NIST SP 800-115¶
NIST's Technical Guide to Information Security Testing and Assessment: guidance on planning and carrying out security assessments, including penetration testing.
Why It Matters¶
SP 800-115 is the recognized government reference for how security testing should be planned, executed, and reported. It is useful for framing an engagement in terms a compliance or GRC audience accepts, and it connects penetration testing to the wider assessment process.
Reference¶
Assessment Techniques and Phases¶
| Area | Covers |
|---|---|
| Review Techniques | Passive examination: documentation, log, ruleset, and configuration review; network sniffing; file integrity checking |
| Target Identification and Analysis | Network discovery, port and service identification, vulnerability scanning, wireless scanning |
| Target Vulnerability Validation | Confirming vulnerabilities through password cracking, penetration testing, and social engineering |
| Assessment Planning | Assessment policy, prioritization and scheduling, approach selection, logistics |
| Assessment Execution | Carrying out the techniques identified in the plan |
| Post-Testing Activities | Turning findings into mitigation recommendations, reporting, and remediation |
How I Use It¶
When an engagement needs to line up with a formal assessment or compliance program, I frame scope and reporting in SP 800-115 terms. Its split between review, identification, and validation techniques is a useful check that an assessment is not relying on a single method.