Skip to content

Evidence request lists

NIST SP 800-53A Rev. 5

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Appendices D to F: Penetration Testing, Reporting and Ongoing Assessment

53A-D
Penetration Testing

Uses adversarial testing to find and exploit weakness in a system under agreed rules, producing evidence that controls hold or do not under attack.

Artefacts an auditor will ask for
  • rules of engagement with scope, timing and authorization
  • test plan including the phases performed
  • findings with exploitation evidence and impact
  • retest evidence and remediation tracking
Where this commonly fails
  • testing authorized informally with no rules of engagement
  • scope so narrow that the result is uninformative
  • findings reported with no exploitation evidence to support severity
53A-E
Assessment Reports

Sets what the assessment report must carry so that the reader can judge both the findings and the basis on which they were reached.

Artefacts an auditor will ask for
  • assessment report containing scope, method, depth and coverage
  • per-control findings with supporting evidence references
  • statement of limitations and any scope reductions
  • distribution and version control of the report
Where this commonly fails
  • report gives conclusions without method or coverage
  • limitations omitted so the reader overstates the assurance
  • report reissued without version control
53A-F
Ongoing Assessment and Automation

Moves assessment from a point-in-time exercise to a continuing one, using automation where it can produce evidence more often and more reliably than a person.

Artefacts an auditor will ask for
  • ongoing assessment strategy naming what is assessed continuously and at what frequency
  • automated evidence collection configuration and its coverage
  • validation that automated results are accurate
  • integration of ongoing results into risk decisions
Where this commonly fails
  • automation collects data that nobody reviews
  • automated results never validated against manual checks
  • ongoing assessment claimed while the only evidence is annual

Appendix C: Assessment Methods and Attributes

53A-C-COVERAGE
Assessment Attribute: Coverage

Sets the scope and breadth of an assessment method, expressed as basic, focused or comprehensive sampling of the assessment objects.

Artefacts an auditor will ask for
  • assigned coverage value per procedure
  • population size and sample size with selection method
  • evidence the sample is representative
Where this commonly fails
  • sample of one described as representative
  • population undefined so coverage is unmeasurable
  • coverage reduced during execution without record
53A-C-DEPTH
Assessment Attribute: Depth

Sets the rigour and level of detail of an examination, interview or test as basic, focused or comprehensive.

Artefacts an auditor will ask for
  • assigned depth value per procedure
  • evidence the applied rigour matches the assigned value
  • rationale linking depth to the assurance requirement
Where this commonly fails
  • comprehensive claimed while the work performed was basic
  • depth assigned uniformly with no thought
  • depth not recorded at all
53A-C-EXAMINE
Assessment Method: Examine

Reviews, inspects, observes, studies or analyses assessment objects to establish fact, understanding or the basis for a further judgement.

Artefacts an auditor will ask for
  • list of objects examined with version and date
  • examination notes recording what was seen
  • retained copies or references to the examined artefacts
Where this commonly fails
  • examination recorded as a document title with no observation
  • objects examined are drafts rather than issued versions
  • examination substituted for testing on technical controls
53A-C-INTERVIEW
Assessment Method: Interview

Holds discussions with individuals or groups to gather understanding, clarify how something operates, or obtain evidence that a practice is real.

Artefacts an auditor will ask for
  • interview record with participant role and date
  • questions asked and responses summarized
  • corroboration of interview claims by examine or test
Where this commonly fails
  • interviews with managers only, never with the people who perform the work
  • claims accepted with no corroboration
  • no record of who was interviewed
53A-C-TEST
Assessment Method: Test

Exercises an assessment object under specified conditions and compares actual behaviour with expected behaviour.

Artefacts an auditor will ask for
  • test procedure with conditions and expected result
  • actual result captured as output, screenshot or log
  • record of the test environment and its equivalence to production
  • retest evidence after remediation
Where this commonly fails
  • expected result not stated so any outcome passes
  • testing performed in an environment unlike production
  • negative cases never tested

Chapter Three: The Assessment Process

53A-3.1
Prepare for Control Assessments

Establishes the preparation that makes an assessment executable: scope, objectives, assessor competence and independence, logistics and access to evidence.

Artefacts an auditor will ask for
  • assessment scope and objective statement
  • assessor competence and independence records
  • agreed access to systems, documents and personnel
  • schedule and points of contact
Where this commonly fails
  • assessor independence assumed rather than documented
  • access arranged after the assessment starts
  • scope agreed verbally and later disputed
53A-3.2.1
Determine Which Controls Are to Be Assessed

Fixes which controls fall in the assessment, from the security and privacy plans and the reason the assessment is being run.

Artefacts an auditor will ask for
  • list of controls in scope with the basis for inclusion
  • reference to the system security and privacy plans
  • record of controls excluded and why
  • evidence scope matches the purpose of the assessment
Where this commonly fails
  • scope copied from a prior assessment without review
  • exclusions undocumented
  • inherited controls neither included nor formally attributed elsewhere
53A-3.2.2
Select Procedures to Assess the Controls

Selects the assessment procedures matching the controls in scope so that every in-scope control has a procedure behind it.

Artefacts an auditor will ask for
  • mapping from each in-scope control to its selected procedure
  • evidence of full coverage of the scoped set
  • identification of controls with no standard procedure
Where this commonly fails
  • procedures selected for the baseline while tailored controls are missed
  • coverage gaps discovered mid-assessment
  • procedure selected but its determination statements dropped
53A-3.2.3
Tailor Assessment Procedures

Adjusts the standard procedures to the system, the platform and the assessment purpose, and records why each adjustment was made.

Artefacts an auditor will ask for
  • tailoring decisions recorded per procedure
  • rationale for each adjustment
  • approval of the tailored plan
  • comparison of tailored to standard procedure
Where this commonly fails
  • tailoring used to remove effort rather than to fit context
  • adjustments made without record
  • tailored plan not approved before execution
53A-3.2.3.1
Method and Object Considerations in Tailoring

Adjusts which methods and objects a procedure uses, since not every mechanism, activity or individual is relevant to every system.

Artefacts an auditor will ask for
  • record of methods and objects added or removed per procedure
  • justification tied to system characteristics
  • evidence relevant objects were not silently dropped
Where this commonly fails
  • test method removed for technical controls with no compensating rigour
  • objects narrowed to what is easy to reach
  • no record of what the standard procedure originally required
53A-3.2.3.2
Depth and Coverage Considerations in Tailoring

Sets the rigour of each method, basic, focused or comprehensive, and the size of the sample, in line with the assurance needed.

Artefacts an auditor will ask for
  • depth and coverage value assigned per procedure
  • sampling plan and population size
  • rationale linking rigour to assurance requirement
  • evidence the assigned depth was actually applied
Where this commonly fails
  • depth assigned in the plan and ignored in execution
  • sample chosen for convenience rather than representativeness
  • population size unknown so coverage cannot be judged
53A-3.2.3.3
Common Control Considerations in Tailoring

Handles controls provided in whole or part by a common control provider, so that inherited controls are assessed once and attributed correctly.

Artefacts an auditor will ask for
  • identification of common and hybrid controls and their provider
  • provider assessment results and their currency
  • statement of what the system inherits and what it implements
  • agreement with the provider on assessment responsibility
Where this commonly fails
  • inheritance claimed with no provider evidence
  • hybrid controls assessed as fully inherited
  • provider results out of date or out of scope
53A-3.2.3.4
System, Platform and Organization Considerations in Tailoring

Adjusts procedures for the actual technology and organizational context, including platforms where a standard procedure does not fit.

Artefacts an auditor will ask for
  • platform inventory informing tailoring
  • adjusted procedures for non-standard platforms
  • record of organizational constraints affecting the assessment
Where this commonly fails
  • procedures written for servers applied unchanged to operational technology or cloud
  • organizational constraints used to justify no assessment at all
  • platform differences discovered during execution
53A-3.2.3.5
Reuse of Assessment Evidence

Governs when results from earlier assessments may be reused, judged on age, independence, scope and whether the system has changed since.

Artefacts an auditor will ask for
  • record of results proposed for reuse with their date and type
  • validation of independence and scope of the earlier assessment
  • assessment of change since the earlier result
  • documented decision to reuse recorded in the assessment plan
Where this commonly fails
  • reuse of a self-assessment where independence was required
  • reuse without checking what changed since
  • reuse decision made informally and not recorded in the plan
53A-3.2.3.6
External System Considerations

Handles controls provided by external systems and providers, where assessment depends on contracts, agreements and third-party evidence.

Artefacts an auditor will ask for
  • inventory of external systems in scope
  • contract or agreement terms establishing assessment rights
  • third-party assessment reports and their scope and period
  • gap analysis where third-party scope falls short
Where this commonly fails
  • third-party report accepted without reading its scope
  • no assessment rights in the agreement
  • complementary user entity responsibilities never addressed
53A-3.2.4
Develop Procedures for Organization-Specific Controls

Requires assessment procedures to be written for controls the organization added itself, so tailored controls are not left unassessed.

Artefacts an auditor will ask for
  • list of organization-specific controls
  • assessment procedures authored for each
  • integration of those procedures into the assessment plan
  • review of the authored procedures
Where this commonly fails
  • organization-specific controls present in the plan with no procedure
  • procedures authored but never integrated
  • authored procedures lacking determination statements
53A-3.2.5
Optimize Selected Assessment Procedures

Sequences and consolidates procedures so shared evidence is gathered once, without reducing the rigour that was set.

Artefacts an auditor will ask for
  • consolidated evidence requests across procedures
  • assessment sequence or schedule
  • record showing consolidation did not reduce depth or coverage
Where this commonly fails
  • optimization used as cover for cutting scope
  • evidence requested repeatedly from the same owners
  • sequence ignores dependencies so findings arrive too late
53A-3.2.6
Finalize the Assessment Plan and Obtain Approval

Fixes the plan and secures approval to execute before assessment begins, so scope and rigour are agreed rather than negotiated during fieldwork.

Artefacts an auditor will ask for
  • final assessment plan with version
  • approval record from the authorizing party
  • change control over the plan during execution
  • distribution to the assessed organization
Where this commonly fails
  • assessment begins before approval
  • plan changed during fieldwork with no record
  • approval by the team being assessed
53A-3.3
Conduct Control Assessments

Executes the approved plan and records, for each determination statement, whether it is satisfied or other than satisfied, with the supporting evidence.

Artefacts an auditor will ask for
  • completed procedures with per-statement judgements
  • evidence register linking each judgement to its source
  • record of deviations from the plan during execution
  • assessor notes supporting other-than-satisfied findings
Where this commonly fails
  • judgements recorded with no evidence reference
  • deviations from the plan undocumented
  • findings softened before the report is written
53A-3.4
Analyze Assessment Report Results

Turns raw findings into a risk view: what the weakness actually enables, whether it is real, and what should be done about it.

Artefacts an auditor will ask for
  • analysis of findings including cause and exploitability
  • risk determination per finding
  • recommendations and their basis
  • record of findings disputed and how resolved
Where this commonly fails
  • findings listed with severity from a tool and no analysis
  • risk assigned without considering the environment
  • recommendations generic enough to fit any finding
53A-3.5
Assess Security and Privacy Capabilities

Assesses whether a set of controls working together delivers the intended capability, rather than only whether each control passes in isolation.

Artefacts an auditor will ask for
  • defined capabilities and the controls constituting each
  • assessment of the capability as a whole
  • record of cases where all controls passed but the capability did not
  • reporting at capability level
Where this commonly fails
  • capability never defined so only individual controls are judged
  • aggregate weakness invisible because each control passed
  • capability assessment asserted with no method

Chapter Two: The Fundamentals

53A-2.1
Assessments Within the System Development Life Cycle

Places control assessment inside the development life cycle rather than at the end of it, so that findings arrive while they can still change the build.

Artefacts an auditor will ask for
  • assessment activities scheduled against life cycle stages
  • developmental assessment results feeding design decisions
  • evidence assessment findings changed a build or design
  • criteria for what is assessed at each stage
Where this commonly fails
  • assessment scheduled only before authorization
  • developmental testing results discarded rather than reused
  • no defined trigger for reassessment on major change
53A-2.2
Control Structure and Organization

Establishes how a control decomposes into its parts, since the assessment objective is derived from that structure rather than invented.

Artefacts an auditor will ask for
  • worked example showing a control broken into its constituent statements
  • mapping from control parts to assessment objectives
  • evidence organization-defined parameters are resolved before assessment
Where this commonly fails
  • organization-defined parameters left unresolved so the control cannot be assessed
  • control assessed as a single yes or no
  • assessment written against a paraphrase rather than the control statement
53A-2.3
Building an Effective Assurance Case

Treats the assessment as the construction of an assurance case: claims about the system supported by evidence of sufficient quality and quantity.

Artefacts an auditor will ask for
  • stated assurance claims for the system
  • evidence set supporting each claim with its source
  • rationale for why the evidence is sufficient
  • record of evidence rejected as insufficient
Where this commonly fails
  • evidence collected in volume with no claim it supports
  • sufficiency asserted rather than reasoned
  • assurance case never revisited as the system changes
53A-2.4.1
Assessment Objects

Names what an assessment is performed against: specifications, mechanisms, activities and individuals, so that scope is concrete rather than abstract.

Artefacts an auditor will ask for
  • object list per procedure identifying specifications, mechanisms, activities and individuals
  • sampling basis where objects are numerous
  • evidence objects were actually available at assessment time
Where this commonly fails
  • objects described generically as the system
  • individuals named by role with no one identified to interview
  • mechanisms listed but never inspected
53A-2.4.2
Assessment Methods

Establishes the three methods, examine, interview and test, and requires the method chosen to suit the objective rather than the convenience of the assessor.

Artefacts an auditor will ask for
  • method selected per determination statement with rationale
  • evidence that more than documentary examination was used for technical controls
  • records of each method as applied
Where this commonly fails
  • everything assessed by examine because it is cheapest
  • interview used to establish technical fact
  • test claimed with no test artefact
53A-2.4.3
Assessment Objectives and Determination Statements

Frames the assessment as a set of determination statements derived from the control, each of which must be judged satisfied or other than satisfied.

Artefacts an auditor will ask for
  • determination statements per control assessed
  • judgement recorded against each statement
  • evidence linked to the specific statement it supports
Where this commonly fails
  • a single judgement recorded for a multi-part control
  • statements marked satisfied with no linked evidence
  • statements reworded until they can be met
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-53A Rev. 5 framework page.