What evidence should teams collect for NIST SP 800-53A control assessments?
Map evidence to each , not only to the control identifier. An is a specification, mechanism, activity, or individual selected for review. The potential methods and objects in a procedure are a starting point; SP 800-53A does not expect every listed method and object to be used. The assessment plan selects the combination needed for the system, operating conditions, risk, and assurance requirement.
Preserve the completed control text and organization-defined parameters; the object examined, individual or group interviewed, or mechanism or activity tested; the assessed boundary; evidence date; population and sample when sampling is used; assessor; finding; and limitations. This record lets a reviewer understand why a determination was satisfied or other than satisfied.
Existing evidence may be reused only after the organization decides it remains credible and applicable to current operating conditions. Record the original assessment date and type, identify changes since that assessment, and add new work when the earlier coverage does not address the current configuration or objective. A current policy can support intended requirements, for example, but it cannot by itself show that a technical mechanism operated as configured during the assessed period.
- Examine specifications and records such as plans, procedures, configurations, inventories, logs, tickets, approvals, and prior assessment results.
- Interview the people who perform, oversee, or depend on the activity when their knowledge or execution is part of the determination.
- Test mechanisms or activities under stated conditions when behavior or operating effectiveness must be observed.
- Record depth as basic, focused, or comprehensive and record coverage as basic, focused, or comprehensive for each selected method.
- For inherited controls, verify actual inheritance and obtain the common-control provider's applicable assessment results instead of treating a matching identifier as evidence.
Defines completed control statements, organization-defined parameters, common controls, hybrid controls, and control enhancements that assessment evidence must address.
Sections 2.4 and 3.2 and Appendices C and E define assessment objectives, determination statements, objects, methods, depth, coverage, evidence selection, reuse, and findings.