Assessment Method (Examine, Interview, Test)
An assessment method is one of the three basic actions an assessor uses to gather evidence when evaluating whether security or privacy controls are in place and working: examining documents or artifacts, interviewing people, and testing systems or mechanisms. These methods help assessors form a reliable picture of how well a system meets its requirements. The reader should verify current authoritative guidance, as specific procedures may vary by program and revision.
Per NIST terminology, an assessment method is one of three types of actions (examine, interview, test) taken by assessors to obtain evidence during a control assessment. The examine method involves reviewing, inspecting, observing, studying, or analyzing assessment objects such as specifications, mechanisms, or activities; the interview method involves holding discussions with individuals or groups to gather evidence and support understanding; and the test method involves exercising assessment objects under specified conditions to compare actual behavior with expected outcomes. These methods define the nature of the assessor's actions and are applied against assessment objects during an assessment. This entry describes the concept generally and does not cover program-specific application, scoring, or objectives, which practitioners should confirm against the applicable current NIST assessment guidance and any tailoring imposed by the responsible authority.
Why it matters
Assessment methods form the evidentiary backbone of any credible control assessment. When an assessor concludes that a control is satisfied, that conclusion should rest on concrete evidence gathered through examining artifacts, interviewing personnel, or testing mechanisms, rather than on assertion alone. Understanding the three methods helps compliance officers and information system security managers anticipate what an assessor will look for and prepare accordingly, and it helps authorizing officials weigh how much confidence to place in a given assessment result.
The methods also matter because they are not interchangeable, and relying on a single method can produce a misleading picture. A policy document reviewed under the examine method may describe an intended control, but an interview or test may reveal whether that control operates as written in practice. This distinction reinforces a point experts routinely stress: producing documentation is not the same as demonstrating that a control is implemented and effective, and compliance on paper is not equivalent to security. Assessors generally combine methods to corroborate findings and reduce the risk of a control appearing satisfied when it is not.
Readers should also keep in mind that assessment is distinct from authorization. Applying examine, interview, and test methods produces evidence and findings; it does not by itself grant an Authority to Operate. How these methods are applied, scored, and mapped to specific assessment objectives varies by program and by the revision of the applicable NIST guidance, so practitioners should confirm the current authoritative text and any tailoring imposed by the responsible authority.
Who it's relevant to
Inside Assessment Method (Examine, Interview, Test)
Common questions
Answers to the questions practitioners most commonly ask about Assessment Method (Examine, Interview, Test).