Security Questionnaire Mapper
Clause text

NIST SP 800-53 Rev 5: the clauses the register cites

The 10 NIST SP 800-53 Rev 5 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.

The requirement lines are our statement of each clause, read against the copy we hold and cited to it.

10 clauses

the families they anchor
SP 800-53 AC-2 Account management

Requires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.

Evidence an assessor expects: Account type register showing which account types are permitted and which are prohibited; Provisioning and deprovisioning tickets carrying documented approval by the responsible party; Leaver reconciliation between the human resources record and account disablement dates; Periodic account recertification results with evidence that revocations were executed; Monitoring output for atypical account usage and for dormant accounts
Where answers usually fall short: Shared and service accounts sit outside the joiner mover leaver process entirely; Recertification is signed off in bulk without any account actually being removed
Source: NIST SP 800-53 Rev 5
SP 800-53 AU-6 Audit record review, analysis, and reporting

Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.

Evidence an assessor expects: Defined review frequency and the activity indicators being looked for; Completed review records with reviewer, date and findings; Reports issued to the defined recipients and evidence of follow-up; Record of a review level adjustment made in response to changed risk
Where answers usually fall short: Review is automated alerting only, with no periodic analytical review for slow patterns; Findings recorded but never reported to anyone able to act
Source: NIST SP 800-53 Rev 5
SP 800-53 CP-2 Contingency plan

Requires a contingency plan that identifies essential mission and business functions and their contingency requirements, sets recovery objectives, priorities and metrics, assigns roles and contacts, addresses operating through disruption and full restoration without weakening controls, is approved by defined personnel, distributed to defined recipients, coordinated with related plans, reviewed on a defined frequency and updated after change or testing.

Evidence an assessor expects: Approved contingency plan with recovery objectives, priorities and metrics; Business impact analysis identifying essential functions and dependencies; Distribution list and evidence the plan reached the defined recipients; Review and update history including changes after tests or incidents; Evidence of coordination with incident response and related organizational plans
Where answers usually fall short: Plan lists systems but never identifies the business functions they support; Contact details stale, naming people who left the organization
Source: NIST SP 800-53 Rev 5
SP 800-53 CP-9 System backup

Requires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.

Evidence an assessor expects: Backup schedule and success reports covering user-level, system-level and documentation backups; Encryption and access control configuration protecting backup data; Restore test records proving backups are usable; Defined backup frequencies and evidence they are met
Where answers usually fall short: Documentation and configuration backed up nowhere, only application data; Backups unencrypted or reachable with the same credentials as production, so ransomware takes both
Source: NIST SP 800-53 Rev 5
SP 800-53 IA-2 Identification and authentication of organizational users

Requires organizational users to be uniquely identified and authenticated, and requires that unique identity to be carried through to the processes that act on their behalf, so that system activity is attributable to a specific person.

Evidence an assessor expects: Directory or identity store showing unique accounts per organizational user; Authentication configuration including multi-factor where required; Evidence that process and session activity carries the initiating user identity; Register of any shared accounts with justification and compensating attribution
Where answers usually fall short: Shared administrative accounts destroy attribution at exactly the highest privilege; Automation runs under a generic identity that hides who initiated the action
Source: NIST SP 800-53 Rev 5
SP 800-53 IR-8 Incident response plan

Requires an incident response plan that sets the roadmap and structure for the capability, fits it to the organization, defines reportable incidents and success metrics, defines the resources and management support needed, is approved by defined personnel, distributed to defined recipients, reviewed on a defined frequency, updated for change and lessons learned, and protected from unauthorized disclosure and modification.

Evidence an assessor expects: Approved incident response plan with roles, structure and reportable incident definitions; Distribution record to the defined recipients; Review and update history including changes after incidents or exercises; Access controls protecting the plan from unauthorized disclosure or change; Defined metrics for measuring incident response capability
Where answers usually fall short: Plan defines severity levels but never defines what counts as a reportable incident; Plan stored only on the system it is meant to help recover
Source: NIST SP 800-53 Rev 5
SP 800-53 PS-3 Personnel screening

Requires individuals to be screened before access to the system is authorized, and to be rescreened where organization-defined conditions require it and at the frequency defined for those conditions.

Evidence an assessor expects: Screening records showing completion before access authorization; Documented rescreening conditions and their frequencies; Rescreening completion records for the populations covered; Evidence of the treatment applied where screening cannot be completed
Where answers usually fall short: Access granted on the start date while screening is still in progress; Rescreening conditions never defined, so screening happens once in a career
Source: NIST SP 800-53 Rev 5
SP 800-53 RA-5 Vulnerability monitoring and scanning

Requires vulnerability monitoring and scanning of the system and hosted applications at a defined frequency or randomly by a defined process and when new relevant vulnerabilities are reported, using tools and techniques that support standardised enumeration, checklists and impact measurement, with results analysed, remediation within defined response times by risk, results shared with defined personnel, and privileged scanning access where required.

Evidence an assessor expects: Scan schedule and coverage evidence across the system and hosted applications; Scan reports with findings ranked by severity; Defined remediation timeframes by risk level and evidence they are met; Records of scan result distribution to the defined personnel; Configuration showing authenticated or privileged scanning where required
Where answers usually fall short: Unauthenticated scanning only, which understates the real vulnerability position; Remediation timeframes defined but routinely exceeded with no risk acceptance
Source: NIST SP 800-53 Rev 5
SP 800-53 SC-28 Protection of information at rest

Requires the confidentiality or integrity, as the organization determines, of organization-defined information at rest to be protected, so that stored information is safeguarded independently of the access controls in front of it.

Evidence an assessor expects: Definition of the information at rest in scope and whether confidentiality, integrity or both are protected; Encryption configuration for storage, databases and backups; Key management arrangements supporting the protection; Verification evidence such as storage configuration reports
Where answers usually fall short: Primary storage encrypted while backups, exports and logs are not; Encryption keys held beside the data they protect
Source: NIST SP 800-53 Rev 5
SP 800-53 SR-6 Supplier assessments and reviews

Requires assessment and review, at an organization-defined frequency, of the supply chain risk attached to each supplier or contractor and to the particular system, component or service they deliver.

Evidence an assessor expects: Supplier assessment records covering the supply chain risks of what is provided; Defined assessment frequency and evidence reviews occur at that cadence; Risk ratings and the treatment decisions arising from assessments; Evidence assessments cover subcontractors and fourth party dependencies where relevant
Where answers usually fall short: Assessment performed at onboarding only with no defined review cadence; Assessment covers the supplier's corporate posture but not the specific component supplied
Source: NIST SP 800-53 Rev 5