Skip to content

Evidence request lists

NIST SP 800-183

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

NIST SP 800-183: Asset Management

SP800-183-DATA-FLOW
Data Flow and Snapshots

The movement of data through the primitives over time, with snapshots capturing the state of the network of things at instances relevant to a decision trigger.

Artefacts an auditor will ask for
  • Data flow and snapshot timing documentation
Where this commonly fails
  • Data provenance/snapshots not tracked
SP800-183-ENVIRONMENT
Operating Environment and Latency

Environmental factors, including latency between primitives and the geographic distribution of devices, that affect the correctness and timeliness of decisions.

Artefacts an auditor will ask for
  • Latency and distribution analysis affecting decisions
Where this commonly fails
  • Latency/environment risks unaddressed
SP800-183-P4-EUTILITY
Primitive 4: eUtility (external utility)

A software or hardware product or service (for example cloud, computer, database) that executes processes or feeds data into the overall workflow of a network of things.

Artefacts an auditor will ask for
  • eUtility (cloud/compute/db) trust and security controls
Where this commonly fails
  • External utilities not security-assessed
SP800-183-P5-TRIGGER
Primitive 5: Decision Trigger

Creates the final result(s) needed to satisfy the purpose, specification, and requirements of a specific network of things, typically a conditional that initiates an action.

Artefacts an auditor will ask for
  • Decision trigger logic and conditions
Where this commonly fails
  • Decision logic unverified
  • No integrity over trigger conditions
SP800-183-RELIABILITY
Reliability and Trust Across Primitives

Reliability, security, and data integrity considerations applied across the five primitives and their interactions to establish trustworthiness of a network of things.

Artefacts an auditor will ask for
  • Reliability, security, and data integrity analysis across primitives
Where this commonly fails
  • No end-to-end trustworthiness analysis

NIST SP 800-183: Information Security Policies

SP800-183-P1-SENSOR
Primitive 1: Sensor

An electronic utility that measures physical properties such as temperature, acceleration, weight, sound, or location, and outputs data about the physical environment.

Artefacts an auditor will ask for
  • Sensor inventory and data integrity controls
Where this commonly fails
  • Sensor data integrity/authenticity unverified
SP800-183-P2-AGGREGATOR
Primitive 2: Aggregator

A software implementation based on mathematical functions that transforms groups of raw sensor data into intermediate, aggregated data.

Artefacts an auditor will ask for
  • Aggregation logic documentation and validation
Where this commonly fails
  • Aggregation functions unvalidated
SP800-183-P2-CLUSTER
Aggregator Actor: Cluster

An abstract grouping of sensors (or other devices) whose data is collected and aggregated; clusters may overlap and change over time.

Artefacts an auditor will ask for
  • Sensor cluster definitions and membership management
Where this commonly fails
  • Cluster composition undocumented
SP800-183-P2-WEIGHT
Aggregator Actor: Weight

The degree to which a particular sensor's data influences an aggregator's computation, reflecting trust and relevance.

Artefacts an auditor will ask for
  • Sensor weighting/trust scheme documentation
Where this commonly fails
  • Weights/trust assignments unjustified
SP800-183-P3-CHANNEL
Primitive 3: Communication Channel

A medium by which data is transmitted between sensors, aggregators, communication channels, eUtilities, and decision triggers.

Artefacts an auditor will ask for
  • Communication channel security (encryption, integrity)
Where this commonly fails
  • Unencrypted or unauthenticated channels

NoT Elements

NoT.ELEM.COST
Cost Element

Document the Cost element that captures expenses and risks associated with operating and maintaining a Network of Things including security cost.

Artefacts an auditor will ask for
  • Total cost of ownership model
  • Security cost component breakdown
  • Risk to cost mapping
  • Budget approvals
  • Operational cost trend
Where this commonly fails
  • Security cost not separated
  • Maintenance cost underestimated
  • Risk treatment cost not modeled
  • Lifecycle replacement cost absent
NoT.ELEM.DEV
Device ID Element

Document the Device ID element that uniquely identifies each NoT primitive instance enabling provenance, authentication, and tracking.

Artefacts an auditor will ask for
  • Identifier scheme documentation
  • Identifier registry
  • Provenance records per device
  • Identifier collision controls
  • Authentication tied to identifier
Where this commonly fails
  • Identifier scheme lacks uniqueness across vendors
  • No registry of issued identifiers
  • Identifier spoofing not addressed
  • Provenance chain broken at integration
NoT.ELEM.ENV
Environment Element

Document the Environment element that describes the universe in which all NoT primitives operate including physical and logical conditions.

Artefacts an auditor will ask for
  • Environment specification document
  • Physical condition tolerances
  • Operational scenarios
  • Environmental risk register
  • Site survey records
Where this commonly fails
  • Environment not formally documented
  • Operational scenarios incomplete
  • Environmental hazards not assessed
  • Site conditions assumed but unverified
NoT.ELEM.GEO
Geographic Location Element

Document the Geographic Location element that captures the physical place where NoT primitives reside and the implications for data sovereignty, latency, and jurisdiction.

Artefacts an auditor will ask for
  • Geographic placement map
  • Data sovereignty assessment
  • Jurisdictional compliance matrix
  • Latency budget per region
  • Cross border data flow documentation
Where this commonly fails
  • Sensor locations not tracked
  • Data sovereignty not assessed
  • Cross border flows undocumented
  • Jurisdictional regulations not mapped
NoT.ELEM.OWN
Owner Element

Document the Owner element identifying the responsible person, organization, or entity for each primitive and the data it produces or consumes.

Artefacts an auditor will ask for
  • Primitive ownership matrix
  • Data ownership register
  • Vendor accountability documentation
  • Responsibility delegation records
  • Escalation paths
Where this commonly fails
  • Ownership not assigned for shared assets
  • Vendor and customer responsibilities blurred
  • Data ownership disputed
  • No owner of decommissioned primitives
NoT.ELEM.SNAP
Snapshot Element

Document the Snapshot element that captures an instant in time when sensor data and aggregator state were observed enabling reasoning over historical NoT behavior.

Artefacts an auditor will ask for
  • Snapshot retention policy
  • Time synchronization evidence
  • Snapshot integrity controls
  • Sample snapshot records
  • Replay or audit capability
Where this commonly fails
  • No reliable timestamping
  • Snapshots not retained for incident analysis
  • Time skew across devices unmanaged
  • No integrity check on stored snapshots

NoT Primitives

NoT.PRIM.AGGR
Aggregator Primitive

Identify and govern Aggregator primitives that are software implementations that transform groups of raw data into intermediate aggregated data through clusters or weights.

Artefacts an auditor will ask for
  • Aggregator software inventory
  • Aggregation logic documentation
  • Cluster and weight definitions
  • Aggregator change records
  • Output validation evidence
Where this commonly fails
  • Aggregation logic opaque
  • No change control on aggregation rules
  • Aggregator integrity not verified
  • Source data quality not assessed before aggregation
NoT.PRIM.COMM
Communication Channel Primitive

Identify and govern Communication Channel primitives that provide the medium by which data is transmitted between NoT primitives.

Artefacts an auditor will ask for
  • Communication path diagrams
  • Protocol inventory
  • Encryption configuration per channel
  • Channel availability metrics
  • Resilience design documentation
Where this commonly fails
  • Wireless channels not enumerated
  • Unencrypted channels in OT environment
  • Channel resilience not tested
  • Channel ownership unclear across vendors
NoT.PRIM.DTRIG
Decision Trigger Primitive

Identify and govern Decision Trigger primitives that create the final result needed to satisfy the purpose, specification, and requirements of a specific Network of Things.

Artefacts an auditor will ask for
  • Decision trigger rule sets
  • Trigger to action mapping
  • Audit log of triggered decisions
  • Test results for trigger conditions
  • Override or override capability evidence
Where this commonly fails
  • Trigger rules undocumented
  • No audit of trigger firing history
  • Override capability lacking
  • Trigger thresholds not periodically reviewed
NoT.PRIM.EUTIL
External Utility Primitive

Identify and govern External Utility primitives such as cloud services or computing infrastructure that perform computations on behalf of the Network of Things.

Artefacts an auditor will ask for
  • List of cloud and external services in NoT
  • Service trust documentation
  • Performance and reliability SLAs
  • Vendor security attestations
  • Dependency map
Where this commonly fails
  • External services not catalogued
  • Trust relationships not documented
  • SLAs missing for critical services
  • No fallback for external utility failure
NoT.PRIM.SENSOR
Sensor Primitive

Identify and govern Sensor primitives that observe physical or electronic phenomena and produce data inputs to the Network of Things.

Artefacts an auditor will ask for
  • Sensor inventory by deployment
  • Sensor data sheet references
  • Data flow diagrams
  • Sensor onboarding records
  • Calibration and maintenance log
Where this commonly fails
  • Sensor inventory incomplete for OT environment
  • Sensor firmware versions unknown
  • No periodic calibration evidence
  • Sensor authentication absent

Risk Considerations

NoT.RISK.MISSION
Mission Risk for NoT Deployments

Assess mission risk arising from NoT deployments including safety, privacy, and operational impact of primitive failure or compromise.

Artefacts an auditor will ask for
  • NoT specific risk assessment
  • Safety impact analysis
  • Privacy impact analysis
  • Operational continuity plan for NoT
  • Risk treatment plan
Where this commonly fails
  • No NoT specific risk assessment
  • Safety risks not formally analyzed
  • Privacy impact assessment absent for sensor data
  • Continuity plan ignores NoT dependencies

Security Considerations

NoT.SEC.AGGR
Aggregator Security

Apply security controls to Aggregator primitives including integrity of aggregation logic, protection against poisoned inputs, and audit of aggregation decisions.

Artefacts an auditor will ask for
  • Aggregator code integrity verification
  • Input validation rules
  • Anomaly detection on inputs
  • Change control on aggregation logic
  • Audit log of aggregation outputs
Where this commonly fails
  • No input validation before aggregation
  • Aggregator code unsigned
  • Anomalies in inputs not flagged
  • Aggregation logic changes not approved
NoT.SEC.COMM
Communication Channel Security

Apply security controls to Communication Channel primitives including encryption, authentication, integrity protection, and availability assurance.

Artefacts an auditor will ask for
  • Encryption coverage report
  • Channel authentication mechanism
  • Integrity protection design
  • Jamming and denial of service resilience test
  • Backup channel evidence
Where this commonly fails
  • Legacy protocols without encryption
  • Channel authentication missing
  • No protection against replay
  • Single channel dependence
NoT.SEC.DTRIG
Decision Trigger Security

Apply security controls to Decision Trigger primitives including authorization for actions, override controls, and audit of decisions.

Artefacts an auditor will ask for
  • Authorization rules for triggered actions
  • Override capability evidence
  • Decision audit log
  • Safety interlocks
  • Periodic review of decision logic
Where this commonly fails
  • Triggered actions execute without human review where required
  • No override mechanism
  • Decision audit incomplete
  • Safety interlocks not tested
NoT.SEC.EUTIL
External Utility Security

Apply security controls and oversight to External Utility primitives including vendor risk management, secure integration, and dependency monitoring.

Artefacts an auditor will ask for
  • External utility risk assessment
  • Integration security review
  • API authentication and authorization evidence
  • Continuous monitoring of vendor posture
  • Contractual security obligations
Where this commonly fails
  • External utilities not formally assessed
  • API keys long lived and shared
  • No monitoring of vendor security posture
  • Contractual security clauses absent
NoT.SEC.SENSOR
Sensor Security

Apply security controls to Sensor primitives including physical protection, firmware integrity, authentication, and tamper detection.

Artefacts an auditor will ask for
  • Sensor physical security assessment
  • Firmware integrity verification
  • Sensor authentication mechanism
  • Tamper detection evidence
  • Sensor patching evidence
Where this commonly fails
  • Sensors in public locations without tamper detection
  • Firmware updates manual and infrequent
  • Sensor authentication weak or absent
  • Spoofing risk not addressed

Trust in Networks of Things

NoT.TRUST.DATA
Data Trustworthiness

Establish trustworthiness of data generated, transmitted, and acted upon within the Network of Things through integrity, provenance, and authenticity controls.

Artefacts an auditor will ask for
  • Data integrity mechanism documentation
  • Provenance chain records
  • Authenticity verification evidence
  • Tamper detection capability
  • Anomaly detection on data streams
Where this commonly fails
  • Data integrity not verified beyond transport
  • No provenance for derived data
  • Tamper detection absent at edge
  • Anomalous data accepted by aggregators
NoT.TRUST.IDENT
Primitive Identity Trust

Establish trust in the identity of each NoT primitive through unique identifiers, cryptographic credentials, and lifecycle controls.

Artefacts an auditor will ask for
  • Identity issuance policy
  • Credential management evidence
  • Onboarding and revocation records
  • Credential strength documentation
  • Identity audit trail
Where this commonly fails
  • Default credentials remain in production
  • No revocation capability for compromised devices
  • Identity tied to shared secrets across fleet
  • Onboarding not authenticated
NoT.TRUST.RELY
Reliability of Primitives

Establish reliability of NoT primitives ensuring they perform their function consistently within defined tolerances and report failures predictably.

Artefacts an auditor will ask for
  • Reliability targets per primitive
  • Failure mode and effects analysis
  • Mean time between failures data
  • Failure reporting workflow
  • Redundancy design documentation
Where this commonly fails
  • No reliability targets defined
  • Failure modes not analyzed
  • Silent failure modes not detected
  • No redundancy for critical sensors
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-183 framework page.