Frameworks / NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) / NISTSP115-2 NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Review Techniques
NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) NISTSP115-2: Review Techniques - Documentation, Logs, Rulesets, Configurations Apply Section 3 review techniques: documentation review (security policies + procedures + plans + system documentation + diagrams) + log review (security event logs + system logs + audit logs + change management logs) + ruleset review (firewall rules + IDS rules + ACLs) + system configuration review (hardening compliance + secure baselines + configuration files) + network sniffing (when authorised + observing traffic patterns + protocol use) + file integrity checking (HIDS + checksums + signatures).
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 37 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention AWWA-4.4 Audit Logging and Monitoring CAT-D3-2 Detective controls FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) 62351-14 Cyber security event logging ISO27799-05 Audit trail for ePHI access ISO-25012-4.11 Traceability 27011-8.4 Logging and monitoring ISO27043-24 Logging and monitoring ISO21434-24 Logging and monitoring NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures ISMSP-SYS-03 Security Monitoring and Log Management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.