Appendices D to F: Penetration Testing, Reporting and Ongoing Assessment
NIST SP 800-53A Rev. 5 53A-E: Assessment Reports
Sets what the assessment report must carry so that the reader can judge both the findings and the basis on which they were reached.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 10 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties