Frameworks / NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) / NISTSP115-8 NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Operations Support
NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) NISTSP115-8: Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material Apply Appendix A operational considerations including: assessment tool ecosystem (Kali Linux + Metasploit + Nmap + Wireshark + Burp Suite + OWASP ZAP + custom scripts) + tool validation and configuration management + report templates and content standards + integration with information security management system (ISMS) per ISO/IEC 27001 + integration with broader security assessment per NIST SP 800-53A + supporting controls covering governance + access management + crypto + operations + network + transfer + cross-walk with SP 800-171 3.14.7 for vulnerability scanning. Maintain testing programme + scheduling + tracking + reporting cadence + executive visibility.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 347 controls across 86 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-06 Asset inventory and ownership ISO27043-08 Information classification and labeling ISO27043-10 Media management and disposal ISO27043-11 Access control policy and enforcement ISO27043-12 User access management and provisioning ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO27043-22 Protection from malware ISO27043-23 Backup and recovery procedures ISO27043-27 Network security management ISO21434-07 Acceptable use of assets ISO21434-08 Information classification and labeling ISO21434-09 Asset handling procedures ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISO21434-22 Protection from malware ISO21434-23 Backup and recovery procedures ISO21434-27 Network security management ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-17 TLS encryption between email servers (Limited) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-23 Protect authentication credentials (Excellent) ASD37-25 Software firewall - inbound (Very Good) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) API1164-02 Risk Management Framework API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-12 Incident Response API1164-13 Business Continuity and Recovery API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.3 Account Management AWWA-2.4 Physical Access Controls AWWA-3.1 Network Segmentation AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AWWA-4.1 Malware Protection IEC62443-02 System security categorization IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures IEC62443-12 Malware prevention for operational systems IEC62443-13 Network security monitoring IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents ISO27019-02 System security categorization ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27019-12 Malware prevention for operational systems ISO27019-13 Network security monitoring ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents BSI-01 Account management and provisioning BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data BSI-15 Security categorization 27010-10.1 Cryptographic Protection 27010-12.2 Protection from malware 27010-13.1 Communications Security 27010-8.1 Membership Onboarding 27010-8.2 Membership Termination 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.2 Network security and segregation 27011-8.3 Cryptography and key management 27011-8.5 Vulnerability and malware management 27011-8.6 Data protection and backup ISMSP-AC-01 Access Control Policy ISMSP-AC-02 User Account Management ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-06 Business Continuity and Disaster Recovery ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-16 Transmission security and encryption ISO27799-17 Facility access controls NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied IM8-CLD.2 Cloud Security Controls IM8-DAT.1 Data Classification IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing IM8-SEC.2 Access Control IM8-SEC.3 Network Security OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components OWASPTOP10-7 A07:2025 Identification and Authentication Failures FEDRAMP-CP-9 System Backup FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) OWASPAPI-6 Security Misconfiguration and Secure API Design OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria CFR211-G-125 Section 211.125 - Labeling Issuance CFR211-G-130 Section 211.130 - Packaging and Labeling Operations DIQ-1 Data Integration and Interoperability DSO-2 Data Security DSO-3 Data Access Management CJIS-10 System and Information Integrity CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics FFIEC-06 Network security and segmentation FFIEC-09 Encryption and key management FFIEC-12 Disaster recovery procedures 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NISTSP34-4 Information System Contingency Plan (ISCP) Development DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A34 Request for Correction, Addition or Deletion UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management ISO-19650-1-5 Delivery team and task team concepts ISO-19650-2-5.7 Information model delivery ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NFPA1600-5.3 Resource Needs Assessment NFPA1600-6.4 Continuity and Recovery NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NZISM-5 Network Security, System Hardening, and Application Security PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security D.3 Backup and Recovery UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP) CPSC-CS.1 Network Security for Connected Products CPSC-CS.2 Authentication and Access Controls CYB-2 Account Security Measures CYB-5 Cyber Incident Response Plan AMLCTF-35 Identity Verification Standard 4.4.8 Business Continuity and Recovery CA-ITSG33-SC-01 Security Control Catalogue QMSR-820.45 Device labelling and packaging controls (§820.45) FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 60601-1.7.1 Equipment identification and marking ISO-14064-1-5.4 Categorization of indirect GHG emissions ISO-22320-5.2 Incident management process ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ITIL4-15 Access management for services STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NGOB-3 API Security Standards, mTLS, and Encryption AUPRV-4 APP 10-11 Quality, Security of Personal Information EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights ACE-CR-4 Cargo Release Authorization USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 347 it maps to, and the evidence behind each claim, over MCP and REST.