NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Operations Support

NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) NISTSP115-8: Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

Apply Appendix A operational considerations including: assessment tool ecosystem (Kali Linux + Metasploit + Nmap + Wireshark + Burp Suite + OWASP ZAP + custom scripts) + tool validation and configuration management + report templates and content standards + integration with information security management system (ISMS) per ISO/IEC 27001 + integration with broader security assessment per NIST SP 800-53A + supporting controls covering governance + access management + crypto + operations + network + transfer + cross-walk with SP 800-171 3.14.7 for vulnerability scanning. Maintain testing programme + scheduling + tracking + reporting cadence + executive visibility.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 347 controls across 86 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 15 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal
  • ISO27043-11 Access control policy and enforcement
  • ISO27043-12 User access management and provisioning
  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-22 Protection from malware
  • ISO27043-23 Backup and recovery procedures
  • ISO27043-27 Network security management

ISO/SAE 21434 · 14 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • ISO21434-12 User access management and provisioning
  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-22 Protection from malware
  • ISO21434-23 Backup and recovery procedures
  • ISO21434-27 Network security management
  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

API 1164 · 9 controls

  • API1164-02 Risk Management Framework
  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • API1164-12 Incident Response
  • API1164-13 Business Continuity and Recovery
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.3 Account Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.1 Network Segmentation
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.1 Malware Protection

IEC 62443 · 9 controls

  • IEC62443-02 System security categorization
  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures
  • IEC62443-12 Malware prevention for operational systems
  • IEC62443-13 Network security monitoring
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 9 controls

  • ISO27019-02 System security categorization
  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures
  • ISO27019-12 Malware prevention for operational systems
  • ISO27019-13 Network security monitoring
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

BSI IT-Grundschutz · 7 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-15 Security categorization

ISO/IEC 27010:2015 · 7 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-12.2 Protection from malware
  • 27010-13.1 Communications Security
  • 27010-8.1 Membership Onboarding
  • 27010-8.2 Membership Termination
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 7 controls

  • 27011-5.3 Segregation of duties
  • 27011-6.3 Awareness and Training
  • 27011-8.1 User Endpoint Devices
  • 27011-8.2 Network security and segregation
  • 27011-8.3 Cryptography and key management
  • 27011-8.5 Vulnerability and malware management
  • 27011-8.6 Data protection and backup

South Korea ISMS-P · 7 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-02 User Account Management
  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-AC-04 Network Access Control
  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery

ISO 27799:2025 · 6 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-08 Information access management
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-16 Transmission security and encryption
  • ISO27799-17 Facility access controls
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

OWASP ASVS · 6 controls

OWASP MASVS · 6 controls

  • IM8-CLD.2 Cloud Security Controls
  • IM8-DAT.1 Data Classification
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.2 Access Control
  • IM8-SEC.3 Network Security

OWASP Top 10:2025 · 5 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures

FedRAMP Rev 5 · 4 controls

  • FEDRAMP-CP-9 System Backup
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 23837:2023 · 4 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements
  • 23837-1.7.3 Authentication and classical post-processing
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)
  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations
  • DIQ-1 Data Integration and Interoperability
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CJIS-10 System and Information Integrity
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-IRP-4 Organizational characteristics
  • FFIEC-06 Network security and segmentation
  • FFIEC-09 Encryption and key management
  • FFIEC-12 Disaster recovery procedures

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

APPI · 2 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 2 controls

  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management
  • ISO-19650-1-5 Delivery team and task team concepts
  • ISO-19650-2-5.7 Information model delivery

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/IEC 27400:2022 · 2 controls

  • 27400-6.1 Secure Device Design
  • 27400-6.2 Device Identity and Authentication

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • D.3 Backup and Recovery
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPSC-CS.1 Network Security for Connected Products
  • CPSC-CS.2 Authentication and Access Controls
  • CYB-2 Account Security Measures
  • CYB-5 Cyber Incident Response Plan
  • AMLCTF-35 Identity Verification Standard
  • 4.4.8 Business Continuity and Recovery
  • CA-ITSG33-SC-01 Security Control Catalogue
  • QMSR-820.45 Device labelling and packaging controls (§820.45)

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 60601-1.7.1 Equipment identification and marking
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • ACE-CR-4 Cargo Release Authorization
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 347 it maps to, and the evidence behind each claim, over MCP and REST.