Frameworks / NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) / 2 NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Review Techniques
NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) 2: Review Techniques - Documentation, Logs, Rulesets, Configurations Apply Section 3 review techniques: documentation review (security policies + procedures + plans + system documentation + diagrams) + log review (security event logs + system logs + audit logs + change management logs) + ruleset review (firewall rules + IDS rules + ACLs) + system configuration review (hardening compliance + secure baselines + configuration files) + network sniffing (when authorised + observing traffic patterns + protocol use) + file integrity checking (HIDS + checksums + signatures).
What else in your programme already covers this This control maps to 42 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.