Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST 800-53A explained

NIST 800-53A: The Clear Guide to Assessment Procedures

NIST 800-53A — SP 800-53A Revision 5, Assessing Security and Privacy Controls in Information Systems and Organizations, published in January 2022 — is the publication an assessor works from, and therefore the best guide to what evidence a control owner will be asked for. For every control and enhancement in SP 800-53 Rev 5 it provides an assessment procedure: a set of assessment objectives broken into numbered determination statements, each with potential assessment methods — examine, interview, test — and the assessment objects those methods are applied to.

Findings are recorded as satisfied or other than satisfied, per determination statement, and the depth and coverage of each method are set at basic, focused or comprehensive. This guide explains the anatomy of a procedure, the three methods and four object types, how depth and coverage are chosen, the five-step assessment process, what goes in the assessment report, and how a control owner uses 800-53A to prepare evidence before the assessor arrives.

NIST 800-53A: the anatomy of an assessment procedure
Control (800-53) → assessment objective → determination statements (AC-17a.[01], AC-17b.) → methods: examine / interview / test → objects: specifications, mechanisms, activities, individuals → depth and coverage: basic / focused / comprehensive → finding: satisfied / other than satisfied.

What NIST 800-53A is for

SP 800-53 states controls; SP 800-53B selects them; SP 800-53A tests them. The assessment procedures are what a FedRAMP 3PAO, an agency assessor, a StateRAMP assessor or an internal assessment team applies to produce the security and privacy assessment reports that go into the authorisation package with the system security plan, privacy plan and plan of action and milestones. Rev 5 of 800-53A was aligned to the Rev 5 catalogue, decomposed the objectives into more granular determination statements, and separated the determination statements for organization-defined parameters from those for the control items — so that an unassigned parameter now fails on its own line. Our guide to NIST SP 800-53 covers the publication set.

The anatomy of an assessment procedure

Element What it is Example (AC-17 Remote Access)
Assessment objective What the assessor is trying to determine for the control, derived from the control statement Determine if the remote access control is implemented as stated
Determination statements The objective decomposed into granular, individually answerable items; further granularised where the control text bundles several requirements AC-17a.[01] usage restrictions are established and documented for each type of remote access; AC-17a.[02] configuration/connection requirements; AC-17a.[03] implementation guidance; AC-17b. each type of remote access is authorized prior to allowing such connections
Potential assessment methods Examine, interview and test — not every procedure uses all three AC-17-Examine, AC-17-Interview, AC-17-Test
Assessment objects What each method is applied to: specifications, mechanisms, activities, individuals Examine: access control policy, remote access procedures, configuration settings, authorisations, audit records, SSP; Interview: personnel managing remote access, administrators; Test: the remote access management capability
Finding Satisfied or other than satisfied, per determination statement AC-17a.[02] other than satisfied: no connection requirements documented for vendor VPN

The granularity is the point. A control owner who can answer each determination statement with a named artefact, a named person and a demonstrable mechanism has already done the assessor’s work; one who can only say “we have a remote access policy” will fail the statements the policy does not reach.

The three methods and four object types

Method 800-53A definition Applied to What it produces
Examine Reviewing, inspecting, observing, studying or analysing assessment objects to facilitate understanding, achieve clarification or obtain evidence Specifications, mechanisms, activities Document and configuration evidence
Interview Holding discussions with individuals or groups to facilitate understanding, achieve clarification or obtain evidence Individuals Corroboration that people know and do what the documents say
Test Exercising assessment objects under specified conditions to compare actual state to desired state or expected behaviour Activities, mechanisms Proof the control operates
Object type Definition Examples
Specifications Document-based artefacts associated with a system or common control Policies, procedures, plans, requirements, functional specifications, architectural designs
Mechanisms Hardware, software or firmware safeguards employed within a system, including physical protection devices Access control lists, encryption modules, locks, cameras, fire protection
Activities Protection-related actions involving people Running backups, monitoring network traffic, exercising a contingency plan
Individuals People applying the specifications, mechanisms or activities Administrators, security officers, users

Depth and coverage

Each method carries two attributes. Depth is the rigour and level of detail of the examination, interview or test; coverage is its scope and breadth — how many and which objects. Both take the values basic, focused and comprehensive, and Appendix C of 800-53A describes what each value means per method.

The organisation chooses the values in the assessment plan according to the assurance it needs: a low-impact system may be examined at basic depth on a sample of objects; a high-impact system or a FedRAMP High authorisation expects comprehensive depth and coverage on the controls that matter. Depth and coverage are also where reuse of prior assessment evidence is decided — an earlier comprehensive test can support a later focused one if the object has not changed.

The NIST 800-53A assessment process

Step (800-53A Chapter 3) Purpose Output
3.1 Prepare Establish objectives, scope and the assessor’s independence; assemble the SSP, prior results and the control set as tailored Assessment scope and schedule
3.2 Develop the assessment plans Select procedures for every in-scope control, tailor methods and objects, set depth and coverage, handle common and hybrid controls, decide reuse of evidence Security and privacy assessment plans, approved by the organisation
3.3 Conduct the assessments Apply the methods to the objects; record findings per determination statement Assessment findings
3.4 Analyse the report results Findings of other than satisfied are analysed for risk; the organisation decides to accept, reject or mitigate; updates the SSP and POA&M Security and privacy assessment reports; POA&M entries
3.5 Assess capabilities Optionally assess groups of controls as a security or privacy capability rather than one by one Capability-level findings

The assessment report — Appendix E gives its recommended content — carries, for each other-than-satisfied finding, which parts of the control are affected, how the actual state differs from the planned state, and the potential for compromise to confidentiality, integrity, availability or privacy. Organisations may add severity subcategories to prioritise remediation. Our guide to NIST 800-53 tailoring covers the tailored control set the plan is built against.

Using NIST 800-53A before the assessor arrives

  1. Build the evidence matrix from the determination statements, not from the controls. One row per determination statement, with the specification, mechanism, activity and individual that answer it. A control with six statements needs six answers.
  2. Assign every organization-defined parameter first. Rev 5 of 800-53A tests parameters on separate determination statements; an unassigned frequency or list fails before the control is examined.
  3. Prepare for all three methods. A document proves the specification exists; the interview proves people follow it; the test proves the mechanism works. Assessors triangulate, and a policy nobody can describe in interview is a finding.
  4. Run the procedures internally at the depth the plan will use. An internal assessment at focused depth that produces zero findings means the internal assessment was too shallow, not that the system is clean.
  5. Record the 800-53 release. Release 5.2.0 of the catalogue added SA-15(13), SA-24 and SI-02(07); 800-53A procedures for new controls follow, and an assessment against the wrong release is a scoping error before it is a finding.
  6. Mark inapplicable determination statements with a reason. 800-53A allows an assessor to disregard a non-applicable requirement — a privacy statement on a system with no PII — and still find the control satisfied, but only if the inapplicability is recorded.

Our guide to the NIST 800-53 control families is the checklist for making sure the matrix covers every family.

Frequently asked questions

What is NIST 800-53A?
SP 800-53A Revision 5 (January 2022), the companion to SP 800-53 that provides an assessment procedure for every control and enhancement: assessment objectives decomposed into determination statements, with examine, interview and test methods applied to specifications, mechanisms, activities and individuals, producing findings of satisfied or other than satisfied.

What are the three assessment methods?
Examine (review, inspect, observe, study or analyse objects), interview (discuss with individuals or groups) and test (exercise mechanisms or activities under specified conditions and compare actual to expected state). Not every procedure uses all three.

What do depth and coverage mean?
Depth is the rigour and level of detail of a method; coverage is its scope and breadth across assessment objects. Both are set to basic, focused or comprehensive in the assessment plan, according to the assurance required.

What is a determination statement?
A granular, individually answerable item derived from the control statement — AC-17a.[01], AC-17a.[02] and so on — against which the assessor records satisfied or other than satisfied. Rev 5 separates the statements for organization-defined parameters from those for the control items.

Who uses NIST 800-53A?
FedRAMP 3PAOs, agency and StateRAMP assessors, and internal assessment teams performing CA-2 control assessments and CA-7 continuous monitoring — and control owners preparing evidence, because the procedures tell them exactly what will be asked.

Where this leaves you

Read NIST 800-53A as the answer key: build the evidence matrix by determination statement, assign every parameter, prepare a document, a person and a working mechanism for each, run the procedures internally at real depth, and record the 800-53 release and every inapplicability — because the assessor’s report will be written in exactly those terms, and satisfied is the only finding that does not become a POA&M entry.

References

More on NIST 800-53

The control assessment plan template, the evidence matrix keyed to determination statements, the assessment report template on the Appendix E outline and the POA&M register are in the NIST SP 800-53 Security Controls Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.