Skip to content

Evidence request lists

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)

Evidence request list. 97 controls, 97 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

171A 03.01 Access Control

171A-03.01.01
Account Management

Determines whether account types are defined and bounded, whether accounts are created, modified, disabled and removed under a documented process, and whether account use is monitored and periodically re-authorized.

Artefacts an auditor will ask for
  • account management policy and procedure
  • system account inventory showing type, owner and authorizing manager
  • joiner, mover and leaver tickets sampled across the period
  • periodic account recertification output
  • logs or reports showing account use monitoring
Where this commonly fails
  • shared and service accounts absent from the inventory
  • no recertification evidence, only a policy that requires it
  • accounts of departed staff still enabled at the time of test
171A-03.01.02
Access Enforcement

Determines whether approved authorizations are actually enforced by the system rather than merely documented, by testing access decisions against the recorded entitlements.

Artefacts an auditor will ask for
  • access control configuration or rule set export
  • entitlement listings per system holding CUI
  • test results showing an unauthorized attempt being denied
  • mapping from role to permission
Where this commonly fails
  • policy states least privilege but the rule set grants broad access
  • enforcement demonstrated on one system and assumed for the rest
  • no negative test, only evidence that authorized access works
171A-03.01.03
Information Flow Enforcement

Determines whether approved rules governing where CUI may move, inside the system and to connected systems, are implemented and enforced at the enforcement points.

Artefacts an auditor will ask for
  • documented CUI flow rules and approved flow paths
  • firewall, proxy or data loss prevention rule sets implementing those flows
  • network or data flow diagram identifying CUI paths
  • test evidence of a disallowed flow being blocked
Where this commonly fails
  • flow diagram exists but does not match the deployed rule set
  • egress paths such as webmail and cloud storage never assessed
  • rules permit any-any within a zone that includes non-CUI systems
171A-03.01.04
Separation of Duties

Determines whether duties that would allow one person to act without check have been identified and split, and whether system access reflects that split.

Artefacts an auditor will ask for
  • documented duty separation analysis or conflict matrix
  • role definitions and assignment listings
  • evidence of compensating monitoring where separation is not practical
  • exception approvals for combined duties
Where this commonly fails
  • conflict matrix never compared against actual assignments
  • small teams claim impracticality with no compensating control
  • developer and production approver held by the same identity
171A-03.01.05
Least Privilege

Determines whether authorizations granted are limited to what each user needs for assigned duties, and whether privilege grants are reviewed rather than left to accumulate.

Artefacts an auditor will ask for
  • role to entitlement mapping
  • privilege review records with dates and outcomes
  • evidence of removals arising from review
  • approval records for elevated grants
Where this commonly fails
  • review confirms accounts exist rather than testing whether privilege is still needed
  • privilege creep after internal transfers
  • broad administrative groups used as a default
171A-03.01.06
Least Privilege - Privileged Accounts

Determines whether privileged accounts are restricted to named personnel with an authorized need and are separated from those users' ordinary accounts.

Artefacts an auditor will ask for
  • list of privileged accounts and the individuals holding them
  • authorization records for each privileged grant
  • evidence that administrators hold separate ordinary accounts
  • privileged session logs
Where this commonly fails
  • administrators browse and read mail from the privileged account
  • privileged group membership never reconciled to the authorized list
  • vendor or emergency accounts with standing privilege
171A-03.01.07
Least Privilege - Privileged Functions

Determines whether privileged functions are prevented from being executed by non-privileged users and whether such execution attempts are captured in the audit record.

Artefacts an auditor will ask for
  • definition of privileged functions for each system type
  • configuration preventing execution by non-privileged users
  • audit records showing captured attempts
  • test evidence of a blocked attempt
Where this commonly fails
  • no definition of what counts as a privileged function
  • local administrator rights left with standard users
  • attempts blocked but not logged
171A-03.01.08
Unsuccessful Logon Attempts

Determines whether a limit on consecutive failed logons is set and whether the defined response, such as lockout or delay, actually occurs when the limit is reached.

Artefacts an auditor will ask for
  • configured attempt limit and lockout action per platform
  • test evidence of lockout triggering
  • records of lockout events and unlock procedure
  • coverage list showing which systems enforce it
Where this commonly fails
  • setting applied to the domain but not to standalone or cloud systems
  • lockout configured with an immediate automatic reset that defeats it
  • no evidence the setting was tested, only a screenshot of policy
171A-03.01.09
System Use Notification

Determines whether the approved use notification is displayed before access is granted and remains until the user acknowledges it.

Artefacts an auditor will ask for
  • approved banner text
  • screenshots or test evidence from each access path including remote and console
  • configuration setting deploying the banner
Where this commonly fails
  • banner present on workstations but absent on remote access and network devices
  • text differs from the approved version
  • banner shown after authentication rather than before
171A-03.01.10
Device Lock

Determines whether sessions are locked after a defined period of inactivity or on user action, and whether the lock conceals what was on screen until the user re-authenticates.

Artefacts an auditor will ask for
  • configured inactivity period per platform
  • evidence that the lock hides displayed information
  • test evidence of re-authentication being required
  • coverage across laptops, servers and mobile
Where this commonly fails
  • timeout longer than the defined period on a subset of devices
  • screen saver without a re-authentication requirement
  • mobile devices excluded from the setting
171A-03.01.11
Session Termination

Determines whether user sessions are terminated automatically when the defined conditions occur, rather than merely locked.

Artefacts an auditor will ask for
  • defined termination conditions
  • configuration implementing automatic termination
  • test evidence that the session ends and cannot be resumed
  • application and remote access session settings
Where this commonly fails
  • lock treated as termination
  • conditions defined only for the operating system, not applications
  • idle web sessions persist through cookies after termination
171A-03.01.12
Remote Access

Determines whether remote access types are authorized in advance, routed through managed access points, and monitored and controlled while in use.

Artefacts an auditor will ask for
  • inventory of permitted remote access methods
  • authorization records per user or role
  • configuration of managed access control points
  • remote session logs and monitoring output
Where this commonly fails
  • unmanaged remote support tools installed by teams outside the inventory
  • split tunnelling permits direct egress bypassing controls
  • no monitoring of the remote access concentrator itself
171A-03.01.16
Wireless Access

Determines whether wireless access is authorized before connection is allowed and whether the wireless service is protected by authentication and encryption.

Artefacts an auditor will ask for
  • wireless authorization records
  • controller configuration showing authentication and encryption settings
  • site survey or rogue access point detection output
  • list of wireless networks carrying CUI
Where this commonly fails
  • guest and corporate wireless sharing an uncontrolled path
  • pre-shared keys never rotated after staff departures
  • rogue detection not run or its alerts unactioned
171A-03.01.18
Access Control for Mobile Devices

Determines whether mobile devices connecting to the system are authorized, controlled and protected, including encryption of CUI held on them.

Artefacts an auditor will ask for
  • mobile device authorization records
  • mobile device management enrolment and compliance report
  • encryption status per device
  • procedure for lost or stolen devices
Where this commonly fails
  • personally owned devices access CUI outside management
  • encryption reported by policy rather than by device attestation
  • devices out of compliance remain connected
171A-03.01.20
Use of External Systems

Determines whether the terms on which external systems may access, process or store CUI are established and verified, rather than assumed.

Artefacts an auditor will ask for
  • list of external systems used with CUI including cloud services
  • agreements or terms setting the security conditions
  • verification evidence such as an assessment report or attestation
  • restrictions configured on external connections
Where this commonly fails
  • shadow cloud services never inventoried
  • agreement exists but no verification that terms are met
  • no restriction on portable storage used with external systems
171A-03.01.22
Publicly Accessible Content

Determines whether authorized publishers are designated, whether content is reviewed before publication, and whether published content is re-reviewed and corrected when CUI is found.

Artefacts an auditor will ask for
  • list of designated publishers and their training records
  • pre-publication review records
  • periodic review of public sites
  • records of removals where CUI was found
Where this commonly fails
  • review process covers the website but not public code repositories or file shares
  • no periodic re-review after initial publication
  • removal performed with no record of what was exposed

171A 03.02 Awareness and Training

171A-03.02.01
Literacy Training and Awareness

Determines whether awareness training is provided at the defined points and frequency, covers recognition and reporting of relevant threats including insider threat, and is updated.

Artefacts an auditor will ask for
  • training content or syllabus
  • completion records against the current staff list
  • schedule showing initial and recurring delivery
  • evidence of content updates reflecting current threats
Where this commonly fails
  • completion percentages reported without a reconciled population
  • contractors and temporary staff outside the tracking
  • content unchanged for years despite changed threat
171A-03.02.02
Role-Based Training

Determines whether personnel holding roles with security duties receive training specific to those duties before assuming them and at the defined frequency.

Artefacts an auditor will ask for
  • mapping of security-relevant roles to required training
  • completion records per role holder
  • evidence training precedes assumption of duties
  • refresher schedule
Where this commonly fails
  • general awareness training counted as role-based
  • privileged administrators with no role-specific training
  • role mapping not maintained after reorganizations

171A 03.03 Audit and Accountability

171A-03.03.01
Event Logging

Determines whether the event types to be logged are defined, reviewed and updated, and whether the system logs those events.

Artefacts an auditor will ask for
  • defined list of logged event types with rationale
  • logging configuration per platform
  • evidence of periodic review of the event list
  • sample records showing the defined events present
Where this commonly fails
  • event list copied from a template and never tailored
  • cloud and SaaS platforms outside the logging scope
  • review of the event list never performed
171A-03.03.02
Audit Record Content

Determines whether audit records carry enough detail to establish what happened, when, where, the source and the identity involved.

Artefacts an auditor will ask for
  • sample audit records from each major platform
  • field mapping showing the required elements are present
  • configuration enabling the fields
Where this commonly fails
  • records lack user identity because a shared service account performs the action
  • timestamps without a timezone or in local time only
  • source host absent from forwarded records
171A-03.03.03
Audit Record Generation

Determines whether audit records are generated for the defined events across the components that require them, and whether generation is under controlled selection.

Artefacts an auditor will ask for
  • component inventory mapped to logging coverage
  • configuration showing generation enabled
  • evidence of who may change what is logged
  • sample records from each component class
Where this commonly fails
  • coverage list omits network devices or hypervisors
  • any administrator can silently change logging selection
  • generation enabled but records never leave the host
171A-03.03.04
Response to Audit Logging Process Failures

Determines whether logging failures raise an alert to defined personnel within a defined period and whether a defined response follows.

Artefacts an auditor will ask for
  • configured alert on logging failure and its recipients
  • records of failure alerts and the response taken
  • defined response actions such as overwrite, shutdown or notify
  • test evidence of an induced failure
Where this commonly fails
  • alerts route to an unmonitored mailbox
  • storage exhaustion silently overwrites records
  • no evidence that any failure alert has ever been actioned
171A-03.03.05
Audit Record Review, Analysis, and Reporting

Determines whether audit records are reviewed and analysed at a defined frequency for indications of unlawful or unauthorized activity, and whether findings are reported.

Artefacts an auditor will ask for
  • review procedure with frequency and scope
  • dated review records showing what was examined and by whom
  • records of findings and their escalation
  • correlation across sources where used
Where this commonly fails
  • tool alerts treated as the review with no human analysis
  • review evidence exists for one month only
  • findings recorded but never reported or closed
171A-03.03.06
Audit Record Reduction and Report Generation

Determines whether the capability exists to reduce audit records and generate reports supporting on-demand review and investigation, without altering the original records.

Artefacts an auditor will ask for
  • examples of generated reports and queries
  • evidence that original records are preserved unchanged
  • demonstration of on-demand search across the retention period
Where this commonly fails
  • search available only for a recent window shorter than retention
  • reduction performed by deleting rather than summarizing
  • no capability demonstrated, only a tool licence
171A-03.03.07
Time Stamps

Determines whether records carry timestamps from an authoritative source and meet the defined granularity, so events can be sequenced across systems.

Artefacts an auditor will ask for
  • time source configuration and hierarchy
  • evidence of synchronization status across components
  • sample records showing timestamp format and granularity
  • drift monitoring output
Where this commonly fails
  • devices synchronizing to differing or external sources
  • synchronization unmonitored so drift goes unnoticed
  • records in local time without offset, defeating correlation
171A-03.03.08
Protection of Audit Information

Determines whether audit records and the logging tools are protected from unauthorized access, modification and deletion, and whether access to them is limited to authorized personnel.

Artefacts an auditor will ask for
  • access control lists on log stores and logging tools
  • evidence of write-once, forwarding or other tamper resistance
  • list of personnel authorized to manage logs
  • records of access to audit information
Where this commonly fails
  • local administrators can clear the logs of the system they administer
  • forwarding exists but the local copy remains alterable and is the one retained
  • no separation between those who act and those who review their actions

171A 03.04 Configuration Management

171A-03.04.01
Baseline Configuration

Determines whether a current baseline configuration is documented and maintained for the system, and whether it is reviewed and updated under change control.

Artefacts an auditor will ask for
  • current baseline documents per platform type
  • version history showing review and update
  • evidence the baseline reflects deployed state
  • change records driving baseline updates
Where this commonly fails
  • baseline drafted at build time and never updated
  • no baseline for cloud or container images
  • baseline exists but deployed systems were never compared to it
171A-03.04.02
Configuration Settings

Determines whether secure settings are established, documented and applied, and whether deviations are identified and approved.

Artefacts an auditor will ask for
  • documented setting standards and their source
  • compliance scan or configuration report against those standards
  • approved deviation records with rationale
  • remediation records for non-compliant settings
Where this commonly fails
  • hardening standard adopted but never measured
  • deviations tolerated informally with no approval
  • scanning covers servers only, not network or endpoint
171A-03.04.03
Configuration Change Control

Determines whether changes are proposed, reviewed, approved or rejected, and recorded, and whether implemented changes match what was approved.

Artefacts an auditor will ask for
  • change management procedure
  • change records sampled across the period showing review and approval
  • evidence linking implemented change to its approval
  • emergency change handling records
Where this commonly fails
  • emergency changes never retrospectively approved
  • approval by the same person who made the change
  • changes made directly in cloud consoles outside the process
171A-03.04.04
Impact Analyses

Determines whether the security impact of a change is analysed before implementation and whether the analysis informs the approval decision.

Artefacts an auditor will ask for
  • impact analysis records attached to sampled changes
  • criteria defining when analysis is required
  • evidence the analysis influenced approval or rollback planning
Where this commonly fails
  • impact field completed as a formality with no content
  • analysis performed after deployment
  • no analysis for infrastructure-as-code changes
171A-03.04.05
Access Restrictions for Change

Determines whether physical and logical access to make changes is restricted to authorized personnel and whether the restriction is enforced and recorded.

Artefacts an auditor will ask for
  • list of personnel authorized to change each environment
  • access control configuration on repositories, pipelines and production
  • records of change access being exercised
  • separation between build and deploy authority
Where this commonly fails
  • broad developer access to production persists from an earlier migration
  • pipeline service accounts hold unrestricted deployment rights
  • no record of who executed a given change
171A-03.04.06
Least Functionality

Determines whether systems are configured to provide only essential capability, and whether non-essential functions, ports, protocols and services are disabled or restricted.

Artefacts an auditor will ask for
  • definition of essential functions per system role
  • port, protocol and service inventory with justification
  • scan output showing what is actually listening
  • records of disabling non-essential functions
Where this commonly fails
  • justification list not reconciled to scan results
  • default services left enabled on appliances
  • review performed at build only
171A-03.04.08
Authorized Software - Allow by Exception

Determines whether a deny-all, permit-by-exception policy for software execution is defined and enforced, and whether the authorized list is reviewed.

Artefacts an auditor will ask for
  • authorized software list and its approval record
  • execution control configuration and enforcement mode
  • review records for the list
  • test evidence that unauthorized software is blocked
Where this commonly fails
  • control deployed in audit mode only
  • list maintained but enforcement excludes user-writable paths
  • exceptions granted permanently without review
171A-03.04.10
System Component Inventory

Determines whether an inventory of components is maintained at the defined granularity, kept current, and reconciled to what is actually connected.

Artefacts an auditor will ask for
  • component inventory export with required attributes
  • reconciliation between inventory and discovery scan
  • procedure and frequency for update
  • records of unauthorized components found and handled
Where this commonly fails
  • inventory maintained by hand and stale within weeks
  • virtual, cloud and container assets excluded
  • discovery finds assets absent from the inventory with no follow up
171A-03.04.11
Information Location

Determines whether the locations of CUI and the components processing or storing it are identified and documented, and kept current as systems change.

Artefacts an auditor will ask for
  • record of where CUI is stored, processed and transmitted
  • component list flagged for CUI handling
  • procedure for updating on change
  • evidence of discovery or scanning used to confirm
Where this commonly fails
  • location documented for primary systems while backups and file shares are omitted
  • no re-check after migrations
  • CUI in collaboration tools not recognised as a location
171A-03.04.12
System and Component Configuration for High-Risk Areas

Determines whether components taken to high-risk areas receive the defined configuration and whether the defined controls are applied on return.

Artefacts an auditor will ask for
  • defined high-risk areas and issue procedure
  • configuration standard for travel devices
  • records of devices issued and returned
  • inspection, wipe or rebuild records on return
Where this commonly fails
  • policy exists but no record of any device being issued under it
  • returned devices reconnected without inspection
  • standard travel build identical to the ordinary build

171A 03.05 Identification and Authentication

171A-03.05.01
User Identification, Authentication, and Re-Authentication

Determines whether users and their processes are uniquely identified and authenticated before access, and whether re-authentication occurs under the defined circumstances.

Artefacts an auditor will ask for
  • identity store showing unique identifiers
  • authentication configuration per access path
  • defined re-authentication triggers and evidence they fire
  • test of access without authentication being refused
Where this commonly fails
  • shared accounts defeat unique identification
  • re-authentication triggers defined but not configured
  • service and machine identities unmanaged
171A-03.05.02
Device Identification and Authentication

Determines whether devices are uniquely identified and authenticated before connections are established, where required.

Artefacts an auditor will ask for
  • defined device types requiring authentication
  • network access control or certificate configuration
  • enrolment records for authenticated devices
  • test evidence of an unknown device being refused
Where this commonly fails
  • MAC filtering presented as device authentication
  • policy covers wired but not wireless or VPN
  • exception list large enough to defeat the control
171A-03.05.03
Multi-Factor Authentication

Determines whether multi-factor authentication is implemented for the required access, including privileged and network access, and whether it cannot be bypassed.

Artefacts an auditor will ask for
  • scope statement of where MFA is required
  • configuration and enrolment reports
  • evidence of bypass and exception handling
  • test of access attempted without the second factor
Where this commonly fails
  • legacy protocols left open as an MFA bypass
  • break-glass accounts exempt with no compensating monitoring
  • MFA on the portal but not on direct or API access
171A-03.05.04
Replay-Resistant Authentication

Determines whether authentication mechanisms resist replay for the required access types.

Artefacts an auditor will ask for
  • protocol and mechanism inventory for authentication paths
  • configuration showing replay-resistant mechanisms in use
  • evidence that weaker mechanisms are disabled
Where this commonly fails
  • deprecated protocols enabled for compatibility
  • claim of resistance without identifying the mechanism
  • only interactive logon considered, not service authentication
171A-03.05.05
Identifier Management

Determines whether identifiers are authorized before assignment, kept unique to an individual or device, and prevented from reuse for the defined period.

Artefacts an auditor will ask for
  • identifier assignment authorization records
  • evidence of uniqueness enforcement
  • reuse prevention setting or procedure
  • records of identifiers retired
Where this commonly fails
  • identifiers recycled for new starters with the same name
  • no authorization step before creation
  • device identifiers unmanaged
171A-03.05.07
Password Management

Determines whether password composition, protection and change requirements are implemented, including protection of stored and transmitted passwords and screening against compromised values.

Artefacts an auditor will ask for
  • password policy configuration per platform
  • evidence of cryptographic protection in storage and transit
  • compromised password screening evidence
  • procedure for initial and reset passwords
Where this commonly fails
  • policy set in the domain while applications keep their own weaker rules
  • no screening against known-compromised passwords
  • initial passwords predictable and not forced to change
171A-03.05.11
Authentication Feedback

Determines whether feedback during authentication is obscured so that it does not reveal information usable by an unauthorized person.

Artefacts an auditor will ask for
  • test evidence from each authentication interface
  • configuration masking entry and error detail
  • review of error messages for account enumeration
Where this commonly fails
  • error messages distinguish unknown user from wrong password
  • mobile or kiosk interfaces reveal entered characters
  • password visible in a support tool
171A-03.05.12
Authenticator Management

Determines whether authenticators are verified before issue, protected in use, changed at defined events, and revoked when no longer valid.

Artefacts an auditor will ask for
  • issuance procedure including identity verification
  • records of issue, change and revocation
  • protection measures for authenticators in storage and transit
  • evidence of revocation on termination
Where this commonly fails
  • certificates or tokens never revoked after departure
  • default authenticators unchanged on appliances
  • no verification of identity before reset

171A 03.06 Incident Response

171A-03.06.01
Incident Handling

Determines whether an incident handling capability covering preparation, detection and analysis, containment, eradication and recovery exists and is used.

Artefacts an auditor will ask for
  • incident handling procedure
  • incident records showing the phases applied
  • roles and contact list
  • evidence of lessons feeding back into the process
Where this commonly fails
  • records show detection and closure with no containment or eradication detail
  • capability described but no incidents ever recorded
  • handling documented only for major incidents
171A-03.06.02
Incident Monitoring, Reporting, and Response Assistance

Determines whether incidents are tracked and documented, reported to the defined internal and external parties within required times, and whether response assistance is available to users.

Artefacts an auditor will ask for
  • incident tracking records with timeline
  • external reporting records and timing evidence
  • defined reporting thresholds and recipients
  • help desk or response assistance route and its use
Where this commonly fails
  • external reporting obligations not identified
  • reporting timers measured from triage rather than detection
  • users have no route to report suspected incidents
171A-03.06.03
Incident Response Testing

Determines whether the incident response capability is tested at the defined frequency and whether the results are used to improve it.

Artefacts an auditor will ask for
  • test or exercise plan and scenario
  • dated test records with participants
  • findings register from the test
  • evidence of changes made in response
Where this commonly fails
  • test is a document walkthrough only, never a live exercise
  • findings recorded with no owner or due date
  • test excludes third parties who would be involved in a real incident
171A-03.06.04
Incident Response Training

Determines whether personnel are trained in their incident response roles at defined points and frequency, consistent with the assigned role.

Artefacts an auditor will ask for
  • training content per incident response role
  • completion records for role holders
  • schedule showing initial and refresher delivery
  • evidence of update after process changes
Where this commonly fails
  • only the security team trained while system owners hold response duties
  • training predates a significant process change
  • no record of who currently holds each role
171A-03.06.05
Incident Response Plan

Determines whether an incident response plan exists, is distributed to the personnel who need it, is reviewed and updated, and is protected from unauthorized disclosure.

Artefacts an auditor will ask for
  • current incident response plan with version and approval
  • distribution list and evidence of distribution
  • review and update history
  • access restrictions on the plan
Where this commonly fails
  • plan names people who have left
  • no review since issue
  • plan stored only on the system it would be needed to recover

171A 03.07 Maintenance

171A-03.07.04
Maintenance Tools

Determines whether maintenance tools are approved, controlled and monitored, and whether media brought in for maintenance is checked for malicious code.

Artefacts an auditor will ask for
  • approved maintenance tool list
  • records of tool entry and removal
  • scan records for maintenance media
  • controls preventing unauthorized tool removal with data
Where this commonly fails
  • vendor laptops connected with no inspection
  • diagnostic media never scanned
  • tools left installed after the maintenance ends
171A-03.07.05
Nonlocal Maintenance

Determines whether nonlocal maintenance is approved and monitored, uses multi-factor authentication and strong protection, and is terminated when complete.

Artefacts an auditor will ask for
  • approval records for nonlocal maintenance sessions
  • authentication configuration for maintenance access
  • session logs and monitoring evidence
  • evidence sessions and accounts are terminated afterwards
Where this commonly fails
  • permanent vendor access rather than session-based enablement
  • sessions unmonitored once approved
  • maintenance accounts remain enabled between engagements
171A-03.07.06
Maintenance Personnel

Determines whether maintenance personnel are authorized, whether an escort with the necessary skills supervises those without authorization, and whether the authorization list is maintained.

Artefacts an auditor will ask for
  • authorized maintenance personnel list
  • escort procedure and escort records
  • evidence of identity verification on arrival
  • records of unescorted access grants
Where this commonly fails
  • escort present but without the skill to judge what is being done
  • list not updated when vendor staff change
  • access granted on the basis of a company name rather than an individual

171A 03.08 Media Protection

171A-03.08.01
Media Storage

Determines whether media containing CUI is physically controlled and stored securely until sanitized or destroyed.

Artefacts an auditor will ask for
  • media inventory or register
  • description and evidence of the controlled storage location
  • access records for the storage area
  • procedure for check-in and check-out
Where this commonly fails
  • backup tapes and drives held in unlocked areas
  • no register so loss would go unnoticed
  • paper output containing CUI excluded from scope
171A-03.08.02
Media Access

Determines whether access to CUI on media is restricted to authorized personnel.

Artefacts an auditor will ask for
  • list of personnel authorized to access media
  • access control evidence for storage and systems
  • records of media access events
Where this commonly fails
  • everyone with facility access can reach the media store
  • authorization list not reconciled to current staff
  • no distinction between access for storage handling and access to read content
171A-03.08.03
Media Sanitization

Determines whether media is sanitized using approved techniques before disposal or release for reuse, and whether the action is recorded.

Artefacts an auditor will ask for
  • sanitization procedure naming technique per media type
  • sanitization or destruction records with serial numbers
  • certificates from any third party performing destruction
  • verification step evidence
Where this commonly fails
  • reliance on a supplier certificate with no verification
  • reformatting treated as sanitization
  • solid state and embedded storage handled with methods intended for magnetic media
171A-03.08.04
Media Marking

Determines whether media containing CUI is marked with the required markings and distribution limitations.

Artefacts an auditor will ask for
  • marking standard in use
  • sample of marked media and containers
  • procedure for marking on creation
  • exception handling for areas where marking is impractical
Where this commonly fails
  • electronic media unmarked because only paper was considered
  • markings inconsistent between originator and recipient
  • no marking on media leaving the facility
171A-03.08.05
Media Transport

Determines whether media in transport is protected and controlled, transport activities are recorded, and accountability is maintained during transit.

Artefacts an auditor will ask for
  • transport procedure including protection method
  • transport logs showing custody and receipt
  • evidence of encryption or physical protection in transit
  • authorized courier arrangements
Where this commonly fails
  • courier receipts kept but no record of what was sent
  • encryption assumed rather than verified for transported drives
  • no accountability between handover points
171A-03.08.07
Media Use

Determines whether the use of defined media types is restricted or prohibited, and whether portable storage without an identifiable owner is prohibited.

Artefacts an auditor will ask for
  • media use policy naming permitted and prohibited types
  • technical enforcement configuration
  • records of approved exceptions
  • evidence of blocking unidentifiable portable storage
Where this commonly fails
  • policy prohibits use while ports remain open
  • enforcement on managed endpoints only
  • exceptions granted with no expiry
171A-03.08.09
System Backup - Cryptographic Protection

Determines whether the confidentiality of CUI in backups is protected by cryptographic means.

Artefacts an auditor will ask for
  • backup encryption configuration and algorithm in use
  • evidence covering all backup destinations including offsite and cloud
  • key management arrangements for backup keys
  • restore test evidence
Where this commonly fails
  • primary backups encrypted while archive copies are not
  • keys stored with the backup they protect
  • encryption claimed at the storage layer without evidence it applies to the backup set

171A 03.09 Personnel Security

171A-03.09.01
Personnel Screening

Determines whether individuals are screened before being granted access to CUI and rescreened where the defined conditions require it.

Artefacts an auditor will ask for
  • screening criteria and procedure
  • screening completion records for sampled individuals
  • evidence screening precedes access
  • rescreening conditions and records
Where this commonly fails
  • access granted before screening completes
  • contractors screened by their employer with no verification
  • no rescreening condition defined for role changes
171A-03.09.02
Personnel Termination and Transfer

Determines whether access is removed on termination and adjusted on transfer within the defined periods, and whether property and credentials are recovered.

Artefacts an auditor will ask for
  • termination and transfer checklist
  • records showing access removal timing against the defined period
  • property and credential recovery records
  • evidence of review after internal transfer
Where this commonly fails
  • removal recorded for the primary directory only, leaving application accounts active
  • transfers add access without removing the previous set
  • timing not measurable because removal is undated

171A 03.10 Physical Protection

171A-03.10.01
Physical Access Authorizations

Determines whether a list of individuals authorized to enter facilities holding CUI is maintained, credentials are issued on authorization, and the list is reviewed and revoked as required.

Artefacts an auditor will ask for
  • authorized access list with review dates
  • credential issue and return records
  • approval records for new access
  • revocation records
Where this commonly fails
  • list not reconciled to the badge system
  • reviews performed but with no removals ever resulting
  • contractor badges not returned or deactivated
171A-03.10.02
Monitoring Physical Access

Determines whether physical access is monitored, access logs are reviewed, and apparent incidents are responded to.

Artefacts an auditor will ask for
  • access control system logs
  • review records showing dates and reviewer
  • alarm and incident response records
  • camera or intrusion detection coverage of CUI areas
Where this commonly fails
  • logs retained but never reviewed
  • review covers entries only, not failed attempts or after-hours access
  • incidents noted with no response recorded
171A-03.10.06
Alternate Work Site

Determines whether the security requirements applying at alternate work sites are defined and whether their use is assessed.

Artefacts an auditor will ask for
  • defined controls for alternate work sites
  • evidence of assessment or attestation of those controls
  • agreements with personnel working remotely
  • technical controls compensating for the site
Where this commonly fails
  • home working permitted with no defined requirements
  • requirements defined but never assessed
  • controls assume a corporate network that remote sites do not use
171A-03.10.07
Physical Access Control

Determines whether physical access at entry and exit points is enforced and verified, visitors are controlled, and physical access devices are secured and inventoried.

Artefacts an auditor will ask for
  • entry point control description and evidence
  • visitor register and escort records
  • key and access device inventory with issue records
  • evidence of periodic device inventory and combination change
Where this commonly fails
  • tailgating uncontrolled at shared entrances
  • visitor register incomplete or unescorted access common
  • keys issued with no inventory or return process
171A-03.10.08
Access Control for Transmission

Determines whether transmission lines and distribution points carrying CUI are protected from interception and damage.

Artefacts an auditor will ask for
  • identification of transmission media and distribution points carrying CUI
  • evidence of physical protection such as locked rooms, conduit or sealed enclosures
  • inspection records
Where this commonly fails
  • comms rooms shared with other tenants and unsecured
  • patch panels accessible from public areas
  • protection considered for the data centre only, not the floor distribution

171A 03.11 Risk Assessment

171A-03.11.01
Risk Assessment

Determines whether risk to operations, assets and individuals arising from the processing, storage or transmission of CUI is assessed and updated at the defined frequency and on significant change.

Artefacts an auditor will ask for
  • risk assessment report with scope and date
  • methodology defining likelihood and impact
  • evidence of update on significant change
  • register linking assessed risks to owners
Where this commonly fails
  • assessment covers the organization generally and never names CUI systems
  • single assessment years old with no update trigger
  • risks recorded without owners or decisions
171A-03.11.02
Vulnerability Monitoring and Scanning

Determines whether systems are scanned for vulnerabilities at the defined frequency and on new vulnerability reports, whether results are analysed, and whether findings are remediated within defined periods.

Artefacts an auditor will ask for
  • scan schedule and coverage against the asset inventory
  • scan reports across the period
  • remediation records with dates against the defined periods
  • evidence of authenticated scanning where applicable
Where this commonly fails
  • scans unauthenticated and so understate findings
  • coverage misses cloud, container or network assets
  • findings ageing past the defined period with no risk acceptance
171A-03.11.04
Risk Response

Determines whether findings from risk assessments and vulnerability activity are responded to in accordance with the organizational risk tolerance, and whether decisions are recorded.

Artefacts an auditor will ask for
  • risk response decisions with rationale and approver
  • risk tolerance statement
  • tracking of mitigation actions to closure
  • records of formal risk acceptance
Where this commonly fails
  • acceptance implied by inaction rather than decided
  • acceptance approved below the level authorized to accept it
  • no follow up on mitigations once recorded

171A 03.12 Security Assessment and Monitoring

171A-03.12.01
Security Assessment

Determines whether the requirements are assessed at the defined frequency to establish whether they are implemented correctly and producing the intended outcome, and whether results are documented.

Artefacts an auditor will ask for
  • assessment plan and scope
  • assessment results per requirement
  • assessor identity and independence where relevant
  • evidence of frequency being met
Where this commonly fails
  • assessment records the requirement as met with no supporting evidence
  • scope excludes systems that process CUI
  • assessment performed by the person who implemented the control with no review
171A-03.12.02
Plan of Action and Milestones

Determines whether a plan of action is developed and maintained to record deficiencies and the actions and milestones to correct them.

Artefacts an auditor will ask for
  • current plan of action with deficiencies, owners and dates
  • update history showing maintenance
  • evidence linking entries to assessment findings
  • closure evidence for completed items
Where this commonly fails
  • milestone dates repeatedly moved with no explanation
  • deficiencies closed with no evidence of the fix
  • plan not updated after the most recent assessment
171A-03.12.03
Continuous Monitoring

Determines whether the requirements are monitored on an ongoing basis, so that changes in effectiveness are noticed between formal assessments.

Artefacts an auditor will ask for
  • monitoring strategy naming what is monitored and how often
  • monitoring output such as dashboards or periodic reports
  • evidence that monitoring results are reviewed and acted on
  • frequency definition per control area
Where this commonly fails
  • monitoring exists for infrastructure metrics but not for control effectiveness
  • reports produced but never reviewed
  • strategy documented with no operating evidence
171A-03.12.05
Information Exchange

Determines whether the exchange of CUI with other systems is approved and governed by documented terms, and whether the interfaces and controls are recorded and reviewed.

Artefacts an auditor will ask for
  • inventory of information exchanges involving CUI
  • agreements or documented terms per exchange
  • technical interface description and protections
  • review records for the exchanges
Where this commonly fails
  • exchanges established by projects without any agreement
  • agreement in place but the interface has since changed
  • cloud data sharing not treated as an exchange

171A 03.13 System and Communications Protection

171A-03.13.01
Boundary Protection

Determines whether communications are monitored and controlled at external boundaries and key internal boundaries, and whether subnetworks for publicly accessible components are separated.

Artefacts an auditor will ask for
  • network diagram identifying external and key internal boundaries
  • boundary device rule sets
  • evidence of monitoring at those boundaries
  • separation of publicly accessible components
Where this commonly fails
  • flat internal network with the CUI environment unsegmented
  • rule sets accumulate permissive rules never reviewed
  • cloud boundaries not treated as boundaries
171A-03.13.04
Information in Shared System Resources

Determines whether unauthorized and unintended transfer of information through shared system resources is prevented.

Artefacts an auditor will ask for
  • configuration preventing residual data exposure such as object reuse settings
  • evidence for shared storage, memory and virtualization layers
  • test or vendor attestation covering the mechanism
Where this commonly fails
  • multi-tenant platforms assumed safe with no evidence
  • clipboard, temp and swap areas unconsidered
  • control claimed at the operating system while applications share caches
171A-03.13.06
Network Communications - Deny by Default - Allow by Exception

Determines whether network traffic is denied by default and permitted only by exception, at both entry and exit.

Artefacts an auditor will ask for
  • rule set showing an explicit default deny at the end of the chain
  • documented exceptions with business justification
  • egress rules as well as ingress
  • review records for the exception list
Where this commonly fails
  • default deny on inbound only, with outbound any-any
  • exceptions undocumented and unowned
  • cloud security groups permissive by default
171A-03.13.08
Transmission and Storage Confidentiality

Determines whether cryptographic mechanisms protect the confidentiality of CUI during transmission and while stored, unless otherwise protected.

Artefacts an auditor will ask for
  • inventory of CUI transmission paths and stores with the protection applied
  • cipher and protocol configuration evidence
  • evidence of alternative physical safeguards where cryptography is not used
  • scan output confirming weak protocols are disabled
Where this commonly fails
  • internal traffic left unencrypted on the assumption the network is trusted
  • at-rest encryption on the database but not on exports and backups
  • deprecated protocol versions still accepted
171A-03.13.09
Network Disconnect

Determines whether network connections associated with a session are terminated at the end of the session or after a defined period of inactivity.

Artefacts an auditor will ask for
  • configured inactivity period per service
  • evidence the connection is closed rather than idled
  • coverage across VPN, remote desktop and application sessions
Where this commonly fails
  • timeout set on the application while the underlying tunnel persists
  • period longer than defined on some services
  • keepalives defeat the inactivity measure
171A-03.13.10
Cryptographic Key Establishment and Management

Determines whether keys are established and managed in accordance with defined requirements covering generation, distribution, storage, access and destruction.

Artefacts an auditor will ask for
  • key management procedure covering the full lifecycle
  • key inventory with owners and rotation dates
  • evidence of protected storage such as a key store or hardware module
  • records of key rotation and destruction
Where this commonly fails
  • keys stored in configuration files or source repositories
  • no rotation because no inventory exists
  • destruction never recorded so old keys may remain usable
171A-03.13.11
Cryptographic Protection

Determines whether the cryptography used is of the type required for the protection of CUI and is implemented as configured.

Artefacts an auditor will ask for
  • list of cryptographic modules and their validation status
  • configuration showing approved algorithms and modes in use
  • evidence non-approved algorithms are disabled
  • mapping of each CUI protection point to its module
Where this commonly fails
  • validated module installed but the system runs in a non-approved mode
  • approved list documented while legacy ciphers stay enabled
  • cloud service cryptography accepted without checking what it uses
171A-03.13.12
Collaborative Computing Devices and Applications

Determines whether remote activation of collaborative computing devices is prohibited except where permitted, and whether an indication of use is provided to users present.

Artefacts an auditor will ask for
  • policy on cameras, microphones and conferencing devices
  • configuration preventing remote activation
  • evidence of a use indicator for those present
  • exceptions and their approvals
Where this commonly fails
  • conferencing platform settings allow silent remote start
  • indicator suppressed by the platform
  • meeting room devices excluded from the policy
171A-03.13.13
Mobile Code

Determines whether the use of mobile code is controlled, with permitted technologies defined and their use authorized and monitored.

Artefacts an auditor will ask for
  • definition of permitted and prohibited mobile code technologies
  • browser and endpoint configuration enforcing the definition
  • authorization records for permitted use
  • monitoring or blocking evidence
Where this commonly fails
  • policy names outdated technologies and ignores current ones
  • enforcement relies on user instruction only
  • no monitoring of what actually executes
171A-03.13.15
Session Authenticity

Determines whether the authenticity of communications sessions is protected, so that sessions cannot be hijacked or forged.

Artefacts an auditor will ask for
  • protocol configuration providing session authenticity
  • session token handling evidence for applications
  • test evidence covering session fixation or hijack resistance
Where this commonly fails
  • session tokens transmitted or stored insecurely
  • tokens not invalidated at logout
  • authenticity assumed from transport encryption alone

171A 03.14 System and Information Integrity

171A-03.14.01
Flaw Remediation

Determines whether flaws are identified, reported and corrected, whether corrections are tested before installation, and whether they are installed within defined periods.

Artefacts an auditor will ask for
  • patch management procedure with defined periods
  • patch deployment reports against the asset inventory
  • test records before deployment to production
  • exception and deferral records
Where this commonly fails
  • compliance reported by percentage with no view of what remains unpatched
  • emergency patches deployed with no test record
  • firmware, appliances and third-party software outside the process
171A-03.14.02
Malicious Code Protection

Determines whether malicious code protection is implemented at the required points, kept current, and configured to scan and act on detection.

Artefacts an auditor will ask for
  • deployment coverage report against the asset inventory
  • signature or engine currency evidence
  • scan configuration including real time and scheduled scans
  • records of detections and the action taken
Where this commonly fails
  • coverage gaps on servers or non-standard platforms
  • definitions stale on a subset of endpoints
  • detections logged with no response recorded
171A-03.14.03
Security Alerts, Advisories, and Directives

Determines whether alerts and advisories are received from defined external sources, disseminated internally, and acted on.

Artefacts an auditor will ask for
  • named external sources and subscription evidence
  • records of alerts received and disseminated
  • evidence of actions taken in response to specific advisories
  • defined internal recipients
Where this commonly fails
  • alerts received into a mailbox nobody owns
  • dissemination happens but no action is traceable
  • sources cover the operating system only, not the applications in use
171A-03.14.06
System Monitoring

Determines whether the system is monitored to detect attacks and indicators of potential attacks, including unauthorized connections, and whether detections are acted on.

Artefacts an auditor will ask for
  • monitoring architecture showing sensors and coverage
  • detection rules or use cases in place
  • alert records with triage and outcome
  • evidence of monitoring inbound and outbound traffic
Where this commonly fails
  • monitoring covers the perimeter but not internal lateral movement
  • alerts generated in volume with no triage capacity
  • unauthorized device connection not detectable
171A-03.14.08
Information Management and Retention

Determines whether CUI is managed and retained within the system in accordance with the applicable requirements, and disposed of when retention ends.

Artefacts an auditor will ask for
  • retention schedule applicable to CUI
  • evidence of retention settings implemented in systems
  • disposal records at end of retention
  • identification of where retained CUI resides
Where this commonly fails
  • retention schedule exists on paper with no system implementation
  • data kept indefinitely because deletion is unowned
  • backups retained far beyond the schedule

171A 03.15 Planning

171A-03.15.01
Policy and Procedures

Determines whether policies and procedures covering the requirement families exist, are disseminated, are reviewed and updated at the defined frequency, and identify responsible roles.

Artefacts an auditor will ask for
  • policy set covering each family with approval and version
  • dissemination evidence
  • review and update records against the defined frequency
  • named responsible roles
Where this commonly fails
  • policies approved once and never reviewed
  • procedures describe a process that has since changed
  • responsibility assigned to a role that no longer exists
171A-03.15.02
System Security Plan

Determines whether a system security plan is developed, describes the system boundary, environment, requirements and their implementation, and is reviewed and updated.

Artefacts an auditor will ask for
  • current system security plan with version and approval
  • boundary and environment description
  • implementation statement per requirement
  • review and update history
Where this commonly fails
  • plan describes intended rather than implemented state
  • boundary omits systems that process CUI
  • implementation statements are restatements of the requirement
171A-03.15.03
Rules of Behavior

Determines whether rules describing responsibilities and expected behaviour for CUI use are established, acknowledged by users before access, and reviewed and updated.

Artefacts an auditor will ask for
  • rules of behaviour document
  • acknowledgement records reconciled to the user population
  • evidence acknowledgement precedes access
  • review and reissue records after updates
Where this commonly fails
  • acknowledgement collected at hire only and never renewed after rule changes
  • contractors outside the acknowledgement population
  • rules generic with nothing specific to CUI handling

171A 03.16 System and Services Acquisition

171A-03.16.01
Systems Security Engineering Principles

Determines whether security engineering principles are applied to the specification, design, development and modification of the system.

Artefacts an auditor will ask for
  • stated engineering principles adopted
  • design or architecture review records showing their application
  • evidence in requirements and design artefacts
  • records for modifications as well as new build
Where this commonly fails
  • principles adopted in policy with no evidence in any design record
  • applied to new build only while legacy modification is exempt
  • reviews performed after implementation
171A-03.16.02
Unsupported System Components

Determines whether components no longer supported by the developer or vendor are replaced, or whether documented approval and mitigation exist for continued use.

Artefacts an auditor will ask for
  • inventory flagged with support status and end-of-support dates
  • replacement plans and progress
  • approvals and documented mitigations for continued use
  • evidence of compensating controls where used
Where this commonly fails
  • support status not tracked so end of life is discovered late
  • continued use tolerated without approval or mitigation
  • mitigation described but not implemented or verified
171A-03.16.03
External System Services

Determines whether providers of external system services are required to meet the applicable requirements, and whether compliance is defined, documented and monitored.

Artefacts an auditor will ask for
  • inventory of external system services touching CUI
  • contract terms or agreements imposing the requirements
  • evidence of monitoring such as assessments, attestations or reports
  • defined roles and responsibilities between the parties
Where this commonly fails
  • requirements flowed down in contract but never monitored
  • attestation accepted covering a different scope than the service used
  • subcontracted services invisible to the assessment

171A 03.17 Supply Chain Risk Management

171A-03.17.01
Supply Chain Risk Management Plan

Determines whether a plan for managing supply chain risk to the system and its components exists, is reviewed and updated, and is protected from unauthorized disclosure.

Artefacts an auditor will ask for
  • current supply chain risk management plan with approval
  • review and update records
  • evidence the plan covers the system and its components
  • access restrictions on the plan
Where this commonly fails
  • plan is a generic procurement policy with no system-specific content
  • never updated after supplier changes
  • plan not linked to the risk register or to acquisition decisions
171A-03.17.02
Acquisition Strategies, Tools, and Methods

Determines whether acquisition strategies, contract tools and procurement methods are used to identify, protect against and mitigate supply chain risk.

Artefacts an auditor will ask for
  • procurement templates carrying security and supply chain terms
  • evidence of supplier selection criteria including security
  • records of tailored terms for higher-risk acquisitions
  • evidence of use in actual purchases
Where this commonly fails
  • standard terms exist but purchasing routinely bypasses them
  • criteria applied to new suppliers only
  • no differentiation between critical and routine acquisitions
171A-03.17.03
Supply Chain Requirements and Processes

Determines whether a process for identifying and addressing weaknesses or deficiencies in the supply chain is established, and whether security requirements are enforced on suppliers.

Artefacts an auditor will ask for
  • defined supply chain security requirements imposed on suppliers
  • records of supplier assessment or review
  • register of identified supplier weaknesses and their treatment
  • evidence of enforcement or escalation
Where this commonly fails
  • requirements sent to suppliers but responses never evaluated
  • weaknesses identified with no owner or remediation date
  • enforcement route exists in contract but has never been used
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) framework page.