NIST SP 800-66 Rev 2
Administrative

NIST SP 800-66 Rev 2 164.308(a)(8): Evaluation (Standard)

Perform periodic technical and nontechnical evaluation. NIST recommends combining policy review, control testing, vulnerability assessments, and audits to evaluate ongoing compliance.

What else in your programme already covers this

This control maps to 169 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 27 controls

  • 1.2.7 NSC rule sets reviewed every six months
  • 10.4.2.1 Frequency defined by TRA
  • 10.7.2 Critical security control failure detection (all entities)
  • 10.7.3 Failure response timeline
  • 11.3.1 Internal vulnerability scans quarterly
  • 11.3.1.3 Internal scans after significant changes
  • 11.3.2 External vulnerability scans quarterly by ASV
  • 11.4.1 Penetration testing methodology defined
  • 11.4.2 Internal penetration testing annually
  • 11.4.3 External penetration testing annually
  • 11.4.4 Pen test findings remediated
  • 11.4.5 Segmentation testing
  • 11.4.6 Segmentation testing (service providers) every 6 months
  • 12.10.2 IRP reviewed and tested annually
  • 12.3.2 TRA for customized approach
  • 12.4.2 Quarterly PCI compliance reviews (SP)
  • 12.4.2.1 Documentation of quarterly reviews (SP)
  • 12.5.2 PCI DSS scope documented and confirmed annually
  • 12.5.2.1 Service provider scope confirmed every 6 months
  • 12.5.3 Impact analysis on org structure changes (SP)
  • 12.6.1 Formal security awareness program implemented
  • 12.8.4 TPSP compliance monitored
  • 5.2.3.1 Frequency of periodic evaluations per targeted risk analysis
  • 5.2.3 Any system components that are not at risk for malware are evaluated periodically to include the following: • A documented list of all system components not at risk for malware. • Identification and evaluation
  • 6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
  • 6.5.2 Upon completion of a significant change, all applicable PCI DSS requirements are confirmed to be in place on all new or changed systems and networks, and documentation is updated as applicable
  • 7.2.4 All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.

CIS Controls v8 · 10 controls

  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

NIST SP 800-53 Rev 5 · 9 controls

  • NIST800-AU-6 Audit record review, analysis, and reporting
  • NIST800-CA-2 Control assessments
  • NIST800-CA-7 Continuous monitoring
  • NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
  • NIST800-PM-4 Plan of Action and Milestones Process. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems: Are developed
  • NIST800-RA-5 Vulnerability monitoring and scanning
  • NIST800-SI-18 Personally Identifiable Information Quality Operations. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [organization-defined] ; and Correct or delete inaccurate or outdated personally identifiable information
  • NIST800-SI-19 De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectiveness of de-identification
  • SP800-53-CM Configuration Management Family
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

ISO 27001:2022 · 6 controls

  • 5.27 Learning from information security incidents
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.29 Security testing in development and acceptance
  • 8.30 Outsourced development
  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 6 controls

  • 5.4 Planning
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.7.2 Internal audit
  • 6.15 Compliance
  • 6.15.2 Information security reviews
  • 8.4 Privacy by design and privacy by default

APRA CPS 234 · 5 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P31 Annual Review of Testing Program Sufficiency

C5 (Germany) · 5 controls

  • C5-COM-02 Policy for planning and conducting audits
  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

FedRAMP High · 5 controls

  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • RA-5 Vulnerability Monitoring and Scanning

FedRAMP Moderate · 5 controls

  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • RA-5 Vulnerability Monitoring and Scanning
  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • RA-5 Vulnerability Monitoring and Scanning
  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • RA-5 Vulnerability Monitoring and Scanning
  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-18 Triennial Comprehensive Review of the Framework
  • CPS220-P47 Minimum Assessment Required by the Framework Review
  • CPS220-P48 Assessment Following Material Change Outside the Review Cycle
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-66 Review of Operational Risk Management
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • SEC01-BP03 Identify and validate control objectives
  • SEC01-BP08 Evaluate and implement new security services and features regularly
  • SEC06-BP01 Perform vulnerability management
  • SEC11-BP03 Perform regular penetration testing
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-PV-7 Conduct regular red team operations
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

ISO 22301:2019 · 4 controls

  • 8.6 Evaluation of business continuity documentation and capabilities
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.3 Management review

ISO 27002:2022 · 4 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.8 Management of technical vulnerabilities

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-7 Continuous Monitoring
  • RA-5 Vulnerability Monitoring and Scanning

SOC 2 · 4 controls

  • SOC2-CC3.4 COSO principle 9: Identifies and assesses changes that could impact internal controls
  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

CMMC 2.0 · 3 controls

NIST SP 800-172 · 3 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.12.1e Penetration Testing by Independent Agents
  • 3.14.7e Verify Correctness of Security Functions
  • 53A-3.1 Prepare for Control Assessments
  • 53A-3.3 Conduct Control Assessments
  • 53A-E Assessment Reports
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CBPR-PR-33 Testing the effectiveness of safeguards
  • AEO-13 Measurement, Analyses and Improvement

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

Query this from an agent

The graph holds this control, the 169 it maps to, and the evidence behind each claim, over MCP and REST.