Skip to content

NIST SP 800-115

NIST's Technical Guide to Information Security Testing and Assessment: guidance on planning and carrying out security assessments, including penetration testing.

Why It Matters

SP 800-115 is the recognized government reference for how security testing should be planned, executed, and reported. It is useful for framing an engagement in terms a compliance or GRC audience accepts, and it connects penetration testing to the wider assessment process.

Reference

Assessment Techniques and Phases

Area Covers
Review Techniques Passive examination: documentation, log, ruleset, and configuration review; network sniffing; file integrity checking
Target Identification and Analysis Network discovery, port and service identification, vulnerability scanning, wireless scanning
Target Vulnerability Validation Confirming vulnerabilities through password cracking, penetration testing, and social engineering
Assessment Planning Assessment policy, prioritization and scheduling, approach selection, logistics
Assessment Execution Carrying out the techniques identified in the plan
Post-Testing Activities Turning findings into mitigation recommendations, reporting, and remediation

How I Use It

When an engagement needs to line up with a formal assessment or compliance program, I frame scope and reporting in SP 800-115 terms. Its split between review, identification, and validation techniques is a useful check that an assessment is not relying on a single method.

Resources