NIST SP 800-53 Rev 5
9 of the 300 clauses of NIST SP 800-53 Rev 5 are cited by this register, on Asset inventory sync, Backup restore test, Card environment log review, Configuration baseline and drift check, Credential and password rotation, Database snapshot, Dormant account disable, Full backup and more. Every one below is quoted from the copy we hold, with the hours it states where it states any.
Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.
What an assessor asks to see: Account type register showing which account types are permitted and which are prohibited; Provisioning and deprovisioning tickets carrying documented approval by the responsible party; Leaver reconciliation between the human resources record and account disablement dates; Periodic account recertification results with evidence that revocations were executed. Where it usually falls short: Shared and service accounts sit outside the joiner mover leaver process entirely
Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.
What an assessor asks to see: Defined review frequency and the activity indicators being looked for; Completed review records with reviewer, date and findings; Reports issued to the defined recipients and evidence of follow-up; Record of a review level adjustment made in response to changed risk. Where it usually falls short: Review is automated alerting only, with no periodic analytical review for slow patterns
Requires a system-level continuous monitoring strategy aligned to the organizational one, defining the metrics monitored, the frequencies for monitoring and for assessing control effectiveness, ongoing control assessment, correlation and analysis of the results, response actions, and reporting of security and privacy posture to defined personnel.
What an assessor asks to see: Documented continuous monitoring strategy with metrics and frequencies; Evidence of ongoing control assessments performed at the stated cadence; Correlation and analysis output showing findings drawn from monitoring data; Posture reports issued to the defined personnel and the actions they triggered. Where it usually falls short: Monitoring reduced to vulnerability scanning, with most controls never reassessed
Requires the contingency plan to be tested at a defined frequency using defined test types to establish that the plan works and that people are ready to execute it, the test results to be reviewed, and corrective action to be initiated where the test shows it is needed.
What an assessor asks to see: Test plan and scenario documentation for each exercise; Test report with results, observations and participants; Defined test types and frequency, and evidence they were met; Corrective actions raised, tracked and closed following the test. Where it usually falls short: Tabletop exercise substituted for the technical failover test the plan requires
Requires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.
What an assessor asks to see: Backup schedule and success reports covering user-level, system-level and documentation backups; Encryption and access control configuration protecting backup data; Restore test records proving backups are usable; Defined backup frequencies and evidence they are met. Where it usually falls short: Documentation and configuration backed up nowhere, only application data
Requires the incident response capability serving the system to be tested for effectiveness at an organization-defined frequency using the test types the organization has defined, so readiness is demonstrated rather than assumed.
What an assessor asks to see: Defined test types and frequency for incident response testing; Exercise scenario documents and participant lists; Test reports with observations and identified weaknesses; Corrective actions tracked to closure after each test. Where it usually falls short: Only tabletop exercises run, so technical containment steps are never proven
Requires personnel to report suspected incidents to the incident response capability within an organization-defined period, and requires incident information to be reported to the authorities the organization has identified.
What an assessor asks to see: Defined internal reporting timeframe and the channels available to staff; Evidence staff know how and when to report, such as awareness material; List of authorities to be notified and the applicable timeframes; Records of actual notifications made and their timing. Where it usually falls short: Reporting timeframe undefined, so escalation depends on individual judgement
Requires vulnerability monitoring and scanning of the system and hosted applications at a defined frequency or randomly by a defined process and when new relevant vulnerabilities are reported, using tools and techniques that support standardised enumeration, checklists and impact measurement, with results analysed, remediation within defined response times by risk, results shared with defined personnel, and privileged scanning access where required.
What an assessor asks to see: Scan schedule and coverage evidence across the system and hosted applications; Scan reports with findings ranked by severity; Defined remediation timeframes by risk level and evidence they are met; Records of scan result distribution to the defined personnel. Where it usually falls short: Unauthenticated scanning only, which understates the real vulnerability position
Requires system flaws to be identified, reported and corrected, updates related to flaw remediation to be tested for effectiveness and side effects before installation, security relevant software and firmware updates to be installed within an organization-defined period of release, and flaw remediation to be run through the configuration management process.
What an assessor asks to see: Defined installation timeframes for security relevant updates by severity; Patch deployment records measured against those timeframes; Test evidence for updates before production installation; Change records showing remediation passed through configuration management. Where it usually falls short: Timeframes defined but routinely missed with no risk acceptance recorded
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. The whole standard on compliance.theartofservice.com.