Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(8) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(8): Evaluation (Standard) Perform periodic technical and nontechnical evaluation. NIST recommends combining policy review, control testing, vulnerability assessments, and audits to evaluate ongoing compliance.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 155 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.7 1.2.7 Six-monthly review of NSC configurations 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis 10.7.2 10.7.2 Detect and alert on critical security control failures 10.7.3 10.7.3 Respond promptly to critical security control failures 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.4.1 11.4.1 Penetration testing methodology defined and implemented 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.3 11.4.3 External penetration testing annually and after change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 11.4.5 11.4.5 Annual segmentation penetration testing 11.4.6 11.4.6 Service provider segmentation testing every six months 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews 12.5.2 12.5.2 Annual and change-driven scope confirmation 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers 12.5.3 12.5.3 Scope review after significant organisational change 12.6.1 12.6.1 Formal security awareness program 12.8.4 12.8.4 Annual monitoring of TPSP compliance status 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.5.2 6.5.2 Confirm PCI DSS controls after significant change 7.2.4 7.2.4 User accounts and privileges reviewed every six months CIS-1.5 Use a Passive Asset Discovery Tool CIS-17.8 Conduct Post-Incident Reviews CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.2 Perform Periodic External Penetration Tests CIS-18.4 Validate Security Measures CIS-18.5 Perform Periodic Internal Penetration Tests CIS-2.2 Ensure Authorized Software is Currently Supported CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established 5.27 Learning from information security incidents 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.29 Security testing in development and acceptance 8.30 Outsourced development 8.8 Management of technical vulnerabilities 5.4 Planning 5.7.1 Monitoring, measurement, analysis and evaluation 5.7.2 Internal audit 6.15 Compliance 6.15.2 Information security reviews 8.4 Privacy by design and privacy by default CPS234-22 Systematic Control Testing Program CPS234-25 Internal Audit Review of Information Security Controls CPS234-P17 Active Maintenance of Capability Against Change CPS234-P30 Independence and Skill of Testing Personnel CPS234-P31 Annual Review of Testing Program Sufficiency C5-COM-02 Policy for planning and conducting audits C5-COM-03 Internal audits of the information security management system C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures CA-1 Policy and Procedures CA-2 Control Assessments CA-2(1) Independent Assessors CA-7 Continuous Monitoring RA-5 Vulnerability Monitoring and Scanning CA-1 Policy and Procedures CA-2 Control Assessments CA-2(1) Independent Assessors CA-7 Continuous Monitoring RA-5 Vulnerability Monitoring and Scanning CPS220-11 Annual Audit Review of the Framework CPS220-18 Triennial Comprehensive Review of the Framework CPS220-P47 Minimum Assessment Required by the Framework Review CPS220-P48 Assessment Following Material Change Outside the Review Cycle CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing CPS230-66 Review of Operational Risk Management CPS230-P30 Monitoring, Review and Testing of Control Effectiveness SEC01-BP03 Identify and validate control objectives SEC01-BP08 Evaluate and implement new security services and features regularly SEC06-BP01 Perform vulnerability management SEC11-BP03 Perform regular penetration testing ASBv3-GS-5 Define and implement security posture management strategy ASBv3-PV-7 Conduct regular red team operations PV-2 Audit and enforce secure configurations PV-5 Perform vulnerability assessments 8.6 Evaluation of business continuity documentation and capabilities 9.1 Monitoring, measurement, analysis and evaluation 9.2 Internal audit 9.3 Management review 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 8.8 Management of technical vulnerabilities SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities AUCDR-IS-4 Formal vulnerability management program AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program 3.11.5e Assess Effectiveness of Security Solutions 3.12.1e Penetration Testing by Independent Agents 3.14.7e Verify Correctness of Security Functions 53A-3.1 Prepare for Control Assessments 53A-3.3 Conduct Control Assessments 53A-E Assessment Reports E8-PATCHAPP-ML1 Patch Applications (ML1) ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions CBPR-PR-33 Testing the effectiveness of safeguards AEO-13 Measurement, Analyses and Improvement Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 155 it maps to, and the evidence behind each claim, over MCP and REST.