NIST SP 800-171 Rev 3: the evidence behind every control
97 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
03.01 AC (Access Control)
03.01.01Account Management hard03.01.02Access Enforcement moderate03.01.03Information Flow Enforcement easy03.01.04Separation of Duties hard03.01.05Least Privilege moderate03.01.06Least Privilege - Privileged Accounts moderate03.01.07Least Privilege - Privileged Functions easy03.01.08Unsuccessful Logon Attempts hard03.01.09System Use Notification moderate03.01.10Device Lock easy03.01.11Session Termination easy03.01.12Remote Access easy03.01.16Wireless Access hard03.01.18Access Control for Mobile Devices moderate03.01.20Use of External Systems hard03.01.22Publicly Accessible Content hard03.02 AT (Awareness and Training)
03.03 AU (Audit and Accountability)
03.03.01Event Logging moderate03.03.02Audit Record Content easy03.03.03Audit Record Generation moderate03.03.04Response to Audit Logging Process Failures easy03.03.05Audit Record Review, Analysis, and Reporting moderate03.03.06Audit Record Reduction and Report Generation easy03.03.07Time Stamps easy03.03.08Protection of Audit Information easy03.04 CM (Configuration Management)
03.04.01Baseline Configuration hard03.04.02Configuration Settings easy03.04.03Configuration Change Control moderate03.04.04Impact Analyses hard03.04.05Access Restrictions for Change hard03.04.06Least Functionality moderate03.04.08Authorized Software - Allow by Exception moderate03.04.10System Component Inventory easy03.04.11Information Location hard03.04.12System and Component Configuration for High-Risk Areas hard03.05 IA (Identification and Authentication)
03.05.01User Identification and Authentication easy03.05.02Device Identification and Authentication moderate03.05.03Multi-Factor Authentication easy03.05.04Replay-Resistant Authentication easy03.05.05Identifier Management hard03.05.07Password Management hard03.05.11Authentication Feedback hard03.05.12Authenticator Management moderate03.06 IR (Incident Response)
03.06.01Incident Handling hard03.06.02Incident Monitoring, Reporting, and Response Assistance hard03.06.03Incident Response Testing hard03.06.04Incident Response Training hard03.06.05Incident Response Plan hard03.07 MA (Maintenance)
03.07.04Maintenance Tools moderate03.07.05Nonlocal Maintenance hard03.07.06Maintenance Personnel moderate03.08 MP (Media Protection)
03.08.01Media Storage moderate03.08.02Media Access easy03.08.03Media Sanitization easy03.08.04Media Marking hard03.08.05Media Transport hard03.08.07Media Use hard03.08.09System Backup - Cryptographic Protection moderate03.09 PS (Personnel Security)
03.10 PE (Physical Protection)
03.10.01Physical Access Authorizations easy03.10.02Monitoring Physical Access moderate03.10.06Alternate Work Site hard03.10.07Physical Access Control moderate03.10.08Access Control for Transmission hard03.11 RA (Risk Assessment)
03.11.01Risk Assessment hard03.11.02Vulnerability Monitoring and Scanning easy03.11.04Risk Response hard03.12 CA (Security Assessment and Monitoring)
03.12.01Security Assessment hard03.12.02Plan of Action and Milestones hard03.12.03Continuous Monitoring easy03.12.05Information Exchange hard03.13 SC (System and Communications Protection)
03.13.01Boundary Protection moderate03.13.04Information in Shared System Resources moderate03.13.06Network Communications - Deny by Default - Allow by Exception hard03.13.08Transmission Confidentiality and Integrity moderate03.13.09Network Disconnect easy03.13.10Cryptographic Key Establishment and Management moderate03.13.11Cryptographic Protection hard03.13.12Collaborative Computing Devices and Applications moderate03.13.13Mobile Code hard03.13.15Session Authenticity moderate03.14 SI (System and Information Integrity)
03.14.01Flaw Remediation hard03.14.02Malicious Code Protection moderate03.14.03Security Alerts, Advisories, and Directives easy03.14.06System Monitoring easy03.14.08Information Management and Retention hard03.15 PL (Planning)
03.16 SA (System and Services Acquisition)
03.16.01Security Engineering Principles hard03.16.02Unsupported System Components hard03.16.03External System Services moderate