A control list is not an operating record

A spreadsheet can say that a control applies. It usually cannot tell you which application version the statement describes, which part is inherited, which event proves operation, which organization-defined parameter remains unanswered, or whether the evidence was created while the work happened.

A Control Passport is a generated, versioned record attached to an exact operational artifact. It carries the selected control profile, tailoring decisions, parameter answers, evidence bindings, inherited responsibilities, gate definitions, and unresolved gaps.

It is not a certification, an authorization to operate, or a claim that an organization complies with NIST SP 800-53.

THE CORE RULE

A control assertion should identify the artifact, responsibility, and evidence that make it inspectable.

The synthetic instrument

The example was generated from a synthetic grievance and appeals timeliness instrument. The application assembles a case from connected sources, keeps acknowledgement and resolution clocks visible, retrieves relevant policy through Elasticsearch, supports the operator with cited AI assistance, records human disposition, and writes an append-only event ledger.

No client data, current-employer material, protected health information, or production configuration appears in the example.

CONTROLS154149 baseline + 3 added + 2 inherited
PARAMETERS3 / 450Organization-defined values answered
EVIDENCE5Controls bound to ledger or metric events
GATES4Operational framework gates

These counts are not a compliance score. They expose the current profile and its gaps. In this pre-operational example, the artifact digest is not yet bound, 447 organization-defined parameters remain open, and 149 controls are asserted without an application-level evidence binding.

Starting point and tailoring

The example starts from the NIST SP 800-53B low baseline, then records three additions required by the instrument design.

AU-10Non-repudiation

Added because the decision record must preserve actor, rationale, authority version, and disposition.

SA-11Developer Testing and Evaluation

Added because gate logic, evidence retrieval, and record generation require repeatable verification.

SI-10Information Input Validation

Added because case identifiers, retrieved evidence, operator inputs, and generated recommendations cross trust boundaries.

Two controls are marked as inherited from the hosting environment: AC-2 for account management through the identity provider, and SC-13 for cryptographic protection through the platform cryptographic module. Inheritance does not remove responsibility. The passport identifies the provider and leaves verification status visible.

Organization-defined parameters remain explicit

NIST controls include organization-defined parameters that must be set in context. The example answers three:

  • auditable events include case creation, evidence retrieval, gate evaluation, operator confirmation, disposition, notice issuance, and corrections;
  • audit events are recorded continuously as work happens;
  • gate compliance and open-case ageing are reviewed weekly.

The remaining parameters are not silently filled with generic values. They remain open. This is important because an incomplete but honest profile is safer than false precision.

Evidence is bound to operational events

Five controls in the synthetic profile have application-level evidence bindings.

AU-2ledger.event.*

Selected events enter the operating ledger.

AU-10ledger.event.disposition

Actor, rationale, and authority version accompany the disposition.

AU-9ledger.append_only_verification

The system records integrity verification for the append-only ledger.

AC-3ledger.event.access_check

Access decisions produce an inspectable event.

CA-7metrics.gate_compliance_weekly

Continuous monitoring includes gate compliance and case ageing.

An evidence binding is a declaration of where evidence should appear. It does not prove that every event is correct, complete, retained for the required period, or independently assessed. Those questions belong in testing and assessment.

The four operational gates

The passport also carries framework gates because control operation depends on the workflow being governed.

  • ACK: acknowledgement is issued within the applicable clock.
  • RESOLVE_STANDARD: a standard grievance reaches disposition within the applicable clock.
  • RESOLVE_EXPEDITED: an expedited grievance reaches disposition within its shorter clock.
  • CLASSIFY: the case is classified before downstream gates are evaluated.

Each gate has a source framework, version, trigger, required evidence, and ledger event. This makes it possible to inspect not only whether a control was selected, but how the instrument is expected to behave at the point of decision.

Relationship to the NIST publications

The example references the NIST SP 800-53 Rev. 5 control catalog, uses a baseline derived from NIST SP 800-53B, and expects assessment procedures to be developed with NIST SP 800-53A Rev. 5. NIST also publishes OSCAL control catalogs and profiles that support machine-readable implementation.

The downloadable example records OSCAL version 1.2.2 and catalog release 5.2.0 because those are the versions used by the reference generator. Organizations must validate the applicable catalog, baseline, overlays, laws, contracts, and internal policies for their own environment.

What the passport allows a reviewer to ask

The value of the record is not its control count. It is the quality of the questions it makes cheap.

  • Which exact build does this profile describe?
  • Which controls were added or removed, by whom, and why?
  • Which responsibilities are inherited, and from which provider?
  • Which parameters remain unanswered?
  • Which operational events are expected to provide evidence?
  • Did the event occur under the policy and model version shown?
  • What changed between this passport and the previous one?

Use the synthetic example

The example is public for inspection and adaptation. It should be treated as a structure to test, not as a universal control selection or an assessment result.

Build a Control Passport for one workflow →