TENABLE EVIDENCE WORKSHEET Purpose: organize supporting evidence. This worksheet does not calculate a score. Requirement and objective (e.g., 3.11.2[b]): Standard: NIST SP 800-171 Rev. 2 / NIST SP 800-171A (June 2018) Assessment scope and inventory version: Tenable product, and where results are stored: Scan type (vulnerability / configuration audit / web application): Execution/authentication (remote success / remote failed / partial / local agent / unknown): Audit file name, version, and profile: Custom or gold-image changes, and who approved them: Systems or applications expected: Systems or applications successfully tested: Missing, failed, unsupported, or excluded — and why: Scan dates and time zone: Export file name and archive location: What this artifact supports: What it does not establish / other evidence still needed: Fix or risk-decision reference: Owner and target date: Re-scan reference: Reviewer and review date: Evidence state: NOT REVIEWED / MISSING / NEEDS REVIEW / COLLECTED COLLECTED means the artifact has been gathered. It does not mean MET. Unknown stays unknown. Never write passwords, keys, CUI, or drawings here. Editorial template, not a government form. Template checked September 23, 2026. Objectives source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171A.pdf Export fields source: https://docs.tenable.com/nessus/compliance-checks-reference/Content/ComplianceDataExport.htm