NIST SP 800-53A Rev. 5
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Appendices D to F: Penetration Testing, Reporting and Ongoing Assessment
Uses adversarial testing to find and exploit weakness in a system under agreed rules, producing evidence that controls hold or do not under attack.
- rules of engagement with scope, timing and authorization
- test plan including the phases performed
- findings with exploitation evidence and impact
- retest evidence and remediation tracking
- testing authorized informally with no rules of engagement
- scope so narrow that the result is uninformative
- findings reported with no exploitation evidence to support severity
Sets what the assessment report must carry so that the reader can judge both the findings and the basis on which they were reached.
- assessment report containing scope, method, depth and coverage
- per-control findings with supporting evidence references
- statement of limitations and any scope reductions
- distribution and version control of the report
- report gives conclusions without method or coverage
- limitations omitted so the reader overstates the assurance
- report reissued without version control
Moves assessment from a point-in-time exercise to a continuing one, using automation where it can produce evidence more often and more reliably than a person.
- ongoing assessment strategy naming what is assessed continuously and at what frequency
- automated evidence collection configuration and its coverage
- validation that automated results are accurate
- integration of ongoing results into risk decisions
- automation collects data that nobody reviews
- automated results never validated against manual checks
- ongoing assessment claimed while the only evidence is annual
Appendix C: Assessment Methods and Attributes
Sets the scope and breadth of an assessment method, expressed as basic, focused or comprehensive sampling of the assessment objects.
- assigned coverage value per procedure
- population size and sample size with selection method
- evidence the sample is representative
- sample of one described as representative
- population undefined so coverage is unmeasurable
- coverage reduced during execution without record
Sets the rigour and level of detail of an examination, interview or test as basic, focused or comprehensive.
- assigned depth value per procedure
- evidence the applied rigour matches the assigned value
- rationale linking depth to the assurance requirement
- comprehensive claimed while the work performed was basic
- depth assigned uniformly with no thought
- depth not recorded at all
Reviews, inspects, observes, studies or analyses assessment objects to establish fact, understanding or the basis for a further judgement.
- list of objects examined with version and date
- examination notes recording what was seen
- retained copies or references to the examined artefacts
- examination recorded as a document title with no observation
- objects examined are drafts rather than issued versions
- examination substituted for testing on technical controls
Holds discussions with individuals or groups to gather understanding, clarify how something operates, or obtain evidence that a practice is real.
- interview record with participant role and date
- questions asked and responses summarized
- corroboration of interview claims by examine or test
- interviews with managers only, never with the people who perform the work
- claims accepted with no corroboration
- no record of who was interviewed
Exercises an assessment object under specified conditions and compares actual behaviour with expected behaviour.
- test procedure with conditions and expected result
- actual result captured as output, screenshot or log
- record of the test environment and its equivalence to production
- retest evidence after remediation
- expected result not stated so any outcome passes
- testing performed in an environment unlike production
- negative cases never tested
Chapter Three: The Assessment Process
Establishes the preparation that makes an assessment executable: scope, objectives, assessor competence and independence, logistics and access to evidence.
- assessment scope and objective statement
- assessor competence and independence records
- agreed access to systems, documents and personnel
- schedule and points of contact
- assessor independence assumed rather than documented
- access arranged after the assessment starts
- scope agreed verbally and later disputed
Fixes which controls fall in the assessment, from the security and privacy plans and the reason the assessment is being run.
- list of controls in scope with the basis for inclusion
- reference to the system security and privacy plans
- record of controls excluded and why
- evidence scope matches the purpose of the assessment
- scope copied from a prior assessment without review
- exclusions undocumented
- inherited controls neither included nor formally attributed elsewhere
Selects the assessment procedures matching the controls in scope so that every in-scope control has a procedure behind it.
- mapping from each in-scope control to its selected procedure
- evidence of full coverage of the scoped set
- identification of controls with no standard procedure
- procedures selected for the baseline while tailored controls are missed
- coverage gaps discovered mid-assessment
- procedure selected but its determination statements dropped
Adjusts the standard procedures to the system, the platform and the assessment purpose, and records why each adjustment was made.
- tailoring decisions recorded per procedure
- rationale for each adjustment
- approval of the tailored plan
- comparison of tailored to standard procedure
- tailoring used to remove effort rather than to fit context
- adjustments made without record
- tailored plan not approved before execution
Adjusts which methods and objects a procedure uses, since not every mechanism, activity or individual is relevant to every system.
- record of methods and objects added or removed per procedure
- justification tied to system characteristics
- evidence relevant objects were not silently dropped
- test method removed for technical controls with no compensating rigour
- objects narrowed to what is easy to reach
- no record of what the standard procedure originally required
Sets the rigour of each method, basic, focused or comprehensive, and the size of the sample, in line with the assurance needed.
- depth and coverage value assigned per procedure
- sampling plan and population size
- rationale linking rigour to assurance requirement
- evidence the assigned depth was actually applied
- depth assigned in the plan and ignored in execution
- sample chosen for convenience rather than representativeness
- population size unknown so coverage cannot be judged
Handles controls provided in whole or part by a common control provider, so that inherited controls are assessed once and attributed correctly.
- identification of common and hybrid controls and their provider
- provider assessment results and their currency
- statement of what the system inherits and what it implements
- agreement with the provider on assessment responsibility
- inheritance claimed with no provider evidence
- hybrid controls assessed as fully inherited
- provider results out of date or out of scope
Adjusts procedures for the actual technology and organizational context, including platforms where a standard procedure does not fit.
- platform inventory informing tailoring
- adjusted procedures for non-standard platforms
- record of organizational constraints affecting the assessment
- procedures written for servers applied unchanged to operational technology or cloud
- organizational constraints used to justify no assessment at all
- platform differences discovered during execution
Governs when results from earlier assessments may be reused, judged on age, independence, scope and whether the system has changed since.
- record of results proposed for reuse with their date and type
- validation of independence and scope of the earlier assessment
- assessment of change since the earlier result
- documented decision to reuse recorded in the assessment plan
- reuse of a self-assessment where independence was required
- reuse without checking what changed since
- reuse decision made informally and not recorded in the plan
Handles controls provided by external systems and providers, where assessment depends on contracts, agreements and third-party evidence.
- inventory of external systems in scope
- contract or agreement terms establishing assessment rights
- third-party assessment reports and their scope and period
- gap analysis where third-party scope falls short
- third-party report accepted without reading its scope
- no assessment rights in the agreement
- complementary user entity responsibilities never addressed
Requires assessment procedures to be written for controls the organization added itself, so tailored controls are not left unassessed.
- list of organization-specific controls
- assessment procedures authored for each
- integration of those procedures into the assessment plan
- review of the authored procedures
- organization-specific controls present in the plan with no procedure
- procedures authored but never integrated
- authored procedures lacking determination statements
Sequences and consolidates procedures so shared evidence is gathered once, without reducing the rigour that was set.
- consolidated evidence requests across procedures
- assessment sequence or schedule
- record showing consolidation did not reduce depth or coverage
- optimization used as cover for cutting scope
- evidence requested repeatedly from the same owners
- sequence ignores dependencies so findings arrive too late
Fixes the plan and secures approval to execute before assessment begins, so scope and rigour are agreed rather than negotiated during fieldwork.
- final assessment plan with version
- approval record from the authorizing party
- change control over the plan during execution
- distribution to the assessed organization
- assessment begins before approval
- plan changed during fieldwork with no record
- approval by the team being assessed
Executes the approved plan and records, for each determination statement, whether it is satisfied or other than satisfied, with the supporting evidence.
- completed procedures with per-statement judgements
- evidence register linking each judgement to its source
- record of deviations from the plan during execution
- assessor notes supporting other-than-satisfied findings
- judgements recorded with no evidence reference
- deviations from the plan undocumented
- findings softened before the report is written
Turns raw findings into a risk view: what the weakness actually enables, whether it is real, and what should be done about it.
- analysis of findings including cause and exploitability
- risk determination per finding
- recommendations and their basis
- record of findings disputed and how resolved
- findings listed with severity from a tool and no analysis
- risk assigned without considering the environment
- recommendations generic enough to fit any finding
Assesses whether a set of controls working together delivers the intended capability, rather than only whether each control passes in isolation.
- defined capabilities and the controls constituting each
- assessment of the capability as a whole
- record of cases where all controls passed but the capability did not
- reporting at capability level
- capability never defined so only individual controls are judged
- aggregate weakness invisible because each control passed
- capability assessment asserted with no method
Chapter Two: The Fundamentals
Places control assessment inside the development life cycle rather than at the end of it, so that findings arrive while they can still change the build.
- assessment activities scheduled against life cycle stages
- developmental assessment results feeding design decisions
- evidence assessment findings changed a build or design
- criteria for what is assessed at each stage
- assessment scheduled only before authorization
- developmental testing results discarded rather than reused
- no defined trigger for reassessment on major change
Establishes how a control decomposes into its parts, since the assessment objective is derived from that structure rather than invented.
- worked example showing a control broken into its constituent statements
- mapping from control parts to assessment objectives
- evidence organization-defined parameters are resolved before assessment
- organization-defined parameters left unresolved so the control cannot be assessed
- control assessed as a single yes or no
- assessment written against a paraphrase rather than the control statement
Treats the assessment as the construction of an assurance case: claims about the system supported by evidence of sufficient quality and quantity.
- stated assurance claims for the system
- evidence set supporting each claim with its source
- rationale for why the evidence is sufficient
- record of evidence rejected as insufficient
- evidence collected in volume with no claim it supports
- sufficiency asserted rather than reasoned
- assurance case never revisited as the system changes
Names what an assessment is performed against: specifications, mechanisms, activities and individuals, so that scope is concrete rather than abstract.
- object list per procedure identifying specifications, mechanisms, activities and individuals
- sampling basis where objects are numerous
- evidence objects were actually available at assessment time
- objects described generically as the system
- individuals named by role with no one identified to interview
- mechanisms listed but never inspected
Establishes the three methods, examine, interview and test, and requires the method chosen to suit the objective rather than the convenience of the assessor.
- method selected per determination statement with rationale
- evidence that more than documentary examination was used for technical controls
- records of each method as applied
- everything assessed by examine because it is cheapest
- interview used to establish technical fact
- test claimed with no test artefact
Frames the assessment as a set of determination statements derived from the control, each of which must be judged satisfied or other than satisfied.
- determination statements per control assessed
- judgement recorded against each statement
- evidence linked to the specific statement it supports
- a single judgement recorded for a multi-part control
- statements marked satisfied with no linked evidence
- statements reworded until they can be met
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-53A Rev. 5 framework page.