NIST SP 800-171 Rev 3
Evidence request list. 97 controls, 97 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
03.01 AC (Access Control)
Define, establish, modify, disable, and remove account types; assign managers; specify membership conditions; authorize access; monitor account use; notify managers on triggering events; require re-authorization at defined frequencies.
- account management policy
- account inventory with type and owner
- joiner-mover-leaver workflow tickets
- access approval records
- periodic account review reports
- shared/generic accounts not tracked
- no periodic recertification
- stale accounts retained post-termination
Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.
- RBAC/ABAC configuration export
- access control list samples
- system entitlement reports
- role-permission matrix
- entitlements drift
- no segregation of duties enforced
Enforce approved authorizations for controlling the flow of CUI within the system and between connected systems.
- firewall ruleset
- data flow diagrams
- DLP policy export
- proxy/gateway configuration
- flat networks
- no egress filtering for CUI enclaves
Identify duties that require separation; define system access authorizations to support separation of duties.
- SoD matrix
- conflicting role report
- exception approvals
- admins also approving their own changes
- SoD not enforced in finance/IT overlap
Allow only authorized access necessary to accomplish assigned tasks; review privileges periodically; reassign or remove unnecessary privileges.
- privilege review reports
- JIT/JEA configuration
- privileged role inventory
- permanent admin rights
- no quarterly entitlement review
Restrict privileged accounts to designated personnel; require non-privileged accounts for non-security functions.
- PAM tool reports
- dual-account assignment list
- privileged session logs
- admins using privileged accounts for email/web
- no PAM vault
Prevent non-privileged users from executing privileged functions; log execution of privileged functions.
- sudo/UAC configuration
- privileged command audit logs
- unrestricted sudo
- no logging of admin actions
Enforce a limit of consecutive invalid logon attempts and lock the account/node for a defined period.
- AD/IdP lockout policy screenshots
- system hardening baselines
- no lockout on service accounts
- thresholds too lenient
Display a system use notification/banner before granting access, per organization-defined conditions.
- approved banner text
- screenshots from systems
- GPO/MDM configuration
- banner missing on Linux hosts or network devices
- outdated legal text
Prevent further access by initiating device lock after defined inactivity or upon user request; require re-authentication to unlock.
- GPO/MDM screensaver policy
- screensaver timeout configuration
- timeouts too long
- kiosks excluded
Terminate user sessions automatically after defined conditions or trigger events.
- VPN/RDP session timeout settings
- application session timeout config
- no idle timeout on admin consoles
Establish usage restrictions, configuration requirements, and authorize remote access; route remote access via managed access control points; permit only approved remote execution of privileged commands.
- VPN configuration
- ZTNA policy
- remote access authorization records
- MFA enforcement evidence
- split tunneling enabled
- no MFA on VPN
Establish usage restrictions, configuration requirements, and authorize wireless access; protect with authentication and encryption.
- wireless authentication settings (WPA2/3 Enterprise)
- wireless authorization records
- rogue AP detection reports
- legacy WPA2-PSK on corporate SSIDs
- guest SSID routed to internal LAN
Establish configuration requirements, connection requirements, and implementation guidance for mobile devices; encrypt CUI on mobile devices.
- MDM/UEM configuration
- device encryption attestations
- mobile device inventory
- BYOD without containers
- no jailbreak detection
Establish terms and conditions for use of external systems; restrict use of organizationally controlled storage devices on external systems.
- acceptable use policy
- third-party connection agreements
- DLP rules on removable media
- no inventory of external systems used
- personal cloud storage uncontrolled
Designate individuals authorized to make information publicly accessible; train them; review content for CUI prior to posting and periodically thereafter.
- public content review log
- designated approver list
- content review training records
- no scheduled re-review of legacy site content
03.02 AT (Awareness and Training)
Provide security literacy training to system users initially, annually, and after defined events; include insider threat, social engineering, and CUI handling.
- training curriculum
- completion records
- phishing simulation results
- annual refresh schedule
- contractors excluded from training
- no insider threat module
Provide role-based security training to personnel with assigned security roles before authorizing access, when required by changes, and periodically thereafter.
- role-to-training mapping
- completion certificates
- training matrix
- developers not trained on secure coding
- admins lack PAM-specific training
03.03 AU (Audit and Accountability)
Specify event types to be logged; coordinate logging across system components; review event types periodically.
- audit logging policy
- event type catalog
- SIEM log source inventory
- app-layer events not logged
- no review of event catalog
Ensure audit records contain information needed to determine what occurred, when, where, source, outcome, and identity of associated subjects.
- sample logs with required fields
- log schema documentation
- missing user attribution
- no host/source IP
Generate audit records for selected event types; retain in accordance with retention requirements.
- log retention policy
- SIEM storage configuration
- archive procedures
- retention shorter than policy
- logs deleted on rotation
Alert defined personnel on audit logging process failures; take defined actions when failures occur.
- SIEM heartbeat alert configuration
- log source down runbook
- alert tickets
- no alerting when log source stops sending
- alerts go to unmonitored mailbox
Review and analyze audit records at defined frequency for indicators of inappropriate or unusual activity; report findings to designated personnel.
- SOC analyst shift logs
- monthly audit review reports
- use case/detection library
- no formal monthly review
- alerts not triaged
Provide audit record reduction and report generation capability supporting on-demand review, analysis, reporting, and after-the-fact investigation.
- SIEM/log analytics platform overview
- saved searches and dashboards
- no full-text search capability
- raw logs only, no parsing
Use internal system clocks to generate time stamps for audit records; synchronize to authoritative time source.
- NTP/PTP configuration
- time drift monitoring reports
- devices syncing to internet directly
- no monitoring of drift
Protect audit information and audit logging tools from unauthorized access, modification, and deletion; authorize access only to a subset of privileged users.
- SIEM access control
- WORM/immutable storage configuration
- log integrity monitoring
- admins can delete logs
- no integrity check on archives
03.04 CM (Configuration Management)
Develop, document, and maintain current baseline configurations for the system; review and update baselines as required.
- golden image inventory
- hardening guides (CIS/STIG)
- baseline review records
- no baselines for network devices
- baselines never reviewed
Establish, document, and implement configuration settings that reflect the most restrictive mode consistent with operational requirements; identify, document, and approve deviations.
- CIS benchmark scan reports
- approved deviation registry
- exceptions undocumented
- drift not detected
Define and document types of changes that require configuration change control; review proposed changes; approve or disapprove with explicit consideration of security impact.
- CAB minutes
- change tickets
- change control policy
- emergency changes bypass review
- no security impact assessment
Analyze security impact of changes prior to implementation; test, validate, and document changes before deployment.
- change impact templates filled
- test results
- approval records
- no test environment
- impact analysis perfunctory
Define, document, approve, and enforce physical and logical access restrictions associated with system changes.
- RBAC for CI/CD
- production access controls
- deployment access matrix
- developers have prod push rights
- no separation of dev/prod
Configure system to provide only essential capabilities; prohibit or restrict use of specified functions, ports, protocols, software, and services.
- allowed services list
- port/protocol baselines
- vulnerability scan output
- legacy services left enabled
- default ports open
Identify software authorized to execute; implement deny-all, allow-by-exception policy; review and update list periodically.
- allowlist configuration (AppLocker/WDAC)
- software authorization list
- review records
- allowlist in audit mode only
- no review cycle
Develop and document an inventory of system components that reflects the current system; review and update inventory periodically.
- CMDB export
- asset discovery scan reports
- inventory review records
- IoT/OT not inventoried
- cloud assets missing
Identify and document the location of CUI and the system components on which it is processed and stored.
- CUI data flow diagrams
- data classification inventory
- system boundary diagrams
- CUI sprawled to shadow IT
- no recent mapping
Issue specifically configured systems to individuals traveling to high-risk locations; apply additional safeguards on return.
- travel laptop program
- device wipe/reimage records
- high-risk destination list
- no travel program
- personal devices used internationally
03.05 IA (Identification and Authentication)
Uniquely identify and authenticate system users and associate that unique identification with processes acting on behalf of those users.
- IdP configuration
- unique account assignment policy
- shared admin accounts
- service accounts mapped to people
Uniquely identify and authenticate devices before establishing a connection.
- 802.1X configuration
- device certificate inventory
- NAC reports
- no NAC on wired ports
- MAC-based bypasses
Implement MFA for access to privileged accounts and for access to non-privileged accounts.
- MFA enrollment reports
- IdP policies
- MFA bypass exception list
- SMS fallback enabled
- service accounts excluded with no compensating control
Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.
- Kerberos/OAuth/FIDO2 configuration
- session token settings
- legacy NTLM enabled
- long-lived tokens
Manage system identifiers by receiving authorization, selecting an identifier, assigning to intended individual/group/role/device, and preventing reuse for a defined period.
- username convention
- deprovisioning procedure
- identifier reuse policy
- recycling usernames
- no central identifier registry
Maintain a list of commonly used, expected, or compromised passwords; verify passwords against the list; transmit passwords only over protected channels; store using approved hash with salt; require immediate password change on temporary credentials.
- password policy
- compromised password list source
- hash algorithm settings
- MD5/SHA1 used
- no breach password screening
Obscure feedback of authentication information during authentication.
- login screen behavior
- application authentication test cases
- password visible toggle defaults to show
Manage authenticators by verifying identity of receiver, establishing initial content, ensuring adequate strength, secure distribution, revocation, periodic change, and protection from disclosure.
- MFA token issuance log
- credential rotation policy
- service account credential vault
- never-rotated service account passwords
- shared secrets in source control
03.06 IR (Incident Response)
Implement incident handling capability including preparation, detection and analysis, containment, eradication, recovery, and post-incident activity.
- incident response plan
- IR runbooks/playbooks
- containment procedures
- IR plan never tested
- no playbooks for ransomware/CUI exfil
Track and document incidents; report incidents to designated personnel and authorities within required timeframes; provide incident response assistance.
- incident register
- DoD/CISA reporting evidence
- DIBNet reports
- 72-hr CUI breach reporting missed
- no incident metrics
Test the incident response capability for the system using defined tests at defined frequency to determine effectiveness; document results.
- tabletop exercise reports
- purple team exercise records
- lessons learned
- last test more than a year old
- lessons learned not actioned
Train personnel in their incident response roles and responsibilities; provide refresher training annually and when changes occur.
- IR role training records
- training plan
- only IR team trained, no executive tabletops
Develop, distribute, review, and update the IR plan; protect from unauthorized disclosure; address CUI compromise reporting.
- current IR plan
- review/approval signature page
- distribution list
- IR plan stale
- no CUI-specific notification process
03.07 MA (Maintenance)
Approve, control, and monitor the use of system maintenance tools; check media containing diagnostic and test programs for malicious code before use.
- approved tools list
- scan logs of diagnostic media
- tool inventory
- technicians bring USB tools unchecked
Approve and monitor nonlocal maintenance and diagnostic activities; require MFA for nonlocal maintenance sessions; terminate sessions when complete.
- remote maintenance authorization
- session recordings
- session termination evidence
- always-on vendor VPN
- no session recording
Establish a process for maintenance personnel authorization; supervise maintenance activities of personnel without required access; maintain list of authorized maintenance organizations or personnel.
- vendor authorization list
- escort logs
- background check evidence for maintainers
- unescorted vendor access
- no maintainer authorization
03.08 MP (Media Protection)
Physically control and securely store digital and non-digital media containing CUI.
- secure storage inventory
- safe/cabinet access logs
- encrypted backup tape register
- paper CUI on desks
- tapes stored unsecured
Restrict access to CUI on system media to authorized personnel or roles.
- access logs
- authorization records
- no logging of physical media access
Sanitize or destroy system media containing CUI before disposal, release, or reuse; verify sanitization actions.
- certificates of destruction
- sanitization log per NIST SP 800-88
- verification reports
- drives donated without wipe
- no certificate retention
Mark system media containing CUI with applicable distribution limitations and handling caveats.
- marking SOP
- sample marked media photos
- label inventory
- CUI banners missing in document headers/footers
Protect and control system media during transport outside controlled areas; maintain accountability; document activities associated with transport.
- chain of custody forms
- courier service contracts
- encryption attestations for transit
- unencrypted laptops in transit
- no transit logs
Restrict or prohibit the use of types of system media on systems or system components; prohibit use of removable media without identifiable owner.
- USB device control policy via DLP/EDR
- approved removable media list
- USB ports open by default
Protect the confidentiality of backup CUI at storage locations using cryptographic mechanisms.
- backup encryption configuration
- key management evidence
- test restore records
- backups encrypted at rest only, not in transit
- no key rotation
03.09 PS (Personnel Security)
Screen individuals prior to authorizing access to the system and CUI; rescreen at defined frequency.
- background check policy
- completed background check records
- rescreen schedule
- contractors not screened
- no rescreen for long tenure staff
Upon termination or transfer, disable access, revoke authenticators/credentials, conduct exit interviews including CUI handling, retrieve property, retain access to organizational information formerly controlled by individual.
- termination checklist
- access revocation tickets
- exit interview records
- delayed deprovisioning
- lingering access in SaaS apps
03.10 PE (Physical Protection)
Develop, approve, and maintain list of individuals with authorized access to facility where CUI resides; issue credentials; review list periodically.
- access list
- badge issuance log
- periodic review records
- badge lists not reconciled with HR
- former employees still on list
Monitor physical access to the facility where the system resides; review logs of physical access; coordinate review with incident response.
- CCTV retention policy
- badge reader logs
- physical security incident reports
- CCTV not retained 90 days
- no review of badge logs
Determine and document alternate work sites allowed; employ controls at alternate work sites; assess feasibility of controls.
- telework policy
- home office security checklist
- VPN required attestation
- no home office security baseline
- shared family computers used
Enforce physical access authorizations at entry/exit points; maintain visitor logs; control access to keys, combinations, and other physical access devices.
- visitor logs
- key/combination inventory
- entry/exit access reports
- unsigned visitor logs
- shared front-door codes
Control physical access to system distribution and transmission lines within facilities.
- wiring closet access controls
- conduit/raceway documentation
- wiring closets unlocked
03.11 RA (Risk Assessment)
Conduct risk assessments including likelihood and impact of unauthorized access, use, disclosure, disruption, modification, or destruction of system and CUI; update at defined frequency and when significant changes occur.
- risk assessment report
- risk register
- methodology document
- RA not updated post major change
- no quantification of CUI risk
Monitor and scan for vulnerabilities at defined frequency and when new vulnerabilities are identified; remediate based on risk.
- scan schedule
- scan reports
- remediation SLA tracking
- scans only quarterly
- remediation SLAs not enforced
Respond to findings from risk assessments, security assessments, and monitoring through accepted, transferred, mitigated, or avoided treatments.
- risk treatment plan
- POAM tracking
- risk acceptance memos
- POAM items past due
- risk acceptances unsigned
03.12 CA (Security Assessment and Monitoring)
Assess security requirements in the system at defined frequency to determine if controls are implemented correctly, operating as intended, and producing the desired outcome.
- assessment report (SAR)
- assessment plan
- scope statement
- self-assessment with no rigor
- no independent assessor
Develop and update a POAM to document planned remediation actions for weaknesses identified during assessments; track to closure.
- current POAM register
- POAM update cadence
- evidence of closure
- POAM items open multi-year
- no quarterly update
Develop and implement a system-level continuous monitoring strategy that includes ongoing monitoring of security requirements and reporting of security status.
- continuous monitoring strategy
- monthly conmon reports
- metrics dashboards
- no conmon strategy document
- metrics never reported up
Approve and manage the exchange of CUI between systems through information exchange agreements, interconnection security agreements, or other appropriate mechanisms.
- ISA/MOU register
- interconnection inventory
- annual review evidence
- informal data sharing
- no ISA for vendor connections
03.13 SC (System and Communications Protection)
Monitor and control communications at external boundaries and key internal boundaries of the system; implement subnetworks for publicly accessible components separated from internal networks; connect to external networks only through managed interfaces.
- firewall config
- DMZ design
- managed interface inventory
- IDS/IPS placement
- public services on internal networks
- no egress filtering
Prevent unauthorized and unintended information transfer via shared system resources.
- VM isolation evidence
- memory clearing config
- multi-tenant isolation design
- object reuse not prevented in custom apps
Deny network communications traffic by default and allow network communications traffic by exception.
- firewall default-deny rule
- exception inventory
- rule review records
- broad any-any rules persist
- no firewall rule review
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI and detect changes during transmission.
- TLS 1.2+ configuration
- cipher suite hardening
- SSH key management
- TLS 1.0/1.1 still allowed
- internal traffic unencrypted
Terminate the network connection associated with a communications session at the end of the session or after a defined period of inactivity.
- VPN/RDP idle timeout configuration
- application session timeout
- VPN sessions never time out
Establish and manage cryptographic keys for cryptography employed in the system in accordance with key management requirements.
- key management policy
- HSM/KMS evidence
- key rotation logs
- keys in source code
- no rotation
Implement FIPS-validated or NSA-approved cryptography for protecting the confidentiality of CUI.
- FIPS 140-2/3 validation certificates
- cryptographic module inventory
- FIPS mode evidence
- non-FIPS algorithms used
- FIPS mode not enabled on OS
Prohibit remote activation of collaborative computing devices and applications with specified exceptions; provide indication to users physically present.
- camera/mic policy
- indicator LED config
- videoconferencing settings
- meeting clients can join muted with camera unknowingly off
Define acceptable and unacceptable mobile code and mobile code technologies; authorize, monitor, and control use of mobile code.
- browser/script control settings
- EDR policies for macros and scripts
- macros enabled by default
- no JavaScript controls
Protect the authenticity of communications sessions.
- mutual TLS configuration
- session token settings
- anti-CSRF evidence
- no mutual TLS for service-to-service
- weak session token entropy
03.14 SI (System and Information Integrity)
Identify, report, and correct system flaws; test software and firmware updates for effectiveness and side effects before installation; install security-relevant updates within defined time periods.
- patch management policy
- patch reports
- patch testing evidence
- SLA tracking
- critical patches past SLA
- no test cycle
Implement malicious code protection at system entry and exit points; update protection mechanisms; configure to perform periodic scans and real-time scans of files; address receipt of false positives.
- EDR/AV deployment report
- signature update evidence
- scan results
- EDR not on Linux servers
- exclusions overly broad
Receive system security alerts, advisories, and directives from external organizations on an ongoing basis; generate internal alerts/advisories; disseminate.
- CISA/US-CERT subscription evidence
- internal advisory distribution log
- no formal subscriptions
- advisories not actioned
Monitor the system to detect attacks and indicators of potential attacks; identify unauthorized use of the system; deploy monitoring devices strategically.
- IDS/IPS configuration
- EDR coverage report
- SOC monitoring runbooks
- blind spots in cloud workloads
- IDS not tuned
Manage and retain CUI within the system and CUI output from the system in accordance with applicable laws, regulations, and policies.
- retention schedule
- data lifecycle policy
- disposal records
- indefinite retention
- no defensible deletion
03.15 PL (Planning)
Develop, document, and disseminate organization-level policy and procedures for each family of security requirements; review and update on defined frequency.
- policy library
- approval signatures
- annual review records
- policies last reviewed 3+ years ago
- no procedures for some families
Develop, document, and maintain a system security plan describing the system boundary, environment of operation, security requirements implementation, and connections to other systems.
- current SSP
- boundary diagram
- control implementation statements
- SSP outdated
- no boundary diagram
- control statements incomplete
Establish and provide rules of behavior describing user responsibilities; require acknowledgment before authorizing access; review and update on defined frequency.
- AUP
- user acknowledgment records
- no acknowledgment for existing users
- AUP not refreshed annually
03.16 SA (System and Services Acquisition)
Apply security engineering principles in the specification, design, development, implementation, and modification of the system.
- secure SDLC policy
- architecture review records
- threat models
- no threat modeling on new features
- architecture reviews skipped
Replace system components when support for the components is no longer available; provide justification and approval for continued use of unsupported components.
- EOL inventory
- replacement plan
- approved exception register
- Windows Server 2012 still in use
- no EOL tracking
Require providers of external system services to comply with security requirements; define and document oversight and user roles; monitor compliance of external service providers.
- vendor security requirements clauses
- SOC 2 reports
- vendor monitoring records
- no annual review of vendor attestations
- no flow-down clauses
03.17 SR (Supply Chain Risk Management)
Develop a plan for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services; update the plan on defined frequency.
- SCRM plan
- update history
- approval records
- no documented SCRM plan
- scope limited to IT only
Develop and implement acquisition strategies, contract tools, and procurement methods to identify, protect against, and mitigate supply chain risks.
- procurement security clauses
- supplier risk tiering
- RFP security templates
- no security in procurement template
- tier 1 vendors not assessed
Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes; enforce flow-down of supply chain requirements to subcontractors.
- supplier assessment workflow
- flow-down clauses in contracts
- subcontractor inventory
- no flow-down to subcontractors
- no process for identified weaknesses
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-171 Rev 3 framework page.