Templates
Information Security
NIST 800-53a Audit and Assessment Checklist
🔍

NIST 800-53a Audit and Assessment Checklist

1
Gather and review appropriate documentation, including prior audit reports, remediation plans, and system security plans
2
Identify key personnel to interview
3
Arrange interviews with the key personnel
4
Perform analysis of policies, procedures, and controls
5
Approval: Policies and Procedures Evaluation
6
Collect samples from the system or process to be audited
7
Analyze the samples for compliance with NIST standards
8
Perform site inspections to assess physical security measures
9
Analyze and evaluate data collected from inspections and sample analysis
10
Prepare preliminary audit findings report
11
Approval: Preliminary Audit Findings
12
Discuss preliminary findings with the audited entity
13
Revise audit findings as necessary based on entity feedback
14
Prepare final audit report
15
Delivery of the final report to the managers
16
Approval: Final NIST 800-53a Audit Report
17
Provide suggestions for remediation
18
Pursue agreement on remediation plan
19
Observe the implementation of the remediation plan
20
Verify the effectiveness of the remediation plan by reassessing the audited area