Evidence testing separates appearance from operation
Interviews and policies describe intent; configuration, records, logs, tests, tickets, and observation establish whether outcomes are actually achieved.
Conduct a NIST CSF risk assessment and gap analysis with evidence testing, Current and Target Profiles, risk ratings, ownership, and remediation priorities.
The assessment should explain which service, asset, data, stakeholder, or obligation is affected and what plausible harm the gap allows.
Interviews and policies describe intent; configuration, records, logs, tests, tickets, and observation establish whether outcomes are actually achieved.
Some fixes reduce immediate exposure, while others establish asset, identity, logging, governance, or recovery foundations needed by many later improvements.
A useful assessment explains which service, asset, data, stakeholder, or obligation is affected and what plausible harm the condition enables. It distinguishes an absent control from weak coverage, inconsistent operation, stale evidence, untested effectiveness, or an accepted exception.
NIST CSF provides outcomes and vocabulary. Risk assessment adds threat, vulnerability, likelihood, impact, existing safeguards, uncertainty, and treatment decisions. NIST SP 800-30 and the NISTIR 8286 series provide related risk concepts that can support methodology.
| Method | What it reveals | Limitations to manage |
|---|---|---|
| Document review | Approved intent, roles, procedures, prior findings, contractual context | Documents may be stale or disconnected from operation |
| Interviews | Workflow, ownership, exceptions, undocumented dependencies | Statements require corroboration |
| Configuration review | Technical design, assignments, exclusions, inherited settings | A snapshot may not prove recurring operation |
| Record sampling | Whether reviews, changes, incidents, and remediation occur | Samples must represent scope and period |
| Technical testing | Exposure, enforcement, detection, segmentation, recovery | Authorization, scope, safety, and timing matter |
| Observation or exercise | Real decision paths, handoffs, timing, and human capability | Scenarios must be realistic and lessons tracked |
Condition: Four standing Global Administrator assignments exist; two are used for routine work, and no documented quarterly recertification occurs.
Evidence: Entra role export, sign-in sample, access-review configuration, and administrator interview.
Risk: Excess standing privilege and weak review increase the likelihood that unnecessary or compromised administrative access persists and affects cloud data and services.
Recommendation: Separate routine and privileged identities, reduce standing assignments, use time-bound activation where available, establish quarterly certification, protect emergency access, and alert on role changes.
Validation: Updated role export, activation settings, completed certification, emergency-account test, and approved exceptions.
A finding should state the observed condition, expected outcome, evidence, affected scope, business consequence, recommendation, owner, priority, and validation. Avoid generic wording such as “improve security” that cannot be implemented or tested.
Is there a credible actor, failure mode, or event for this environment?
How accessible is the weakness and what prerequisites exist?
Which preventive, detective, response, and recovery controls reduce risk?
Could the event affect safety, operations, revenue, customers, data, contracts, or reputation?
How many services, records, users, or locations may be affected and for how long?
Is the rating supported by current evidence, or does uncertainty need to be recorded?
Sequence work by immediate exposure, potential impact, dependencies, implementation risk, business windows, and available resources. Some projects directly reduce risk; others establish foundations used by many controls. Asset ownership, identity governance, logging, vulnerability management, and recovery testing often unlock several later improvements.
| Workstream | Typical timing | Closure expectation |
|---|---|---|
| Immediate containment | Hours to days | Exposure removed or compensating safeguard validated |
| Urgent remediation | Days to weeks | High-risk weakness corrected and retested |
| Foundational capability | Weeks to months | Repeatable process, ownership, coverage, and evidence established |
| Longer-term maturity | Quarterly roadmap | Target Profile progress, indicators, and residual-risk decision |
Accepted risk needs named authority, rationale, duration, compensating safeguards, and a review date. Closure should never imply zero residual risk.
Define objectives, scope, stakeholders, Profile context, evidence requirements, and rating method.
Review documents, systems, records, interviews, samples, exceptions, and technical results.
State condition, evidence, risk, affected outcome, recommendation, owner, and uncertainty.
Sequence actions, track accepted risk, validate high-risk closure, and update the Current Profile.
After gaps are documented and rated, use the next guide to improve the supporting Profile, evidence system, or implementation portfolio.
Use the Current and Target Profile guide to record achieved practices, uncertainty, target priority, action ownership, and validation in a form that can be maintained after the assessment.
Use the evidence and documentation guide to improve indexing, artifact quality, collection frequency, source integrity, access control, retention, and the distinction between an evidence weakness and an absent control.
Use the NIST roadmap guide to group immediate containment, urgent remediation, foundational capability, and longer-term maturity into owned work with dependencies and closure criteria.
The Compliance Readiness Assessment Wizard can provide an initial comparison point, while the free assessment library supports focused technical review. See Ali Hassani’s profile for the experience behind OC Security Audit’s risk-based method.
No. Risk depends on business context, threat, exposure, existing controls, impact, and the importance of the outcome.
Document missing evidence and assumptions instead of assigning false precision to risk ratings.
Closure should require appropriate evidence and, for significant technical findings, validation that the control now operates effectively.
Ali Hassani brings 25+ years of IT, cybersecurity, compliance, Microsoft infrastructure, cloud, network, firewall, vulnerability-management, and operational experience. OC Security Audit can work with leadership, internal IT, and MSP teams to assess NIST CSF alignment and build a practical roadmap.
When findings require technical implementation or ongoing IT operations, IT Perfection can support relevant Microsoft 365, Azure, endpoint, backup, server, network, monitoring, patching, and managed IT work.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.