Archstone Security · Research exhibit · SP 800-171A collector study
Every assessment objective in NIST SP 800-171A Rev 2 that a system can answer for itself is answered by one of five collection mechanisms. All five are commodity capabilities the standard already obliges a contractor to operate. This exhibit classifies all 320 Rev 2 assessment objectives by which mechanism class can read them — and by how much of the standard each class reaches on its own.
Dataset v8.8 Standard NIST SP 800-171A Rev 2 · 320 assessment objectives Identifiers OSCAL form, per NIST OSCAL guidance Basis single reference architecture, n=1 Resolves to every figure below traces to a row in the table at the foot of this page
There are two distinct acts between a published requirement and a machine-readable answer. Designation — naming which objectives the Department will accept machine evidence for, and from what class of mechanism — is a policy act, performed once, inherited by every supplier at no marginal cost. Mapping — determining which specific configuration setting satisfies a given objective on a given platform — is engineering work, platform-specific, and perishable.
This exhibit publishes the first and withholds the second. That is not a limitation of the exhibit; it is the boundary the underlying proposal argues the Department should draw.
Objective identifier · family · reportability disposition · which mechanism class can read it · whether a published referent exists
The objective-to-setting mapping: specific configuration items, registry paths, policy identifiers, benchmark rule IDs, or query definitions
Mechanism classes are cumulative in cost and in coverage. Add one at a time and watch what the standard gives back. Each square is one of the 320 assessment objectives, grouped by family. The at-least-partial totals at each rung — 33.1, 63.8 and 69.7 percent — are unchanged from earlier revisions of this dataset; what later revisions moved is the boundary between full and partial, not the size of the observable set.
Counts are objectives that class can read, at any disposition. An objective readable more than one way is counted under each — 91 objectives are reachable by two mechanisms and 2 by three, which is why the columns exceed 320 in sum.
The most expensive collector reaches the least scoreable ground. Thirty-one objectives are reachable by log query and by nothing else, and exactly one of them is fully reportable. Twenty-nine of the thirty-one carry no published referent — no authoritative artifact stating what the emitted events must show for the objective to be satisfied.
The consequence is visible in the ladder above. Adding tenant configuration to an endpoint collector takes fully reportable objectives from 81 to 142. Adding log query on top of both takes it from 142 to 143 — one objective, for the most operationally costly capability in the set. It converts a further eighteen from unreached to partially reportable, and that is all it does. This is not a property of logging. Log data is abundant and the mechanism is mature. It is a property of the referent gap — the emission exists and there is nothing published to score it against. Where the Department has published a referent, the cheap collectors resolve the objective completely; where it has not, the expensive collector still cannot.
Counts of fully and partially reportable objectives each mechanism class can read, by SP 800-171 family. Families with no observable objectives at all are shown for completeness — their absence is a finding, not a gap in the study.
Cell values count objectives, not settings. A family total below the sum of its row reflects objectives readable by more than one mechanism.
Stated so the numbers above can be read at the weight they actually carry.
Sort any column. Filter by identifier, family, objective text, or mechanism. Mechanism tags name the collector class only.
| Objective | Control | Assessment objective | Family | Reportability | Mechanism class | Published referent |
|---|