Archstone Security · Research exhibit · SP 800-171A collector study

Which mechanism reads which objective.

Every assessment objective in NIST SP 800-171A Rev 2 that a system can answer for itself is answered by one of five collection mechanisms. All five are commodity capabilities the standard already obliges a contractor to operate. This exhibit classifies all 320 Rev 2 assessment objectives by which mechanism class can read them — and by how much of the standard each class reaches on its own.

Dataset v8.8 Standard NIST SP 800-171A Rev 2 · 320 assessment objectives Identifiers OSCAL form, per NIST OSCAL guidance Basis single reference architecture, n=1 Resolves to every figure below traces to a row in the table at the foot of this page

What this exhibit does and does not publish

There are two distinct acts between a published requirement and a machine-readable answer. Designation — naming which objectives the Department will accept machine evidence for, and from what class of mechanism — is a policy act, performed once, inherited by every supplier at no marginal cost. Mapping — determining which specific configuration setting satisfies a given objective on a given platform — is engineering work, platform-specific, and perishable.

This exhibit publishes the first and withholds the second. That is not a limitation of the exhibit; it is the boundary the underlying proposal argues the Department should draw.

Published here

Objective identifier · family · reportability disposition · which mechanism class can read it · whether a published referent exists

Not published here

The objective-to-setting mapping: specific configuration items, registry paths, policy identifiers, benchmark rule IDs, or query definitions

What each collector class reaches

Mechanism classes are cumulative in cost and in coverage. Add one at a time and watch what the standard gives back. Each square is one of the 320 assessment objectives, grouped by family. The at-least-partial totals at each rung — 33.1, 63.8 and 69.7 percent — are unchanged from earlier revisions of this dataset; what later revisions moved is the boundary between full and partial, not the size of the observable set.

Fully reportable — the objective is answered end to end Partially reportable — emission exists but is incomplete or has no published referent Not reached at this collector class

The five mechanism classes

Counts are objectives that class can read, at any disposition. An objective readable more than one way is counted under each — 91 objectives are reachable by two mechanisms and 2 by three, which is why the columns exceed 320 in sum.

1
fully reportable
objective added

The most expensive collector reaches the least scoreable ground. Thirty-one objectives are reachable by log query and by nothing else, and exactly one of them is fully reportable. Twenty-nine of the thirty-one carry no published referent — no authoritative artifact stating what the emitted events must show for the objective to be satisfied.

The consequence is visible in the ladder above. Adding tenant configuration to an endpoint collector takes fully reportable objectives from 81 to 142. Adding log query on top of both takes it from 142 to 143 — one objective, for the most operationally costly capability in the set. It converts a further eighteen from unreached to partially reportable, and that is all it does. This is not a property of logging. Log data is abundant and the mechanism is mature. It is a property of the referent gap — the emission exists and there is nothing published to score it against. Where the Department has published a referent, the cheap collectors resolve the objective completely; where it has not, the expensive collector still cannot.

Mechanism coverage by family

Counts of fully and partially reportable objectives each mechanism class can read, by SP 800-171 family. Families with no observable objectives at all are shown for completeness — their absence is a finding, not a gap in the study.

Cell values count objectives, not settings. A family total below the sum of its row reflects objectives readable by more than one mechanism.

What this study does not establish

Stated so the numbers above can be read at the weight they actually carry.

  • N = 1. Classifications are made against a single reference architecture — a Windows and Azure environment with a FedRAMP Moderate backend, hardened to a published benchmark. Another architecture would move rows.
  • Eighty objectives emit nothing. Of the 97 classified not observable, 80 have no collection mechanism at any cost. These are conduct, judgment, and documentary objectives, and they are why assessors remain necessary.
  • Seventeen emit but are still classified not observable. A mechanism exists, but it lies outside the declared reference architecture or has no published referent to score against. These rows retain their mechanism value as a record of where emission would originate.
  • Mechanism class is not tool selection. Each class names a capability, not a product. Open implementations exist for all five and no commercial compliance platform is used anywhere in the reference environment.
  • Partial is a real bucket, not a soft yes. It means emission exists and does not reach the objective's full parameter. The credibility of the fully reportable column depends on this distinction being enforced.
  • The figures are Rev 2 and do not carry to Rev 3. Rev 3 has seventeen families to this study's fourteen and a different objective count, so every number here is revision-specific. The method transfers — the emission test, the disposition taxonomy, the collector ladder — and so does the finding that the referent gap, not the mechanism, is what limits machine reportability. The counts do not. A Rev 3 cut is a separate study.
  • Eleven fully reportable objectives rest on DoD-published parameter values. For an agency that has not published equivalents, those revert to organization-defined: referents comparable across suppliers fall from 100 to 89, and organization-defined rises from 43 to 54. The classification is otherwise agency-neutral — nothing in the collector ladder or the emission test is specific to one department.
  • Multi-mechanism rows are treated disjunctively. Where an objective lists more than one mechanism, any one of them is taken as sufficient. The classification records which are capable, not which are required together.

All 320 assessment objectives

Sort any column. Filter by identifier, family, objective text, or mechanism. Mechanism tags name the collector class only.

Objective Control Assessment objective Family Reportability Mechanism class Published referent