01 — Agree the assessment
Confirm objectives, criteria, evidence period, control populations, boundaries, report audience and confidentiality. Identify the people who can explain the controls and the people who can approve remediation. Record exclusions and expected limitations.
02 — Request proportionate evidence
Prepare a request list tied to the criteria. Ask for dated records with source and ownership, using agreed redaction and secure transfer. Obtain complete populations before selecting samples. Track missing items separately from confirmed failures.
03 — Assess and corroborate
Combine examination of records, interviews and authorised configuration review. Reconcile what the policy requires with what settings and operating records show. Interview statements explain context; corroborating evidence supports conclusions.
04 — Review findings for factual accuracy
Give control owners the observed condition, sample details and supporting references. Resolve factual disputes, document alternative evidence and separate factual correction from risk acceptance. Preserve the basis for each conclusion.
05 — Report decisions and actions
Provide management with a prioritised view and practitioners with actionable detail. Include limitations, dependencies, accountable owners and agreed target dates. Do not hide uncertainty behind a single aggregate score.
06 — Validate remediation
Inspect the implemented change and, where relevant, a new operating sample. A closed ticket is not enough evidence by itself. Record full closure, partial remediation, accepted risk or an unresolved finding distinctly.
Primary sources
- Atlant Security IT security audit
- NIST Cybersecurity Framework
- NIST SP 800-53A assessment methodology
General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.
Build your audit scoping brief, or send your requirements with an NDA or RFP. High-level context is sufficient for the first conversation.

