Skip to content

Evidence request lists

NIST SP 800-92

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Integration with NIST Family and Maturity

NISTSP92-8
Integration with NIST SP 800-53 AU Family, SP 800-137 ConMon, SP 800-61 IR, and Maturity

Integrate log management with broader NIST family per NIST SP 800-92 Chapter 6 (Establishing and Maintaining Log Management Infrastructures) + cross-references throughout. Integration with NIST SP 800-53 Rev 5 Audit and Accountability (AU) family: meet AU-1 through AU-16 control requirements (Policy + Audit Events + Content + Capacity + Response to Failures + Review-Analysis-Reporting + Reduction-Report Generation + Time Stamps + Protection + Non-Repudiation + Retention + Generation + Monitoring-Alerting + Cross-Organisation Auditing + Session Audit + Alternate Audit Capability + Audit Records Format Standardisation). Integration with NIST SP 800-137 Information Security Continuous Monitoring: log management is a primary continuous-monitoring data source feeding security posture metrics + control assessment + risk re-assessment + RMF Authorize maintenance. Integration with NIST SP 800-61

Artefacts an auditor will ask for
  • mapping evidence to NIST SP 800-53 AU family controls
  • continuous monitoring integration evidence per SP 800-137
  • IR runbook integration with log query playbooks per common incident category
  • maturity assessment + year-over-year advancement evidence
Where this commonly fails
  • log management isolated from AU compliance / ConMon / IR resulting in duplicate effort
  • no maturity assessment + no improvement plan
  • log query playbooks absent for IR producing slow investigation

Log Analysis and Detection

NISTSP92-5
Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review

Operate log analysis per NIST SP 800-92 Chapter 5 (Operational Processes) + Section 5.12 (Performing Log Analysis). Correlation and detection rules per Section 5.12.1: implement correlation rules combining signals across sources (authentication + endpoint + network + identity + cloud + application) to detect compound attack patterns (credential stuffing + lateral movement + data exfiltration + insider misuse + supply chain compromise + ransomware staging) + maintain rule lifecycle (development + test + deployment + tuning + retirement) + track false positive and true positive rate + align rule coverage with MITRE ATTandCK. Baselining and anomaly detection per Section 5.12.2: capture normal behaviour baselines per user + asset + service + apply statistical or machine learning anomaly detection where signature-based detection is insufficient + manage model drift + bias + explainability. Al

Artefacts an auditor will ask for
  • correlation rule catalogue with lifecycle + tuning metrics + MITRE ATTandCK mapping
  • baselining and anomaly detection configuration + model drift management
  • alerting workflow + case management integration + SLA + escalation + closure
  • scheduled manual review evidence for high-value low-volume sources
  • forensic search capability + chain-of-custody preservation
Where this commonly fails
  • correlation rules deployed but never tuned producing alert fatigue
  • no manual review of high-value low-volume sources
  • no MITRE coverage tracking

Log Generation

NISTSP92-2
Log Generation: OS, Application, Security Tools, Network, Cloud, Required Event Content

Configure log generation across all sources per NIST SP 800-92 Chapter 2 (Log Categories) + Chapter 3 (Log Management Infrastructure) + Chapter 5 (Log Management Operational Processes). Operating system log generation per Section 2.2.1: enable and configure system logs (Windows Event Log + Linux syslog/journald + macOS unified log + Solaris audit) capturing authentication + privilege use + system events + service starts/stops + audit events. Application and service logging per Section 2.2.2: enable application audit logs covering authentication + authorisation + transactions + errors + administrative actions with consistent format and identifiers across the application portfolio. Security tool logging per Section 2.2.3: include firewall + IDS/IPS + antivirus + EDR + vulnerability scanners + DLP + WAF + identity broker + secrets management + cloud security posture + container runtime + si

Artefacts an auditor will ask for
  • log source inventory per category (OS + app + security tool + network + cloud + SaaS)
  • required event content standard with field list (timestamp + source + type + principal + asset + action + outcome + context)
  • log generation configuration evidence per source
  • coverage report mapping log sources against asset inventory
Where this commonly fails
  • inconsistent event content across sources preventing correlation
  • cloud audit logs not enabled (eg CloudTrail in management account only)
  • endpoint logging incomplete coverage

Log Infrastructure

NISTSP92-3
Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance

Design and operate the log management infrastructure per NIST SP 800-92 Chapter 3 (Log Management Infrastructure) + Chapter 5 (Operational Processes). Log management infrastructure architecture per Section 3.2: (a) tiered architecture covering generation + collection + storage + analysis + reporting, (b) high-availability across collection and storage tiers with documented RTO/RPO, (c) capacity sizing per Section 3.4 with documented log volume forecasting + growth model + headroom planning. Centralised log collection per Section 3.2.2: forwarders or agents (host-installed + sidecar + agentless cloud + tap) deliver to one or more central log management systems + minimise local log retention to reduce attacker advantage. Log transport security per Section 5.3: encrypted in transit (TLS preferred + IPsec + or equivalent), authenticated source + destination, integrity validation, queue/buffe

Artefacts an auditor will ask for
  • log management architecture diagrams + tier definitions + HA + capacity
  • transport security evidence (TLS / IPsec / authenticated + integrity-validated)
  • agent health monitoring with silent-source alerting
  • SIEM governance + correlation rule lifecycle + use-case coverage versus MITRE ATTandCK
Where this commonly fails
  • agent failure goes undetected (silent source not alerted)
  • log transport unencrypted on internal network
  • no SIEM use-case coverage map vs MITRE ATTandCK

Log Management Operations

NISTSP92-4
Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control

Operate log management functions per NIST SP 800-92 Chapter 5 (Operational Processes) + Section 5.5 (Confidentiality, Integrity, and Availability of Logs). Time synchronisation per Section 5.6: deploy NTP (or equivalent) infrastructure with redundant authoritative sources + stratum hierarchy + drift monitoring + alerting + timezone normalisation in central log store (UTC preferred). Log parsing and normalisation per Section 5.7: parse incoming logs to a common schema (Common Event Format + Elastic Common Schema + or vendor schema) + maintain parser catalogue + versioning + test framework + monitoring for parsing failures. Log storage capacity planning per Section 5.8: tiered storage matching access pattern (hot for current incidents + warm for routine query + cold for retention + archive for long-term legal/regulatory) with capacity monitoring + scale triggers + cost optimisation. Log in

Artefacts an auditor will ask for
  • NTP architecture + drift monitoring + UTC normalisation evidence
  • parser catalogue + versioning + parsing failure monitoring
  • tiered storage configuration + capacity monitoring + cost optimisation
  • log integrity protection (WORM / hash chain / signature) + access control + separation of duties + access logging
  • redaction / masking of sensitive content in logs
Where this commonly fails
  • time skew between sources prevents correlation
  • log access not separated between producers and administrators
  • sensitive content logged in plaintext

Log Management Programme

NISTSP92-1
Log Management Programme, Policy, Roles, and Operational Runbooks

Establish a log management programme per NIST SP 800-92 Chapter 2 (Introduction to Computer Security Log Management) + Chapter 4 (Log Management Planning). The programme must (a) define scope of logs covered (operating system + application + service + security tool + network device + cloud + SaaS + identity systems + database + storage), (b) document log management policy approved at senior level with categorisation of logs by criticality + sensitivity + retention class, (c) name accountable roles per Section 4.2: System Owners + Log Management Administrators + Log Reviewers + Privacy Officers + Information Security Officer + Audit Function + Legal + IR + Forensics + Incident Handlers + Application Owners + with documented responsibilities and SLA per role, (d) maintain operational runbooks covering log onboarding + parser maintenance + storage management + access requests + incident res

Artefacts an auditor will ask for
  • approved log management policy covering scope + categories + retention
  • named roles per SP 800-92 Section 4.2 with documented responsibilities + SLAs
  • operational runbooks per role and per workflow
  • annual programme review evidence
Where this commonly fails
  • policy approved but operational runbooks absent
  • no named log management administrator role
  • no annual programme review evidence

Log Retention and Disposition

NISTSP92-6
Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold

Operate log retention per NIST SP 800-92 Chapter 4 (Planning) Section 4.5 + Chapter 5 Operational Processes. Retention policy aligned to legal and regulatory requirements: document retention period per log category (security event logs + audit logs + access logs + system logs + application logs + privacy event logs) matching the longest applicable obligation (regulatory + contractual + investigative + organisational policy). Online vs archive storage tiers: hot storage for incident response horizon (typically 30-90 days online) + warm for routine investigation (typically 1 year) + cold archive for long-term compliance (3+ years up to indefinite for some regulators) + balance cost + retrieval time + integrity guarantee per tier. Backup and recoverability of log data: replicate or back up logs to a separate facility or storage class + test recovery + measure RTO for log data + protect agai

Artefacts an auditor will ask for
  • retention policy per log category aligned to longest applicable obligation
  • tier configuration (hot + warm + cold + archive) with cost + retrieval + integrity per tier
  • log backup + recoverability evidence with RTO measurement
  • secure disposal per NIST SP 800-88 at end of retention
  • legal hold mechanism + integration with case management
Where this commonly fails
  • retention drift longer than necessary increasing breach exposure
  • no log backup so ransomware can destroy evidence
  • legal hold flagging not implemented

Privacy + Cloud/SaaS Logs

NISTSP92-7
Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations

Handle privacy and sensitive content in logs + cloud/SaaS log considerations per NIST SP 800-92 Section 5.11 (Confidentiality and Privacy) + updates aligned with modern cloud-era practice + GDPR + CCPA + sectoral privacy law + HIPAA Privacy Rule. Privacy and data minimisation: review what is captured by each log source + scrub or redact unnecessary personal data + pseudonymise where analytical value justifies retention + document the legal basis for log content under applicable privacy regimes + provide subject access pathways where required + apply data subject rights honoring deletion + correction + portability requests with logs scoped to investigative-necessity carve-outs where applicable + document the carve-out rationale. Sensitive content handling: never log passwords + tokens + cryptographic keys + cardholder data + clinical data + classified content + with technical enforcement

Artefacts an auditor will ask for
  • privacy review per log source + data minimisation evidence
  • sensitive content detection + retroactive cleanup process
  • cloud/SaaS log gap analysis per service + augmentation plan + residual risk acceptance
Where this commonly fails
  • no privacy review producing GDPR/CCPA exposure in logs
  • passwords or tokens leaked into logs without detection
  • cloud/SaaS log gap not analysed producing detection blind spots
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-92 framework page.