Skip to content

Evidence request lists

NIST SP 800-181

Evidence request list. 52 controls, 52 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cyberspace Effects (CE)

NICE-CE-WRL-001
Cyberspace Operations

Conducts operations to gather evidence on hostile entities and to counter real-time or potential threats.

Artefacts an auditor will ask for
  • operational authorities and approval records
  • operation plans and execution logs
  • deconfliction records
  • after action reports
Where this commonly fails
  • operations conducted outside documented authority
  • execution logs incomplete so activity cannot be reconstructed
  • no deconfliction with other activity
NICE-CE-WRL-002
Cyber Operations Planning

Develops cyber operations plans, contributes to target selection and validation, and integrates the effort across partners.

Artefacts an auditor will ask for
  • operation plans with objectives and measures
  • target validation records
  • synchronization and partner coordination records
  • legal review evidence
Where this commonly fails
  • plans lacking measurable objectives
  • validation step skipped under time pressure
  • partners informed after execution
NICE-CE-WRL-003
Exploitation Analysis

Identifies access and collection gaps that could be met through cyber collection and prepares the way to close them.

Artefacts an auditor will ask for
  • gap analysis products
  • access assessment records
  • recommendations and their disposition
  • technical validation of assessed access
Where this commonly fails
  • gaps asserted without technical validation
  • recommendations produced with no route to decision
  • analysis not revisited as the target changes
NICE-CE-WRL-004
Mission Assessment

Builds assessment plans and performance measures and judges whether cyber activity actually achieved its effect.

Artefacts an auditor will ask for
  • assessment plans with measures of performance and effectiveness
  • data collection method for each measure
  • assessment reports against objectives
  • feedback into subsequent planning
Where this commonly fails
  • measures of performance substituted for measures of effectiveness
  • data for the measures never collected
  • assessments produced but not used in planning
NICE-CE-WRL-005
Partner Integration Planning

Advances cooperation across organizational and national boundaries between cyber operations partners.

Artefacts an auditor will ask for
  • partnership agreements and their scope
  • information sharing arrangements and classification handling
  • joint planning records
  • resource and guidance provided to partners
Where this commonly fails
  • sharing arrangement lacks agreed handling rules
  • cooperation dependent on personal relationships
  • partner obligations undocumented
NICE-CE-WRL-006
Target Analysis

Conducts target development at system, component and entity level and maintains the supporting target records.

Artefacts an auditor will ask for
  • target folders with sourcing and currency dates
  • development methodology and validation steps
  • review and update records
  • access controls on target material
Where this commonly fails
  • target folders stale and still relied upon
  • sourcing absent so assessments cannot be checked
  • material held without access control
NICE-CE-WRL-007
Target Network Analysis

Conducts advanced analysis of collection and open-source data to profile targets and maintain continuity of understanding.

Artefacts an auditor will ask for
  • analysis products profiling target networks and activity
  • open-source and collection sourcing records
  • continuity handover records between analysts
  • validation of analytic conclusions
Where this commonly fails
  • continuity lost when an analyst moves on
  • open-source material used without provenance
  • conclusions unvalidated and carried forward as fact

Cyberspace Intelligence (CI)

NICE-CI-WRL-001
All-Source Analysis

Analyses information from multiple sources to prepare the operational picture and answer intelligence requests.

Artefacts an auditor will ask for
  • analysis products with source attribution
  • requirements tracking and response records
  • tradecraft and confidence standards applied
  • review and quality control of products
Where this commonly fails
  • single-source conclusions presented as all-source
  • confidence levels not expressed
  • products issued without review
NICE-CI-WRL-002
All-Source Collection Management

Identifies collection authorities and environment and drives priority requirements into collection strategy.

Artefacts an auditor will ask for
  • documented collection authorities
  • priority requirements register
  • collection plans and tasking records
  • evaluation of collection against requirement
Where this commonly fails
  • collection tasked without confirming authority
  • requirements not prioritized so collection is spread thin
  • no evaluation of whether collection answered the question
NICE-CI-WRL-003
All-Source Collection Requirements Management

Evaluates collection operations and builds effects-based requirement strategies from what is actually available.

Artefacts an auditor will ask for
  • collection gap analysis
  • requirement strategy documents
  • evaluation records of collection operations
  • records of requirements retired or reprioritized
Where this commonly fails
  • gaps identified but never fed back into strategy
  • requirements accumulate and are never retired
  • evaluation absent so ineffective collection continues
NICE-CI-WRL-004
Cyber Intelligence Planning

Develops the intelligence plans that satisfy cyber operation requirements and levies requirements onto collection.

Artefacts an auditor will ask for
  • intelligence plans linked to operational requirements
  • validation records for levied requirements
  • synchronization records with operations
  • plan review and update history
Where this commonly fails
  • plans not synchronized with the operations they support
  • requirements levied without validation
  • plans static while operations change
NICE-CI-WRL-005
Multi-Disciplined Language Analysis

Applies language and cultural expertise alongside technical knowledge to process and analyse intelligence material.

Artefacts an auditor will ask for
  • language proficiency and currency records
  • analysis products showing linguistic and cultural reasoning
  • quality control of translation and interpretation
  • handling controls for source material
Where this commonly fails
  • proficiency assessed once at hiring
  • machine translation used without linguist review
  • cultural context omitted so meaning is lost

Design and Development (DD)

NICE-DD-WRL-001
Cybersecurity Architecture

Ensures security requirements are carried into enterprise architecture, reference models and solution designs.

Artefacts an auditor will ask for
  • security architecture artefacts and reference patterns
  • design review records showing security input
  • architecture decision records with security rationale
  • exception register for departures from pattern
Where this commonly fails
  • patterns published but projects design around them
  • architecture reviews advisory with no gate
  • exceptions granted permanently with no review
NICE-DD-WRL-002
Enterprise Architecture

Maintains the business, systems and information architecture that the organization builds to, and the rules that govern technology choice.

Artefacts an auditor will ask for
  • current architecture description and roadmap
  • technology standards and their governance
  • evidence architecture is consulted in investment decisions
  • architecture repository currency
Where this commonly fails
  • architecture describes intent rather than the estate as built
  • standards unenforced so the estate fragments
  • repository stale enough to mislead
NICE-DD-WRL-003
Secure Software Development

Builds and maintains applications and utility software with security properties established during construction rather than afterwards.

Artefacts an auditor will ask for
  • secure development standard and its adoption evidence
  • code review records including security review
  • static and dependency analysis results and their handling
  • developer secure coding training records
Where this commonly fails
  • analysis tooling runs but findings are never fixed
  • security review skipped for changes considered small
  • third-party components pulled in with no provenance check
NICE-DD-WRL-004
Secure Systems Development

Designs, develops and tests systems securely and evaluates system security across the development life cycle.

Artefacts an auditor will ask for
  • system design documentation with security decisions
  • security evaluation results at each life cycle stage
  • threat modelling records
  • traceability from security requirement to test
Where this commonly fails
  • security evaluated once at the end
  • threat model produced and never revisited after design change
  • requirements untraceable to any test
NICE-DD-WRL-005
Software Security Assessment

Analyses applications and utility software for security weakness and delivers findings that can actually be acted on.

Artefacts an auditor will ask for
  • assessment scope and methodology
  • test results with reproduction detail and severity
  • retest evidence after remediation
  • tooling configuration and coverage
Where this commonly fails
  • findings delivered without reproduction steps so they stall
  • no retest so remediation is unverified
  • assessment covers the front end and ignores APIs
NICE-DD-WRL-006
Systems Requirements Planning

Translates business need into system requirements and makes sure security policy lands inside those requirements.

Artefacts an auditor will ask for
  • requirements documents including security requirements
  • traceability matrix from need to requirement
  • stakeholder sign-off records
  • evidence security policy was consulted
Where this commonly fails
  • security requirements written as non-functional wishes
  • traceability broken after change requests
  • sign-off by delivery rather than the accountable owner
NICE-DD-WRL-007
Systems Testing and Evaluation

Plans and runs system tests and reports results honestly against specification and requirement.

Artefacts an auditor will ask for
  • test plans and cases including security cases
  • test execution records and defect logs
  • evaluation report against requirements
  • evidence of regression coverage
Where this commonly fails
  • security cases dropped under schedule pressure
  • defects closed as accepted with no risk decision
  • no regression so fixed defects reappear
NICE-DD-WRL-008
Technology Research and Development

Researches and engineers new capability with security integrated from the outset rather than retrofitted.

Artefacts an auditor will ask for
  • research plans and objectives
  • prototype security assessment records
  • transition criteria including security readiness
  • records of security involvement in the research cycle
Where this commonly fails
  • prototypes promoted to production without assessment
  • security involvement begins at transition
  • research systems left running with production data

Implementation and Operation (IO)

NICE-IO-WRL-001
Data Analysis

Analyses data from disparate sources to produce cybersecurity and privacy insight, including building the algorithms that do it.

Artefacts an auditor will ask for
  • analysis methodology and data source inventory
  • algorithm or model documentation
  • validation of analytical output
  • data handling controls for analysed data
Where this commonly fails
  • analysis output presented with no validation
  • source data lineage unknown
  • sensitive data copied into analysis environments uncontrolled
NICE-IO-WRL-002
Database Administration

Administers databases and data management systems so that data is stored, queried and protected reliably.

Artefacts an auditor will ask for
  • database inventory with owner and classification
  • access control and privileged account listings for databases
  • backup and restore test evidence
  • patch and configuration compliance for database platforms
Where this commonly fails
  • application accounts hold database administrator rights
  • restores never tested
  • database patching lags the operating system cycle
NICE-IO-WRL-003
Knowledge Management

Manages the processes and tools by which the organization captures and finds its own intellectual capital.

Artefacts an auditor will ask for
  • knowledge repository structure and ownership
  • classification and access rules for stored knowledge
  • currency and review process for content
  • usage and findability measures
Where this commonly fails
  • repositories proliferate with no ownership
  • sensitive material stored in open collaboration spaces
  • content never retired so search returns superseded guidance
NICE-IO-WRL-004
Network Operations

Plans, implements and operates network services and systems across physical and virtual environments.

Artefacts an auditor will ask for
  • network documentation and current topology
  • change records for network configuration
  • monitoring and capacity evidence
  • segmentation and rule set governance
Where this commonly fails
  • topology diagram out of date with the running configuration
  • network changes made outside change control
  • virtual and cloud networking managed by a different team with different rules
NICE-IO-WRL-005
Systems Administration

Sets up and maintains systems and their components in line with organizational security policy and procedure.

Artefacts an auditor will ask for
  • build standards and evidence systems are built to them
  • administrator account inventory and privilege basis
  • patch and configuration compliance reporting
  • administrative action logging
Where this commonly fails
  • builds drift from standard with no reconciliation
  • administrators share a common privileged account
  • administrative actions not attributable to an individual
NICE-IO-WRL-006
Systems Security Analysis

Analyses how security integrates through system integration, testing, operation and maintenance, and manages that security posture.

Artefacts an auditor will ask for
  • system security analysis records
  • integration and interface security reviews
  • posture reporting for the systems covered
  • records of security issues raised and tracked
Where this commonly fails
  • analysis performed at build and never during operation
  • interfaces to other systems excluded from analysis
  • issues raised with no tracking to closure
NICE-IO-WRL-007
Technical Support

Provides technical support to users on client hardware and software within established policy, and is a first line for security signals.

Artefacts an auditor will ask for
  • support procedures including security escalation route
  • ticket records showing security escalations
  • technician access model and its limits
  • user verification procedure before privileged assistance
Where this commonly fails
  • technicians hold standing administrative rights on all endpoints
  • no identity verification before password reset
  • security-relevant tickets closed without escalation

Investigation (IN)

NICE-IN-WRL-001
Cybercrime Investigation

Investigates intrusion incidents and crimes using the full investigative tradecraft, to a standard that supports action.

Artefacts an auditor will ask for
  • case files with investigative plan and outcome
  • authorities and legal basis for investigative steps
  • liaison records with law enforcement where applicable
  • investigator training records
Where this commonly fails
  • investigative steps taken without documented authority
  • case files insufficient to support any subsequent action
  • no liaison route established before it is needed
NICE-IN-WRL-002
Digital Evidence Analysis

Identifies, collects, examines and preserves digital evidence under controlled and documented technique.

Artefacts an auditor will ask for
  • collection and preservation procedures
  • documented examination steps per case
  • integrity verification such as hashing records
  • storage and retention controls for evidence
Where this commonly fails
  • integrity hashes not recorded at collection
  • evidence stored on general file shares
  • examination steps undocumented so results cannot be reproduced

Oversight and Governance (OG)

NICE-OG-WRL-001
Communications Security (COMSEC) Management

Owns the organization's COMSEC holdings and the accounting, handling and destruction discipline that keeps keying material accountable.

Artefacts an auditor will ask for
  • named COMSEC custodian and alternate appointment letters
  • COMSEC account inventory and destruction records
  • handling and storage procedure
  • custodian training certificates
Where this commonly fails
  • custodian appointed with no alternate
  • inventory reconciliations not performed at the required interval
  • destruction recorded without two-person verification
NICE-OG-WRL-002
Cybersecurity Policy and Planning

Writes and maintains the cybersecurity policy and strategy set and keeps it aligned to organizational direction and external obligation.

Artefacts an auditor will ask for
  • policy set with named owner and review dates
  • cybersecurity strategy or plan with approval
  • record of regulatory drivers tracked into policy
  • policy review minutes
Where this commonly fails
  • policy owner is a committee so nobody actually maintains it
  • strategy not refreshed after a major change of business direction
  • obligations tracked in a spreadsheet nobody reads
NICE-OG-WRL-003
Cybersecurity Workforce Management

Plans the cybersecurity workforce: what capability is needed, what exists, and how the gap is closed through hiring and development.

Artefacts an auditor will ask for
  • workforce plan with role coverage and headcount
  • skills gap analysis against required work roles
  • training and development budget and plan
  • recruitment pipeline records
Where this commonly fails
  • plan counts headcount but not capability
  • gap analysis performed once with no reassessment
  • development plans exist for staff who have since left
NICE-OG-WRL-004
Cybersecurity Curriculum Development

Designs the content, methods and assessment for cybersecurity awareness, training and education, grounded in what the roles actually require.

Artefacts an auditor will ask for
  • curriculum map linking content to role requirements
  • learning objectives and assessment design
  • content version history and review records
  • evaluation of learner outcomes
Where this commonly fails
  • content bought in and never mapped to the roles it serves
  • no assessment so effectiveness is unmeasurable
  • curriculum unchanged as the threat and tooling move on
NICE-OG-WRL-005
Cybersecurity Instruction

Delivers cybersecurity awareness, training and education and is accountable for whether learners can actually do the thing afterwards.

Artefacts an auditor will ask for
  • instructor qualification and currency records
  • delivery schedule and attendance records
  • learner feedback and assessment results
  • evidence of remediation for failed assessments
Where this commonly fails
  • attendance recorded as the outcome measure
  • instructor currency lapsed
  • no route for learners who fail to be retrained
NICE-OG-WRL-006
Cybersecurity Legal Advice

Provides legal advice on cybersecurity matters and tracks the legislation and regulation that changes what the organization must do.

Artefacts an auditor will ask for
  • register of applicable legislation and regulation with review dates
  • records of advice given on cybersecurity matters
  • escalation route from security operations to legal
  • evidence legal review precedes contentious decisions
Where this commonly fails
  • regulatory register maintained by security rather than legal
  • advice sought after the decision is taken
  • cross-border obligations unmapped
NICE-OG-WRL-007
Executive Cybersecurity Leadership

Sets direction and holds accountability for cybersecurity across the organization, including its effect on physical as well as digital operations.

Artefacts an auditor will ask for
  • documented accountability and reporting line for the role
  • board or executive reporting pack on cybersecurity
  • risk appetite statement and its approval
  • evidence of decisions taken at this level
Where this commonly fails
  • accountability documented but the role holds no budget or authority
  • reporting is activity metrics rather than risk position
  • risk appetite never expressed so escalation has no threshold
NICE-OG-WRL-008
Privacy Compliance

Runs the privacy compliance programme, including the assessments and records that show personal information is handled lawfully.

Artefacts an auditor will ask for
  • privacy programme plan and staffing
  • privacy impact assessment records
  • record of processing activities
  • breach notification procedure and any invocations
Where this commonly fails
  • privacy folded into security with no distinct assessment work
  • record of processing incomplete for newer systems
  • assessments performed after go-live
NICE-OG-WRL-009
Product Support Management

Plans and manages the support strategy that keeps a fielded capability sustainable, including its security sustainment over life.

Artefacts an auditor will ask for
  • product support strategy and cost model
  • supportability and obsolescence analysis
  • sustainment schedule including security patching responsibility
  • supplier support agreements
Where this commonly fails
  • support strategy silent on who patches what
  • obsolescence identified too late to fund replacement
  • security sustainment cost excluded from the model
NICE-OG-WRL-010
Program Management

Leads a defined programme end to end and is accountable for its outcome, including keeping it aligned to organizational priority.

Artefacts an auditor will ask for
  • programme charter with named accountable owner
  • benefits or outcome definition and tracking
  • stakeholder and dependency register
  • programme reporting and decision records
Where this commonly fails
  • programme reports schedule and spend but never benefit
  • dependencies on other programmes untracked
  • security treated as a workstream rather than a constraint
NICE-OG-WRL-011
Secure Project Management

Manages technology projects and is accountable for cybersecurity being built in rather than added after delivery.

Artefacts an auditor will ask for
  • project plans showing security activities and gates
  • evidence security requirements are set at initiation
  • gate or stage review records including security sign-off
  • risk register entries owned by the project
Where this commonly fails
  • security gate passed on a promise to fix later
  • security requirements added at test stage
  • project closes with open security actions and no owner
NICE-OG-WRL-012
Security Control Assessment

Independently assesses management, operational and technical controls and reports whether they are actually working.

Artefacts an auditor will ask for
  • assessment plan and scope
  • independence statement for the assessor
  • test procedures and results per control
  • assessment report with findings and evidence
Where this commonly fails
  • assessor assessing controls they helped implement
  • results asserted without underlying test evidence
  • scope quietly narrowed to what is known to pass
NICE-OG-WRL-013
Systems Authorization

Decides whether a system may operate at the residual risk it carries, and owns that decision.

Artefacts an auditor will ask for
  • authorization decision records with named authorizing official
  • residual risk statement supporting each decision
  • conditions and expiry attached to authorizations
  • evidence of reauthorization on significant change
Where this commonly fails
  • authorization granted indefinitely with no reassessment
  • decision signed by someone without authority to accept the risk
  • conditions attached but never followed up
NICE-OG-WRL-014
Systems Security Management

Manages the day-to-day cybersecurity of a defined system, programme or enclave and is the accountable point for it.

Artefacts an auditor will ask for
  • assignment records naming the security manager per system
  • system security documentation maintained by the role
  • evidence of control operation and exception handling
  • handover records when the role changes
Where this commonly fails
  • role unassigned for systems inherited through acquisition
  • documentation maintained by a contractor with no handover
  • no evidence of what the role actually does day to day
NICE-OG-WRL-015
Technology Portfolio Management

Manages the portfolio of technology investment so that what is funded matches mission and enterprise priority.

Artefacts an auditor will ask for
  • portfolio inventory with investment status
  • prioritization criteria including risk and security debt
  • investment decision records
  • retirement and consolidation plans
Where this commonly fails
  • portfolio lists projects but not the systems they leave behind
  • security debt invisible to prioritization
  • no decision record explaining why an investment was made
NICE-OG-WRL-016
Technology Program Auditing

Audits technology programmes or their components against published standards and reports the compliance position.

Artefacts an auditor will ask for
  • audit plan and standards used
  • audit working papers and evidence
  • audit reports with findings and management response
  • follow up on prior findings
Where this commonly fails
  • audit repeats the same findings year after year with no escalation
  • working papers absent so conclusions are unsupported
  • management response accepted with no verification

Protection and Defense (PD)

NICE-PD-WRL-001
Defensive Cybersecurity

Analyses output from defensive tooling and turns it into risk reduction rather than an alert backlog.

Artefacts an auditor will ask for
  • tool coverage and tuning records
  • triage procedure and queue metrics
  • records of analysis outcomes and actions
  • escalation criteria and evidence of use
Where this commonly fails
  • alert volume exceeds triage capacity so alerts expire
  • tuning never revisited so noise persists
  • analysis stops at containment with no root cause
NICE-PD-WRL-002
Digital Forensics

Analyses digital evidence from security incidents to establish what happened, in a way that survives scrutiny.

Artefacts an auditor will ask for
  • forensic procedure and tooling validation
  • chain of custody records
  • case notes and analysis findings
  • examiner training and currency
Where this commonly fails
  • evidence collected by responders with no custody record
  • tooling never validated so results are challengeable
  • volatile data lost because collection order was wrong
NICE-PD-WRL-003
Incident Response

Investigates, analyses and responds to incidents on the network and drives them to genuine closure.

Artefacts an auditor will ask for
  • incident records showing detection through recovery
  • containment and eradication actions with timestamps
  • post-incident review records
  • on-call and escalation rosters
Where this commonly fails
  • incidents closed at containment with no eradication
  • post-incident actions recorded but unowned
  • response depends on individuals rather than a documented process
NICE-PD-WRL-004
Infrastructure Support

Tests, deploys, maintains and administers the infrastructure that the cybersecurity capability itself runs on.

Artefacts an auditor will ask for
  • inventory of security infrastructure and its owners
  • deployment and change records
  • availability and health monitoring of security tooling
  • maintenance and patch records for security platforms
Where this commonly fails
  • security tooling itself unpatched
  • outages in monitoring platforms undetected
  • no redundancy for the systems that detect attack
NICE-PD-WRL-005
Insider Threat Analysis

Identifies and assesses insider threat activity and produces the findings that start a response.

Artefacts an auditor will ask for
  • insider threat programme charter and authorities
  • data sources approved for insider analysis
  • case records and referral decisions
  • legal and privacy review of the programme
Where this commonly fails
  • programme operating without documented legal and privacy review
  • referrals made with no defined threshold
  • analysis limited to technical signals with no context
NICE-PD-WRL-006
Threat Analysis

Collects, processes and analyses threat information and turns it into indicators the organization can defend against.

Artefacts an auditor will ask for
  • intelligence requirements and named sources
  • analysis products and their distribution
  • indicator feeds into detection tooling
  • feedback on the usefulness of products
Where this commonly fails
  • intelligence consumed but never converted into detection
  • products distributed to nobody in particular
  • requirements never defined so collection is aimless
NICE-PD-WRL-007
Vulnerability Analysis

Assesses systems and networks for deviation from acceptable configuration and policy and measures how effective the defences actually are.

Artefacts an auditor will ask for
  • assessment scope and schedule against the asset inventory
  • findings with severity and affected assets
  • evidence of validation to remove false positives
  • measurement of defensive effectiveness over time
Where this commonly fails
  • scan coverage smaller than the estate
  • findings unvalidated so credibility erodes
  • no trend so it is impossible to say if posture improved
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-181 framework page.