5.4 Preparing the Initial Assessment/Audit Report

Key Takeaways

  • SP 800-53A resolves every assessment objective to one of exactly two determinations: satisfied or other than satisfied.
  • The initial report exists to give the system owner a formal opportunity to respond before findings are finalized, which is a due-process requirement rather than a courtesy.
  • Assessors report findings and risk analysis; they do not decide remediation or accept risk, and an assessor who dictates fixes has compromised their independence.
  • Preliminary findings must state the evidence examined and the specific deviation observed, because a finding without evidence cannot survive challenge.
  • Risk mitigation summaries in the initial report describe options and their effect, leaving the selection of a response to the system owner and Authorizing Official.
Last updated: August 2026

Preparing the Initial Assessment/Audit Report

Task 5.3 sits between conducting the assessment (5.2) and reviewing it to plan risk responses (5.4). Its outputs are specific: risks identified during the assessment, risk mitigation summaries, and preliminary findings recorded. This is the draft report — deliberately not the final one — and understanding why the draft stage exists is what the exam tests.


1. The Two-Value Determination Model

NIST SP 800-53A Rev. 5 structures assessment around determination statements. Each control decomposes into assessment objectives, each objective into determination statements, and each statement resolves to exactly two possible values:

DeterminationMeaning
SatisfiedThe evidence shows the objective is met: implemented correctly, operating as intended, producing the desired outcome
Other Than SatisfiedAnything else — not implemented, partially implemented, implemented incorrectly, or not demonstrable from available evidence

There is deliberately no "partially satisfied" value. A control that works for 90% of servers is other than satisfied, with the scope of the deficiency described in the finding narrative. Exam distractors regularly offer "partially satisfied" or "compliant with exceptions" as options; both are wrong.

"Other than satisfied" is not a synonym for "failed." It also covers the case where the assessor could not obtain sufficient evidence. If the organization cannot produce logs demonstrating that quarterly account reviews occurred, the objective is other than satisfied even if the reviews genuinely happened — because in assessment terms, an activity that cannot be evidenced did not occur. This is one of the most practically important ideas in Domain 5.


2. What a Defensible Preliminary Finding Contains

Findings are challenged. A finding that cannot survive a system owner's objection wastes everyone's time and damages the assessor's credibility. Each preliminary finding should record:

ElementContent
Control and objectiveThe specific control and determination statement not met
Assessment method usedExamine, interview, or test — and against which assessment object
Evidence examinedNamed artifacts, configuration exports, screenshots, interview records, scan output with dates
Observed conditionPrecisely what was found, in factual terms
Required conditionWhat the control and its organization-defined parameters require
The deviationThe gap between observed and required
Preliminary risk analysisLikelihood, impact, and affected scope in context

The discipline that separates strong findings from weak ones is separating observation from conclusion. "Account lockout is misconfigured" is a conclusion. "The Corporate-Auth-Baseline policy exported 2026-08-14 sets lockoutThreshold to 10; the SSP-approved organization-defined parameter is 5; 340 of 1,200 directory objects inherit this policy" is an observation — and it is far harder to dispute.

Contextualized Risk, Not Raw Severity

The initial report gives risk ratings, not just technical severity. A CVSS base score describes intrinsic severity in the abstract; the assessment must place it in this environment. Applying NIST SP 800-30 Rev. 1, the assessor considers threat sources and events, vulnerability severity, predisposing conditions, existing controls, likelihood of occurrence, and impact — which is how the same 9.8 CVSS vulnerability can rate High on an internet-facing portal and Low on an air-gapped lab host with no sensitive data.

[!IMPORTANT] Critical findings do not wait for the report. Rules of Engagement require immediate escalation of actively exploitable, high-impact conditions — typically within hours — to the ISSM, system owner, and Authorizing Official. Holding an unauthenticated remote-code-execution finding on a production system for three weeks until the draft report circulates is an assessor failure, not thoroughness.


3. Why the Draft Stage Exists

The initial report is issued to the system owner before findings are finalized, and this serves four purposes:

  1. Factual accuracy. Assessors work with incomplete context. A finding may rest on a misunderstanding of the architecture, on evidence the assessor was not given, or on testing a decommissioned component. The response window catches these cheaply.
  2. Due process. The system owner has a legitimate right to respond before findings become part of the permanent authorization record and drive an AO decision.
  3. Early remediation. Simple deficiencies — a misconfigured parameter, a missing procedure document — can often be fixed within the response window and reassessed, so they never reach the final report as open items. This is the mechanism task 5.4 refers to as reassessing non-compliant findings with newly applied corrective actions.
  4. Risk response planning. The system owner needs the findings in hand to plan responses, which is exactly what task 5.4 requires.

Legitimate Versus Illegitimate Challenges

LegitimateIllegitimate
Factual error — the assessor tested the wrong host"This finding will delay our authorization"
Evidence exists but was not provided during fieldwork"No other system gets cited for this"
The finding misreads a documented compensating control"The risk rating makes us look bad to leadership"
The organization-defined parameter cited is out of date"Our budget cannot cover remediation"

An assessor revises findings for the left column and holds firm on the right. Adjusting a risk rating because a stakeholder finds it politically inconvenient is a loss of independence, and independence is what gives the report its value to the Authorizing Official.


4. Risk Mitigation Summaries: Describe, Do Not Decide

The blueprint asks for "risk mitigation summaries outlined" in the initial report, and candidates consistently over-read this. The assessor may describe options and their likely effect on risk. The assessor may not select the response, commit the organization to a remediation, set a completion date, or accept risk on anyone's behalf.

The reason is structural. An assessor who designs the fix is later assessing their own work, which destroys the independence the whole model rests on. If the assessor specifies "implement a jump-host architecture with session recording," then reassesses that architecture, there is no independent evaluation left — the same conflict of interest that bars the ISSO from assessing the controls they operate.

The correct boundary:

Assessor SaysAssessor Does Not Say
"This deficiency could be addressed by enforcing the parameter through group policy, by network isolation, or by a compensating control; each would reduce likelihood.""You will implement group policy enforcement by 30 September."
"Residual risk after correction would be Low.""This residual risk is acceptable."
"Three findings share a root cause in the change management process.""Reorganize change management under the CISO."

Deciding the response is the system owner's job (task 5.4); accepting the residual risk is the Authorizing Official's (Domain 6).

From Initial to Final

The path is: initial report issued → system owner reviews and responds → factual corrections applied → quick-win remediations completed and reassessed and validated → risk responses selected → final report (task 5.5) records the definitive determination for every objective, incorporating both corrected findings and the results of any reassessment. Findings still open at that point flow to the POA&M and into the authorization package.

Loading diagram...
From Fieldwork to Final Report: The Initial Report Cycle
Test Your Knowledge

An assessor verifies that a required quarterly privileged-account review is enforced on 90% of in-scope servers but cannot be demonstrated on the remaining 10%. Under NIST SP 800-53A Rev. 5, how is the determination statement recorded?

A
B
C
D
Test Your Knowledge

A system owner responds to a draft finding by stating that the deficiency is real but that citing it will delay the authorization milestone and reflect poorly on the programme. How should the assessor proceed?

A
B
C
D
Test Your Knowledge

In the initial assessment report, an assessor writes: 'The organization will deploy a jump-host architecture with session recording by 30 September, after which this residual risk is acceptable.' What is wrong with this statement?

A
B
C
D