NIST SP 800-183
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
NIST SP 800-183: Asset Management
The movement of data through the primitives over time, with snapshots capturing the state of the network of things at instances relevant to a decision trigger.
- Data flow and snapshot timing documentation
- Data provenance/snapshots not tracked
Environmental factors, including latency between primitives and the geographic distribution of devices, that affect the correctness and timeliness of decisions.
- Latency and distribution analysis affecting decisions
- Latency/environment risks unaddressed
A software or hardware product or service (for example cloud, computer, database) that executes processes or feeds data into the overall workflow of a network of things.
- eUtility (cloud/compute/db) trust and security controls
- External utilities not security-assessed
Creates the final result(s) needed to satisfy the purpose, specification, and requirements of a specific network of things, typically a conditional that initiates an action.
- Decision trigger logic and conditions
- Decision logic unverified
- No integrity over trigger conditions
Reliability, security, and data integrity considerations applied across the five primitives and their interactions to establish trustworthiness of a network of things.
- Reliability, security, and data integrity analysis across primitives
- No end-to-end trustworthiness analysis
NIST SP 800-183: Information Security Policies
An electronic utility that measures physical properties such as temperature, acceleration, weight, sound, or location, and outputs data about the physical environment.
- Sensor inventory and data integrity controls
- Sensor data integrity/authenticity unverified
A software implementation based on mathematical functions that transforms groups of raw sensor data into intermediate, aggregated data.
- Aggregation logic documentation and validation
- Aggregation functions unvalidated
An abstract grouping of sensors (or other devices) whose data is collected and aggregated; clusters may overlap and change over time.
- Sensor cluster definitions and membership management
- Cluster composition undocumented
The degree to which a particular sensor's data influences an aggregator's computation, reflecting trust and relevance.
- Sensor weighting/trust scheme documentation
- Weights/trust assignments unjustified
A medium by which data is transmitted between sensors, aggregators, communication channels, eUtilities, and decision triggers.
- Communication channel security (encryption, integrity)
- Unencrypted or unauthenticated channels
NoT Elements
Document the Cost element that captures expenses and risks associated with operating and maintaining a Network of Things including security cost.
- Total cost of ownership model
- Security cost component breakdown
- Risk to cost mapping
- Budget approvals
- Operational cost trend
- Security cost not separated
- Maintenance cost underestimated
- Risk treatment cost not modeled
- Lifecycle replacement cost absent
Document the Device ID element that uniquely identifies each NoT primitive instance enabling provenance, authentication, and tracking.
- Identifier scheme documentation
- Identifier registry
- Provenance records per device
- Identifier collision controls
- Authentication tied to identifier
- Identifier scheme lacks uniqueness across vendors
- No registry of issued identifiers
- Identifier spoofing not addressed
- Provenance chain broken at integration
Document the Environment element that describes the universe in which all NoT primitives operate including physical and logical conditions.
- Environment specification document
- Physical condition tolerances
- Operational scenarios
- Environmental risk register
- Site survey records
- Environment not formally documented
- Operational scenarios incomplete
- Environmental hazards not assessed
- Site conditions assumed but unverified
Document the Geographic Location element that captures the physical place where NoT primitives reside and the implications for data sovereignty, latency, and jurisdiction.
- Geographic placement map
- Data sovereignty assessment
- Jurisdictional compliance matrix
- Latency budget per region
- Cross border data flow documentation
- Sensor locations not tracked
- Data sovereignty not assessed
- Cross border flows undocumented
- Jurisdictional regulations not mapped
Document the Owner element identifying the responsible person, organization, or entity for each primitive and the data it produces or consumes.
- Primitive ownership matrix
- Data ownership register
- Vendor accountability documentation
- Responsibility delegation records
- Escalation paths
- Ownership not assigned for shared assets
- Vendor and customer responsibilities blurred
- Data ownership disputed
- No owner of decommissioned primitives
Document the Snapshot element that captures an instant in time when sensor data and aggregator state were observed enabling reasoning over historical NoT behavior.
- Snapshot retention policy
- Time synchronization evidence
- Snapshot integrity controls
- Sample snapshot records
- Replay or audit capability
- No reliable timestamping
- Snapshots not retained for incident analysis
- Time skew across devices unmanaged
- No integrity check on stored snapshots
NoT Primitives
Identify and govern Aggregator primitives that are software implementations that transform groups of raw data into intermediate aggregated data through clusters or weights.
- Aggregator software inventory
- Aggregation logic documentation
- Cluster and weight definitions
- Aggregator change records
- Output validation evidence
- Aggregation logic opaque
- No change control on aggregation rules
- Aggregator integrity not verified
- Source data quality not assessed before aggregation
Identify and govern Communication Channel primitives that provide the medium by which data is transmitted between NoT primitives.
- Communication path diagrams
- Protocol inventory
- Encryption configuration per channel
- Channel availability metrics
- Resilience design documentation
- Wireless channels not enumerated
- Unencrypted channels in OT environment
- Channel resilience not tested
- Channel ownership unclear across vendors
Identify and govern Decision Trigger primitives that create the final result needed to satisfy the purpose, specification, and requirements of a specific Network of Things.
- Decision trigger rule sets
- Trigger to action mapping
- Audit log of triggered decisions
- Test results for trigger conditions
- Override or override capability evidence
- Trigger rules undocumented
- No audit of trigger firing history
- Override capability lacking
- Trigger thresholds not periodically reviewed
Identify and govern External Utility primitives such as cloud services or computing infrastructure that perform computations on behalf of the Network of Things.
- List of cloud and external services in NoT
- Service trust documentation
- Performance and reliability SLAs
- Vendor security attestations
- Dependency map
- External services not catalogued
- Trust relationships not documented
- SLAs missing for critical services
- No fallback for external utility failure
Identify and govern Sensor primitives that observe physical or electronic phenomena and produce data inputs to the Network of Things.
- Sensor inventory by deployment
- Sensor data sheet references
- Data flow diagrams
- Sensor onboarding records
- Calibration and maintenance log
- Sensor inventory incomplete for OT environment
- Sensor firmware versions unknown
- No periodic calibration evidence
- Sensor authentication absent
Risk Considerations
Assess mission risk arising from NoT deployments including safety, privacy, and operational impact of primitive failure or compromise.
- NoT specific risk assessment
- Safety impact analysis
- Privacy impact analysis
- Operational continuity plan for NoT
- Risk treatment plan
- No NoT specific risk assessment
- Safety risks not formally analyzed
- Privacy impact assessment absent for sensor data
- Continuity plan ignores NoT dependencies
Security Considerations
Apply security controls to Aggregator primitives including integrity of aggregation logic, protection against poisoned inputs, and audit of aggregation decisions.
- Aggregator code integrity verification
- Input validation rules
- Anomaly detection on inputs
- Change control on aggregation logic
- Audit log of aggregation outputs
- No input validation before aggregation
- Aggregator code unsigned
- Anomalies in inputs not flagged
- Aggregation logic changes not approved
Apply security controls to Communication Channel primitives including encryption, authentication, integrity protection, and availability assurance.
- Encryption coverage report
- Channel authentication mechanism
- Integrity protection design
- Jamming and denial of service resilience test
- Backup channel evidence
- Legacy protocols without encryption
- Channel authentication missing
- No protection against replay
- Single channel dependence
Apply security controls to Decision Trigger primitives including authorization for actions, override controls, and audit of decisions.
- Authorization rules for triggered actions
- Override capability evidence
- Decision audit log
- Safety interlocks
- Periodic review of decision logic
- Triggered actions execute without human review where required
- No override mechanism
- Decision audit incomplete
- Safety interlocks not tested
Apply security controls and oversight to External Utility primitives including vendor risk management, secure integration, and dependency monitoring.
- External utility risk assessment
- Integration security review
- API authentication and authorization evidence
- Continuous monitoring of vendor posture
- Contractual security obligations
- External utilities not formally assessed
- API keys long lived and shared
- No monitoring of vendor security posture
- Contractual security clauses absent
Apply security controls to Sensor primitives including physical protection, firmware integrity, authentication, and tamper detection.
- Sensor physical security assessment
- Firmware integrity verification
- Sensor authentication mechanism
- Tamper detection evidence
- Sensor patching evidence
- Sensors in public locations without tamper detection
- Firmware updates manual and infrequent
- Sensor authentication weak or absent
- Spoofing risk not addressed
Trust in Networks of Things
Establish trustworthiness of data generated, transmitted, and acted upon within the Network of Things through integrity, provenance, and authenticity controls.
- Data integrity mechanism documentation
- Provenance chain records
- Authenticity verification evidence
- Tamper detection capability
- Anomaly detection on data streams
- Data integrity not verified beyond transport
- No provenance for derived data
- Tamper detection absent at edge
- Anomalous data accepted by aggregators
Establish trust in the identity of each NoT primitive through unique identifiers, cryptographic credentials, and lifecycle controls.
- Identity issuance policy
- Credential management evidence
- Onboarding and revocation records
- Credential strength documentation
- Identity audit trail
- Default credentials remain in production
- No revocation capability for compromised devices
- Identity tied to shared secrets across fleet
- Onboarding not authenticated
Establish reliability of NoT primitives ensuring they perform their function consistently within defined tolerances and report failures predictably.
- Reliability targets per primitive
- Failure mode and effects analysis
- Mean time between failures data
- Failure reporting workflow
- Redundancy design documentation
- No reliability targets defined
- Failure modes not analyzed
- Silent failure modes not detected
- No redundancy for critical sensors
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-183 framework page.