, and monitors maintenance tools used to maintain the system that processes CUI.

Artefacts an auditor will ask for
  • Maintenance tool register
  • Approval workflow output
  • Tool scanning evidence
  • Examine media check process
  • Test for unauthorized tool introduction
Where this commonly fails
  • Vendor laptops not inventoried
  • Diagnostic tools allowed over network without controls
  • Removable media not scanned
  • No record of tool removal

Media Protection

171-MP-1
Media Protection

Protect system media that contain controlled unclassified information during storage, transport, and disposal, including marking, sanitisation, and access controls.

Artefacts an auditor will ask for
  • Media handling procedure
  • Marking standards and samples
  • Transport logs
  • Sanitisation records and certificates
Where this commonly fails
  • Marking inconsistent
  • No transport logs
  • Sanitisation certificates missing

Media Protection Assessment

3.8.3
Media Sanitization

Assess that the organization sanitizes or destroys system media containing CUI before disposal or release for reuse.

Artefacts an auditor will ask for
  • Sanitization log per asset
  • Certificate of destruction
  • Method matrix mapped to media type
  • Examine sanitization method selection
  • Test residual data sampling
Where this commonly fails
  • Cloud tenant data sanitization not documented
  • Verification step missing
  • Mobile device wipe not validated
  • Decommissioned media inventory incomplete
A.03.08.03
Media Sanitization Assessment

Assess that the organization sanitizes or destroys system media containing CUI before disposal or release for reuse.

Artefacts an auditor will ask for
  • Sanitization log per asset
  • Certificates of destruction
  • NIST 800-88 verification
  • Examine sanitization method matrix
  • Test residual data on sample media
Where this commonly fails
  • Cloud tenant offboarding sanitization undocumented
  • Mobile devices wiped without verification
  • Decommissioned servers tracked manually
  • Method not aligned to media type

NIST SP 800-171: Access Control & Identity

SP800-171-3.5.10
Store and transmit only encrypted passwords

Store and transmit only cryptographically-protected representations of passwords.

Artefacts an auditor will ask for
  • Password storage/transmission standard
  • Evidence of hashing/encryption in transit
Where this commonly fails
  • Cleartext or reversible password storage
  • Credentials transmitted unencrypted
SP800-171-3.5.4
Replay-resistant authentication

Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

Artefacts an auditor will ask for
  • Replay-resistant mechanism configuration
Where this commonly fails
  • Legacy protocols vulnerable to replay still enabled
SP800-171-3.6.1
Operational incident-handling capability

Establish an operational incident-handling capability including preparation, detection, analysis, containment, recovery, and user response activities.

Artefacts an auditor will ask for
  • Incident response plan
  • Evidence of preparation, detection, analysis, containment, recovery
Where this commonly fails
  • Plan exists but untested
  • No defined roles for response
SP800-171-3.6.2
Track, document, and report incidents

Track, document, and report incidents to appropriate officials and authorities both internal and external to the organization.

Artefacts an auditor will ask for
  • Incident tracking records
  • Internal and external reporting evidence
Where this commonly fails
  • Incidents not reported to required authorities
  • No tracking/ticketing of incidents
SP800-171-3.6.3
Test incident response capability

Test the organizational incident response capability.

Artefacts an auditor will ask for
  • Tabletop or live IR test reports
Where this commonly fails
  • No periodic IR testing
  • Test findings not remediated
SP800-171-3.7.1
Perform system maintenance

Perform maintenance on organizational information systems.

Artefacts an auditor will ask for
  • Maintenance schedule and records
Where this commonly fails
  • Ad hoc maintenance without records

NIST SP 800-171: Audit & Accountability

SP800-171-3.13.16
Protect confidentiality of CUI at rest

Protect the confidentiality of CUI at rest.

Artefacts an auditor will ask for
  • Encryption-at-rest configuration for CUI
Where this commonly fails
  • CUI at rest unencrypted
  • Key management weaknesses
SP800-171-3.14.1
Identify, report, and correct flaws

Identify, report, and correct information and information system flaws in a timely manner.

Artefacts an auditor will ask for
  • Patch management records and timelines
Where this commonly fails
  • Flaws not corrected timely
  • No flaw identification process
SP800-171-3.14.2
Malicious code protection

Provide protection from malicious code at appropriate locations within organizational information systems.

Artefacts an auditor will ask for
  • Endpoint protection deployment and coverage
Where this commonly fails
  • Endpoints without malware protection
  • Outdated signatures/engines
SP800-171-3.14.3
Monitor security alerts and advisories

Monitor information system security alerts and advisories and take appropriate actions in response.

Artefacts an auditor will ask for
  • Process for consuming and acting on alerts/advisories
Where this commonly fails
  • Advisories received but not actioned
SP800-171-3.14.6
Monitor systems and traffic for attacks

Monitor the information system, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

Artefacts an auditor will ask for
  • Network/host monitoring coverage for attack detection
Where this commonly fails
  • Inbound/outbound traffic not monitored
  • No detection use cases

NIST SP 800-171: Configuration Management

SP800-171-3.12.3
Continuously monitor controls

Monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.

Artefacts an auditor will ask for
  • Continuous monitoring strategy and reports
Where this commonly fails
  • Point-in-time only, no ongoing monitoring
SP800-171-3.13.1
Monitor and protect communications at boundaries

Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of information systems.

Artefacts an auditor will ask for
  • Network boundary architecture
  • Firewall/proxy configurations
Where this commonly fails
  • Key internal boundaries unmonitored
SP800-171-3.13.11
Employ FIPS-validated cryptography

Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

Artefacts an auditor will ask for
  • FIPS-validated module certificate references
Where this commonly fails
  • Non-FIPS crypto protecting CUI
  • Validation certificates not tracked
SP800-171-3.13.6
Deny network traffic by default

Deny network communications traffic by default and allow network communications traffic by exception (deny all, permit by exception).

Artefacts an auditor will ask for
  • Deny-by-default firewall rule base
Where this commonly fails
  • Permissive default-allow rules
  • Unjustified exceptions
SP800-171-3.13.8
Encrypt CUI in transmission

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

Artefacts an auditor will ask for
  • Encryption-in-transit standard and coverage
Where this commonly fails
  • CUI transmitted unencrypted internally
  • Weak cipher suites

NIST SP 800-171: Incident Response

SP800-171-3.11.1
Periodically assess risk

Periodically assess the risk to organizational operations, assets, and individuals resulting from the operation of systems that process, store, or transmit CUI.

Artefacts an auditor will ask for
  • Periodic risk assessment reports
Where this commonly fails
  • Risk assessments stale or not performed
  • Scope excludes CUI systems
SP800-171-3.11.2
Scan for vulnerabilities

Scan for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified.

Artefacts an auditor will ask for
  • Vulnerability scan reports and cadence
Where this commonly fails
  • Infrequent scanning
  • Scan coverage gaps
SP800-171-3.11.3
Remediate vulnerabilities

Remediate vulnerabilities in accordance with assessments of risk.

Artefacts an auditor will ask for
  • Remediation tracking tied to risk
Where this commonly fails
  • Vulnerabilities unremediated past SLA
  • No risk-based prioritization
SP800-171-3.12.1
Periodically assess security controls

Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.

Artefacts an auditor will ask for
  • Control assessment reports
Where this commonly fails
  • Controls assumed effective without assessment
SP800-171-3.12.2
Plans of action for deficiencies

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

Artefacts an auditor will ask for
  • Plan of action and milestones (POA&M)
Where this commonly fails
  • POA&M not maintained or tracked to closure

NIST SP 800-171: Risk Assessment & Management

SP800-171-3.10.1
Limit physical access

Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

Artefacts an auditor will ask for
  • Physical access control list and records
Where this commonly fails
  • Unescorted access to controlled areas
  • Stale physical access lists
SP800-171-3.10.3
Escort and monitor visitors

Escort visitors and monitor visitor activity.

Artefacts an auditor will ask for
  • Visitor logs and escort procedures
Where this commonly fails
  • Visitors not escorted or logged
SP800-171-3.10.6
Safeguard CUI at alternate work sites

Enforce safeguarding measures for CUI at alternate work sites such as telework sites.

Artefacts an auditor will ask for
  • Telework/alternate site safeguarding policy
Where this commonly fails
  • No safeguards defined for remote work sites
SP800-171-3.9.1
Screen individuals before CUI access

Screen individuals prior to authorizing access to information systems containing CUI.

Artefacts an auditor will ask for
  • Pre-access screening records
Where this commonly fails
  • Access granted before screening completes
SP800-171-3.9.2
Protect CUI during personnel actions

Ensure that CUI and information systems containing CUI are protected during and after personnel actions such as terminations and transfers.

Artefacts an auditor will ask for
  • Termination/transfer checklists
  • Access revocation evidence
Where this commonly fails
  • Access not revoked promptly on termination

NIST SP 800-171: System & Communications Protection

SP800-171-3.7.2
Control maintenance tools and personnel

Provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

Artefacts an auditor will ask for
  • Controls over maintenance tools, personnel, and techniques
Where this commonly fails
  • Maintenance tools not inspected
  • Uncontrolled maintenance personnel access
SP800-171-3.7.5
MFA for nonlocal maintenance

Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when complete.

Artefacts an auditor will ask for
  • MFA config for nonlocal maintenance sessions
  • Session termination evidence
Where this commonly fails
  • Remote maintenance without MFA
  • Sessions not terminated when complete
SP800-171-3.8.1
Protect system media containing CUI

Protect (physically control and securely store) information system media containing CUI, both paper and digital.

Artefacts an auditor will ask for
  • Media handling and storage procedures
Where this commonly fails
  • Paper CUI uncontrolled
  • Media stored without physical security
SP800-171-3.8.3
Sanitize or destroy media before disposal

Sanitize or destroy information system media containing CUI before disposal or release for reuse.

Artefacts an auditor will ask for
  • Sanitization/destruction records and methods
Where this commonly fails
  • Media reused without sanitization
  • No certificate of destruction
SP800-171-3.8.6
Encrypt CUI on digital media during transport

Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected.

Artefacts an auditor will ask for
  • Encryption config for media in transport
Where this commonly fails
  • Portable media unencrypted in transit
SP800-171-3.8.7
Control removable media

Control the use of removable media on information system components.

Artefacts an auditor will ask for
  • Removable media control policy and technical enforcement
Where this commonly fails
  • USB ports unrestricted
  • No device control software

Personnel Security Assessment

3.9.2
Personnel Transfer and Termination

Assess that the organization ensures organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.

Artefacts an auditor will ask for
  • Termination checklist
  • Access revocation timeline
  • Asset retrieval log
  • Examine transfer process
  • Test for orphan accounts
Where this commonly fails
  • Contractor offboarding inconsistent
  • SaaS account removal lag
  • Privileged credentials not rotated post departure
  • No formal transfer access review
A.03.09.02
Personnel Termination Assessment

Assess that on termination of individual employment the organization disables system access, terminates authenticators, and retrieves CUI assets.

Artefacts an auditor will ask for
  • Termination ticket sample
  • Access revocation timeline
  • Asset return inventory
  • Examine HR to IT integration
  • Test for orphaned accounts
Where this commonly fails
  • Contractor terminations not tracked
  • Same day access removal not consistent
  • SaaS accounts orphaned after offboarding
  • No exit interview record for CUI handlers

Physical Protection

171-PE-1
Physical Access Authorisations

Limit physical access to systems, equipment, and operating environments that handle controlled unclassified information to authorised individuals.

Artefacts an auditor will ask for
  • Physical access policy
  • Authorisation lists by area
  • Visitor logs
  • CCTV and access system records
Where this commonly fails
  • Authorisations not reviewed
  • Visitor logs incomplete
  • Monitoring not retained

Physical Protection Assessment

3.10.6
Alternate Work Site Safeguards

Assess that the organization enforces safeguarding measures for CUI at alternate work sites.

Artefacts an auditor will ask for
  • Telework policy
  • Acceptable use acknowledgment
  • Physical control guidance for home offices
  • Examine safeguard requirements
  • Test compliance through attestation
Where this commonly fails
  • Home office safeguards not enforced
  • Shared device use not addressed
  • Lock and screen requirements absent
  • No verification of alternate site controls

Physical and Environmental Protection Assessment

A.03.10.01
Physical Access Authorization Assessment

Assess that the organization limits physical access to the system, equipment, and the respective operating environments to authorized individuals.

Artefacts an auditor will ask for
  • Authorized personnel list
  • Badge access logs
  • Visitor records
  • Examine access list review evidence
  • Test physical entry controls
Where this commonly fails
  • Colocation cage access not reviewed
  • Visitor escort policy not enforced
  • Cleaning crew access undocumented
  • No tailgating mitigation tested

Planning

A.03.15.01
System Security Plan Assessment

Assess that the organization develops a system security plan that describes the system boundary, environment of operation, security requirements, and relationships with other systems.

Artefacts an auditor will ask for
  • Current SSP with version control
  • Boundary and data flow diagrams
  • CUI inventory by component
  • Examine SSP completeness
  • Test SSP accuracy against environment
Where this commonly fails
  • SSP not updated after architecture changes
  • Cloud responsibility matrix absent
  • External system connections undocumented
  • CUI categorization not in SSP

Risk Assessment

171-RA-1
Risk Assessment

Periodically assess risk to systems and the controlled unclassified information they process, store, and transmit, and update assessments after significant changes.

Artefacts an auditor will ask for
  • Risk assessment methodology
  • Periodic assessment reports
  • Change-triggered reassessments
  • Risk register entries
Where this commonly fails
  • Assessments overdue
  • Methodology inconsistent
  • No change triggers defined
171-RA-2
Vulnerability Scanning and Remediation

Scan for vulnerabilities in systems and applications at a defined cadence and remediate identified vulnerabilities within risk-based timeframes.

Artefacts an auditor will ask for
  • Scan coverage report
  • Vulnerability backlog with SLAs
  • Remediation records
  • Verification scan results
Where this commonly fails
  • Coverage gaps
  • SLAs missed without justification
  • No verification of fixes
3.11.1
Risk Assessments

Assess that the organization periodically assesses the risk to organizational operations, organizational assets, and individuals resulting from the operation of systems and the associated processing, storage, or transmission of CUI.

Artefacts an auditor will ask for
  • Annual risk assessment report
  • Methodology documentation
  • Risk register entries
  • Examine threat catalog
  • Test risk treatment evidence
Where this commonly fails
  • No CUI specific scope
  • Risk register lacks owners
  • Supply chain risks not assessed
  • Frequency not documented
3.11.2
Vulnerability Scanning

Assess that the organization scans for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

Artefacts an auditor will ask for
  • Authenticated scan results
  • Remediation tracking
  • Scan schedule
  • Examine scope completeness
  • Test patch SLA
Where this commonly fails
  • Cloud images not scanned
  • Authenticated scans not used consistently
  • Web application scanning absent
  • Patch backlog without justification
A.03.11.01
Risk Assessment Process

Assess that the organization periodically assesses the risk to organizational operations, organizational assets, and individuals resulting from the operation of systems and the associated processing, storage, or transmission of CUI.

Artefacts an auditor will ask for
  • Annual risk assessment
  • Threat catalog
  • Risk register linked to CUI flows
  • Examine methodology
  • Test risk treatment evidence
Where this commonly fails
  • CUI specific scenarios absent
  • Inherited risks from suppliers not assessed
  • Risk acceptance lacks executive sign off
  • Risk register stale
A.03.11.02
Vulnerability Monitoring Assessment

Assess that the organization monitors and scans for vulnerabilities in the system and hosted applications on a defined frequency and when new vulnerabilities affecting the system are identified.

Artefacts an auditor will ask for
  • Authenticated scan results
  • Patch SLA report
  • Exception register
  • Examine scan scope coverage
  • Test remediation timelines
Where this commonly fails
  • Container images not scanned in registry
  • Cloud workloads omitted
  • False positives recycled without analyst review
  • Patch backlog growing

Security Assessment

3.12.1
Security Control Assessment

Assess that the organization periodically assesses the security controls in organizational systems to determine if the controls are effective in their application.

Artefacts an auditor will ask for
  • Assessment plan
  • Assessor independence statement
  • Findings report
  • Examine procedures
  • Test evidence quality
Where this commonly fails
  • No defined frequency
  • Plan of action not maintained
  • Assessor independence unclear
  • Procedures not tailored to environment
A.03.12.01
Security Control Assessments

Assess that the organization periodically assesses the security requirements for organizational systems to determine if the requirements are effective in their application.

Artefacts an auditor will ask for
  • Assessment plan with scope and procedures
  • Assessor independence statement
  • Findings report with evidence index
  • Examine procedure mapping
  • Test sampling rationale
Where this commonly fails
  • No defined assessment frequency
  • Self assessment lacks evidence
  • Plan of action and milestones stale
  • Independence not documented for internal assessors

System and Communications Protection

171-SC-1
Boundary Protection

Monitor and control communications at the external boundary of systems and at key internal boundaries that separate controlled unclassified information from other zones.

Artefacts an auditor will ask for
  • Network architecture diagrams
  • Firewall and gateway rule sets
  • Monitoring configuration
  • Rule review records
Where this commonly fails
  • Flat networks
  • Rules not reviewed
  • No internal segmentation
171-SC-2
Encryption of Controlled Unclassified Information

Implement validated encryption to protect the confidentiality of controlled unclassified information in transit and at rest where required.

Artefacts an auditor will ask for
  • Encryption policy
  • Validated module inventory
  • Key management procedure
  • Coverage matrix by data store and channel
Where this commonly fails
  • Unvalidated modules in use
  • Keys stored alongside data
  • Coverage gaps in backups
3.13.11
Cryptographic Protection

Assess that the organization employs FIPS validated cryptography when used to protect the confidentiality of CUI.

Artefacts an auditor will ask for
  • FIPS module inventory with certificate numbers
  • Module configuration evidence
  • Key management policy
  • Examine FIPS mode enablement
  • Test cipher selection
Where this commonly fails
  • FIPS mode not enabled on endpoints
  • Non FIPS libraries used in custom apps
  • Cloud KMS settings not aligned
  • Backup encryption module unclear
3.13.5
Network Segmentation

Assess that the organization implements subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

Artefacts an auditor will ask for
  • Network diagrams
  • Firewall rule sets
  • Segmentation test results
  • Examine DMZ design
  • Test segmentation enforcement
Where this commonly fails
  • Flat networks remain in legacy environments
  • Cloud network segmentation not validated
  • East west traffic not restricted
  • DMZ to internal exceptions
3.13.8
Transmission Confidentiality

Assess that the organization implements cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

Artefacts an auditor will ask for
  • TLS configuration scan
  • VPN tunnel inventory
  • FIPS module listings
  • Examine encryption coverage
  • Test for cleartext transmission
Where this commonly fails
  • Legacy SMB or FTP still active
  • Internal traffic unencrypted
  • Email transport encryption opportunistic
  • FIPS validated module not used
A.03.13.11
Cryptographic Protection of CUI at Rest

Assess that the organization employs FIPS validated cryptography when used to protect the confidentiality of CUI.

Artefacts an auditor will ask for
  • FIPS module list with certificate numbers
  • Storage encryption coverage map
  • Key management policy
  • Examine database encryption
  • Test for unencrypted CUI repositories
Where this commonly fails
  • Backup media not encrypted
  • Key custodian roles unclear
  • Cloud KMS key rotation gaps
  • Object storage with public defaults
SP800-171-3.5.3
Multifactor authentication for privileged/network access

Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

Artefacts an auditor will ask for
  • MFA enforcement policy and config
  • Coverage report for privileged and network access
Where this commonly fails
  • MFA not enforced for all privileged access
  • Exemptions without compensating controls

System and Information Integrity

171-SI-1
Flaw Remediation

Identify, report, and correct system flaws in a timely manner, including operating systems, applications, and firmware components.

Artefacts an auditor will ask for
  • Patch management procedure
  • Patch cadence schedule
  • Exception register with risk acceptance
  • Verification reports
Where this commonly fails
  • No firmware patching
  • Exceptions never expire
  • Verification absent
171-SI-2
Malicious Code Protection

Provide protection from malicious code at appropriate locations in systems and update protections in response to new threats.

Artefacts an auditor will ask for
  • Endpoint protection platform records
  • Signature and engine update logs
  • Detection response playbook
  • Coverage reports
Where this commonly fails
  • Coverage gaps for servers
  • Outdated signatures
  • No response playbook
3.14.1
Flaw Remediation

Assess that the organization identifies, reports, and corrects system flaws in a timely manner.

Artefacts an auditor will ask for
  • Patch deployment reports
  • Emergency patch records
  • Patch testing evidence
  • Examine SLA adherence
  • Test missing patches sample
Where this commonly fails
  • Firmware not in scope
  • Patch testing not documented
  • Cloud images outdated
  • Rollback procedures absent
3.14.6
Monitoring for Attacks

Assess that the organization monitors organizational systems including inbound and outbound communications traffic to detect attacks and indicators of potential attacks.

Artefacts an auditor will ask for
  • IDS or IPS configuration
  • SIEM detection content
  • EDR coverage report
  • Examine traffic monitoring scope
  • Test alert handling
Where this commonly fails
  • Outbound traffic monitoring absent
  • Cloud egress visibility limited
  • DNS monitoring not in place
  • Endpoint coverage gaps
A.03.14.01
Flaw Remediation Assessment

Assess that the organization identifies, reports, and corrects system flaws in a timely manner.

Artefacts an auditor will ask for
  • Patch deployment reports
  • Vulnerability to patch mapping
  • Emergency patch evidence
  • Examine SLA adherence
  • Test patch verification
Where this commonly fails
  • Firmware updates not tracked
  • OT and IoT excluded
  • Patch testing not documented
  • No rollback procedure tested
A.03.14.06
System Monitoring Assessment

Assess that the organization monitors the system to detect attacks and indicators of potential attacks and unauthorized connections.

Artefacts an auditor will ask for
  • SIEM detection content list
  • EDR coverage report
  • Alert triage records
  • Examine detection efficacy metrics
  • Test sample alerts to closure
Where this commonly fails
  • Cloud control plane events not monitored
  • Lateral movement detections missing
  • Coverage gaps on remote endpoints
  • Alert fatigue documented but not addressed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-171 framework page.