NIST SP 800-181
Evidence request list. 52 controls, 52 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cyberspace Effects (CE)
Conducts operations to gather evidence on hostile entities and to counter real-time or potential threats.
- operational authorities and approval records
- operation plans and execution logs
- deconfliction records
- after action reports
- operations conducted outside documented authority
- execution logs incomplete so activity cannot be reconstructed
- no deconfliction with other activity
Develops cyber operations plans, contributes to target selection and validation, and integrates the effort across partners.
- operation plans with objectives and measures
- target validation records
- synchronization and partner coordination records
- legal review evidence
- plans lacking measurable objectives
- validation step skipped under time pressure
- partners informed after execution
Identifies access and collection gaps that could be met through cyber collection and prepares the way to close them.
- gap analysis products
- access assessment records
- recommendations and their disposition
- technical validation of assessed access
- gaps asserted without technical validation
- recommendations produced with no route to decision
- analysis not revisited as the target changes
Builds assessment plans and performance measures and judges whether cyber activity actually achieved its effect.
- assessment plans with measures of performance and effectiveness
- data collection method for each measure
- assessment reports against objectives
- feedback into subsequent planning
- measures of performance substituted for measures of effectiveness
- data for the measures never collected
- assessments produced but not used in planning
Advances cooperation across organizational and national boundaries between cyber operations partners.
- partnership agreements and their scope
- information sharing arrangements and classification handling
- joint planning records
- resource and guidance provided to partners
- sharing arrangement lacks agreed handling rules
- cooperation dependent on personal relationships
- partner obligations undocumented
Conducts target development at system, component and entity level and maintains the supporting target records.
- target folders with sourcing and currency dates
- development methodology and validation steps
- review and update records
- access controls on target material
- target folders stale and still relied upon
- sourcing absent so assessments cannot be checked
- material held without access control
Conducts advanced analysis of collection and open-source data to profile targets and maintain continuity of understanding.
- analysis products profiling target networks and activity
- open-source and collection sourcing records
- continuity handover records between analysts
- validation of analytic conclusions
- continuity lost when an analyst moves on
- open-source material used without provenance
- conclusions unvalidated and carried forward as fact
Cyberspace Intelligence (CI)
Analyses information from multiple sources to prepare the operational picture and answer intelligence requests.
- analysis products with source attribution
- requirements tracking and response records
- tradecraft and confidence standards applied
- review and quality control of products
- single-source conclusions presented as all-source
- confidence levels not expressed
- products issued without review
Identifies collection authorities and environment and drives priority requirements into collection strategy.
- documented collection authorities
- priority requirements register
- collection plans and tasking records
- evaluation of collection against requirement
- collection tasked without confirming authority
- requirements not prioritized so collection is spread thin
- no evaluation of whether collection answered the question
Evaluates collection operations and builds effects-based requirement strategies from what is actually available.
- collection gap analysis
- requirement strategy documents
- evaluation records of collection operations
- records of requirements retired or reprioritized
- gaps identified but never fed back into strategy
- requirements accumulate and are never retired
- evaluation absent so ineffective collection continues
Develops the intelligence plans that satisfy cyber operation requirements and levies requirements onto collection.
- intelligence plans linked to operational requirements
- validation records for levied requirements
- synchronization records with operations
- plan review and update history
- plans not synchronized with the operations they support
- requirements levied without validation
- plans static while operations change
Applies language and cultural expertise alongside technical knowledge to process and analyse intelligence material.
- language proficiency and currency records
- analysis products showing linguistic and cultural reasoning
- quality control of translation and interpretation
- handling controls for source material
- proficiency assessed once at hiring
- machine translation used without linguist review
- cultural context omitted so meaning is lost
Design and Development (DD)
Ensures security requirements are carried into enterprise architecture, reference models and solution designs.
- security architecture artefacts and reference patterns
- design review records showing security input
- architecture decision records with security rationale
- exception register for departures from pattern
- patterns published but projects design around them
- architecture reviews advisory with no gate
- exceptions granted permanently with no review
Maintains the business, systems and information architecture that the organization builds to, and the rules that govern technology choice.
- current architecture description and roadmap
- technology standards and their governance
- evidence architecture is consulted in investment decisions
- architecture repository currency
- architecture describes intent rather than the estate as built
- standards unenforced so the estate fragments
- repository stale enough to mislead
Builds and maintains applications and utility software with security properties established during construction rather than afterwards.
- secure development standard and its adoption evidence
- code review records including security review
- static and dependency analysis results and their handling
- developer secure coding training records
- analysis tooling runs but findings are never fixed
- security review skipped for changes considered small
- third-party components pulled in with no provenance check
Designs, develops and tests systems securely and evaluates system security across the development life cycle.
- system design documentation with security decisions
- security evaluation results at each life cycle stage
- threat modelling records
- traceability from security requirement to test
- security evaluated once at the end
- threat model produced and never revisited after design change
- requirements untraceable to any test
Analyses applications and utility software for security weakness and delivers findings that can actually be acted on.
- assessment scope and methodology
- test results with reproduction detail and severity
- retest evidence after remediation
- tooling configuration and coverage
- findings delivered without reproduction steps so they stall
- no retest so remediation is unverified
- assessment covers the front end and ignores APIs
Translates business need into system requirements and makes sure security policy lands inside those requirements.
- requirements documents including security requirements
- traceability matrix from need to requirement
- stakeholder sign-off records
- evidence security policy was consulted
- security requirements written as non-functional wishes
- traceability broken after change requests
- sign-off by delivery rather than the accountable owner
Plans and runs system tests and reports results honestly against specification and requirement.
- test plans and cases including security cases
- test execution records and defect logs
- evaluation report against requirements
- evidence of regression coverage
- security cases dropped under schedule pressure
- defects closed as accepted with no risk decision
- no regression so fixed defects reappear
Researches and engineers new capability with security integrated from the outset rather than retrofitted.
- research plans and objectives
- prototype security assessment records
- transition criteria including security readiness
- records of security involvement in the research cycle
- prototypes promoted to production without assessment
- security involvement begins at transition
- research systems left running with production data
Implementation and Operation (IO)
Analyses data from disparate sources to produce cybersecurity and privacy insight, including building the algorithms that do it.
- analysis methodology and data source inventory
- algorithm or model documentation
- validation of analytical output
- data handling controls for analysed data
- analysis output presented with no validation
- source data lineage unknown
- sensitive data copied into analysis environments uncontrolled
Administers databases and data management systems so that data is stored, queried and protected reliably.
- database inventory with owner and classification
- access control and privileged account listings for databases
- backup and restore test evidence
- patch and configuration compliance for database platforms
- application accounts hold database administrator rights
- restores never tested
- database patching lags the operating system cycle
Manages the processes and tools by which the organization captures and finds its own intellectual capital.
- knowledge repository structure and ownership
- classification and access rules for stored knowledge
- currency and review process for content
- usage and findability measures
- repositories proliferate with no ownership
- sensitive material stored in open collaboration spaces
- content never retired so search returns superseded guidance
Plans, implements and operates network services and systems across physical and virtual environments.
- network documentation and current topology
- change records for network configuration
- monitoring and capacity evidence
- segmentation and rule set governance
- topology diagram out of date with the running configuration
- network changes made outside change control
- virtual and cloud networking managed by a different team with different rules
Sets up and maintains systems and their components in line with organizational security policy and procedure.
- build standards and evidence systems are built to them
- administrator account inventory and privilege basis
- patch and configuration compliance reporting
- administrative action logging
- builds drift from standard with no reconciliation
- administrators share a common privileged account
- administrative actions not attributable to an individual
Analyses how security integrates through system integration, testing, operation and maintenance, and manages that security posture.
- system security analysis records
- integration and interface security reviews
- posture reporting for the systems covered
- records of security issues raised and tracked
- analysis performed at build and never during operation
- interfaces to other systems excluded from analysis
- issues raised with no tracking to closure
Provides technical support to users on client hardware and software within established policy, and is a first line for security signals.
- support procedures including security escalation route
- ticket records showing security escalations
- technician access model and its limits
- user verification procedure before privileged assistance
- technicians hold standing administrative rights on all endpoints
- no identity verification before password reset
- security-relevant tickets closed without escalation
Investigation (IN)
Investigates intrusion incidents and crimes using the full investigative tradecraft, to a standard that supports action.
- case files with investigative plan and outcome
- authorities and legal basis for investigative steps
- liaison records with law enforcement where applicable
- investigator training records
- investigative steps taken without documented authority
- case files insufficient to support any subsequent action
- no liaison route established before it is needed
Identifies, collects, examines and preserves digital evidence under controlled and documented technique.
- collection and preservation procedures
- documented examination steps per case
- integrity verification such as hashing records
- storage and retention controls for evidence
- integrity hashes not recorded at collection
- evidence stored on general file shares
- examination steps undocumented so results cannot be reproduced
Oversight and Governance (OG)
Owns the organization's COMSEC holdings and the accounting, handling and destruction discipline that keeps keying material accountable.
- named COMSEC custodian and alternate appointment letters
- COMSEC account inventory and destruction records
- handling and storage procedure
- custodian training certificates
- custodian appointed with no alternate
- inventory reconciliations not performed at the required interval
- destruction recorded without two-person verification
Writes and maintains the cybersecurity policy and strategy set and keeps it aligned to organizational direction and external obligation.
- policy set with named owner and review dates
- cybersecurity strategy or plan with approval
- record of regulatory drivers tracked into policy
- policy review minutes
- policy owner is a committee so nobody actually maintains it
- strategy not refreshed after a major change of business direction
- obligations tracked in a spreadsheet nobody reads
Plans the cybersecurity workforce: what capability is needed, what exists, and how the gap is closed through hiring and development.
- workforce plan with role coverage and headcount
- skills gap analysis against required work roles
- training and development budget and plan
- recruitment pipeline records
- plan counts headcount but not capability
- gap analysis performed once with no reassessment
- development plans exist for staff who have since left
Designs the content, methods and assessment for cybersecurity awareness, training and education, grounded in what the roles actually require.
- curriculum map linking content to role requirements
- learning objectives and assessment design
- content version history and review records
- evaluation of learner outcomes
- content bought in and never mapped to the roles it serves
- no assessment so effectiveness is unmeasurable
- curriculum unchanged as the threat and tooling move on
Delivers cybersecurity awareness, training and education and is accountable for whether learners can actually do the thing afterwards.
- instructor qualification and currency records
- delivery schedule and attendance records
- learner feedback and assessment results
- evidence of remediation for failed assessments
- attendance recorded as the outcome measure
- instructor currency lapsed
- no route for learners who fail to be retrained
Provides legal advice on cybersecurity matters and tracks the legislation and regulation that changes what the organization must do.
- register of applicable legislation and regulation with review dates
- records of advice given on cybersecurity matters
- escalation route from security operations to legal
- evidence legal review precedes contentious decisions
- regulatory register maintained by security rather than legal
- advice sought after the decision is taken
- cross-border obligations unmapped
Sets direction and holds accountability for cybersecurity across the organization, including its effect on physical as well as digital operations.
- documented accountability and reporting line for the role
- board or executive reporting pack on cybersecurity
- risk appetite statement and its approval
- evidence of decisions taken at this level
- accountability documented but the role holds no budget or authority
- reporting is activity metrics rather than risk position
- risk appetite never expressed so escalation has no threshold
Runs the privacy compliance programme, including the assessments and records that show personal information is handled lawfully.
- privacy programme plan and staffing
- privacy impact assessment records
- record of processing activities
- breach notification procedure and any invocations
- privacy folded into security with no distinct assessment work
- record of processing incomplete for newer systems
- assessments performed after go-live
Plans and manages the support strategy that keeps a fielded capability sustainable, including its security sustainment over life.
- product support strategy and cost model
- supportability and obsolescence analysis
- sustainment schedule including security patching responsibility
- supplier support agreements
- support strategy silent on who patches what
- obsolescence identified too late to fund replacement
- security sustainment cost excluded from the model
Leads a defined programme end to end and is accountable for its outcome, including keeping it aligned to organizational priority.
- programme charter with named accountable owner
- benefits or outcome definition and tracking
- stakeholder and dependency register
- programme reporting and decision records
- programme reports schedule and spend but never benefit
- dependencies on other programmes untracked
- security treated as a workstream rather than a constraint
Manages technology projects and is accountable for cybersecurity being built in rather than added after delivery.
- project plans showing security activities and gates
- evidence security requirements are set at initiation
- gate or stage review records including security sign-off
- risk register entries owned by the project
- security gate passed on a promise to fix later
- security requirements added at test stage
- project closes with open security actions and no owner
Independently assesses management, operational and technical controls and reports whether they are actually working.
- assessment plan and scope
- independence statement for the assessor
- test procedures and results per control
- assessment report with findings and evidence
- assessor assessing controls they helped implement
- results asserted without underlying test evidence
- scope quietly narrowed to what is known to pass
Decides whether a system may operate at the residual risk it carries, and owns that decision.
- authorization decision records with named authorizing official
- residual risk statement supporting each decision
- conditions and expiry attached to authorizations
- evidence of reauthorization on significant change
- authorization granted indefinitely with no reassessment
- decision signed by someone without authority to accept the risk
- conditions attached but never followed up
Manages the day-to-day cybersecurity of a defined system, programme or enclave and is the accountable point for it.
- assignment records naming the security manager per system
- system security documentation maintained by the role
- evidence of control operation and exception handling
- handover records when the role changes
- role unassigned for systems inherited through acquisition
- documentation maintained by a contractor with no handover
- no evidence of what the role actually does day to day
Manages the portfolio of technology investment so that what is funded matches mission and enterprise priority.
- portfolio inventory with investment status
- prioritization criteria including risk and security debt
- investment decision records
- retirement and consolidation plans
- portfolio lists projects but not the systems they leave behind
- security debt invisible to prioritization
- no decision record explaining why an investment was made
Audits technology programmes or their components against published standards and reports the compliance position.
- audit plan and standards used
- audit working papers and evidence
- audit reports with findings and management response
- follow up on prior findings
- audit repeats the same findings year after year with no escalation
- working papers absent so conclusions are unsupported
- management response accepted with no verification
Protection and Defense (PD)
Analyses output from defensive tooling and turns it into risk reduction rather than an alert backlog.
- tool coverage and tuning records
- triage procedure and queue metrics
- records of analysis outcomes and actions
- escalation criteria and evidence of use
- alert volume exceeds triage capacity so alerts expire
- tuning never revisited so noise persists
- analysis stops at containment with no root cause
Analyses digital evidence from security incidents to establish what happened, in a way that survives scrutiny.
- forensic procedure and tooling validation
- chain of custody records
- case notes and analysis findings
- examiner training and currency
- evidence collected by responders with no custody record
- tooling never validated so results are challengeable
- volatile data lost because collection order was wrong
Investigates, analyses and responds to incidents on the network and drives them to genuine closure.
- incident records showing detection through recovery
- containment and eradication actions with timestamps
- post-incident review records
- on-call and escalation rosters
- incidents closed at containment with no eradication
- post-incident actions recorded but unowned
- response depends on individuals rather than a documented process
Tests, deploys, maintains and administers the infrastructure that the cybersecurity capability itself runs on.
- inventory of security infrastructure and its owners
- deployment and change records
- availability and health monitoring of security tooling
- maintenance and patch records for security platforms
- security tooling itself unpatched
- outages in monitoring platforms undetected
- no redundancy for the systems that detect attack
Identifies and assesses insider threat activity and produces the findings that start a response.
- insider threat programme charter and authorities
- data sources approved for insider analysis
- case records and referral decisions
- legal and privacy review of the programme
- programme operating without documented legal and privacy review
- referrals made with no defined threshold
- analysis limited to technical signals with no context
Collects, processes and analyses threat information and turns it into indicators the organization can defend against.
- intelligence requirements and named sources
- analysis products and their distribution
- indicator feeds into detection tooling
- feedback on the usefulness of products
- intelligence consumed but never converted into detection
- products distributed to nobody in particular
- requirements never defined so collection is aimless
Assesses systems and networks for deviation from acceptable configuration and policy and measures how effective the defences actually are.
- assessment scope and schedule against the asset inventory
- findings with severity and affected assets
- evidence of validation to remove false positives
- measurement of defensive effectiveness over time
- scan coverage smaller than the estate
- findings unvalidated so credibility erodes
- no trend so it is impossible to say if posture improved
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-181 framework page.