NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Review Techniques

NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) 2: Review Techniques - Documentation, Logs, Rulesets, Configurations

Apply Section 3 review techniques: documentation review (security policies + procedures + plans + system documentation + diagrams) + log review (security event logs + system logs + audit logs + change management logs) + ruleset review (firewall rules + IDS rules + ACLs) + system configuration review (hardening compliance + secure baselines + configuration files) + network sniffing (when authorised + observing traffic patterns + protocol use) + file integrity checking (HIDS + checksums + signatures).

What else in your programme already covers this

This control maps to 42 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

ISO 13485 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO 27799 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/SAE 21434 · 1 control

  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-171 · 1 control

  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

South Korea ISMS-P · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.