Skip to main content
Category: Risk Assessment & Analysis

Assessment Method (Examine, Interview, Test)

Also known as: Assessment Methods, Examine, Interview, Test, EIT
Simply put

An assessment method is one of the three basic actions an assessor uses to gather evidence when evaluating whether security or privacy controls are in place and working: examining documents or artifacts, interviewing people, and testing systems or mechanisms. These methods help assessors form a reliable picture of how well a system meets its requirements. The reader should verify current authoritative guidance, as specific procedures may vary by program and revision.

Formal definition

Per NIST terminology, an assessment method is one of three types of actions (examine, interview, test) taken by assessors to obtain evidence during a control assessment. The examine method involves reviewing, inspecting, observing, studying, or analyzing assessment objects such as specifications, mechanisms, or activities; the interview method involves holding discussions with individuals or groups to gather evidence and support understanding; and the test method involves exercising assessment objects under specified conditions to compare actual behavior with expected outcomes. These methods define the nature of the assessor's actions and are applied against assessment objects during an assessment. This entry describes the concept generally and does not cover program-specific application, scoring, or objectives, which practitioners should confirm against the applicable current NIST assessment guidance and any tailoring imposed by the responsible authority.

Why it matters

Assessment methods form the evidentiary backbone of any credible control assessment. When an assessor concludes that a control is satisfied, that conclusion should rest on concrete evidence gathered through examining artifacts, interviewing personnel, or testing mechanisms, rather than on assertion alone. Understanding the three methods helps compliance officers and information system security managers anticipate what an assessor will look for and prepare accordingly, and it helps authorizing officials weigh how much confidence to place in a given assessment result.

The methods also matter because they are not interchangeable, and relying on a single method can produce a misleading picture. A policy document reviewed under the examine method may describe an intended control, but an interview or test may reveal whether that control operates as written in practice. This distinction reinforces a point experts routinely stress: producing documentation is not the same as demonstrating that a control is implemented and effective, and compliance on paper is not equivalent to security. Assessors generally combine methods to corroborate findings and reduce the risk of a control appearing satisfied when it is not.

Readers should also keep in mind that assessment is distinct from authorization. Applying examine, interview, and test methods produces evidence and findings; it does not by itself grant an Authority to Operate. How these methods are applied, scored, and mapped to specific assessment objectives varies by program and by the revision of the applicable NIST guidance, so practitioners should confirm the current authoritative text and any tailoring imposed by the responsible authority.

Who it's relevant to

Assessors and Independent Assessment Teams
Assessors apply examine, interview, and test methods to gather evidence and reach defensible conclusions about control implementation and effectiveness. Understanding when to combine methods, and how the responsible authority expects them to be applied, is central to conducting a rigorous assessment. Specific procedures, scoring, and objectives should be confirmed against current NIST guidance and any program tailoring.
Information System Security Managers and Compliance Officers
These practitioners prepare systems and evidence for assessment. Knowing that assessors may examine artifacts, interview staff, and test mechanisms helps them assemble documentation and, more importantly, ensure that controls actually operate as documented, recognizing that producing a policy is not the same as demonstrating an implemented, effective control.
Authorizing Officials
Authorizing officials rely on assessment results to inform risk decisions. Understanding which methods produced the underlying evidence helps them judge the reliability of findings. They should also keep in mind that an assessment produces evidence and findings but does not by itself constitute an authorization or a time-bound Authority to Operate.
Government Contractors and Auditors
Contractors and auditors supporting federal, defense, or CUI-related systems encounter these methods when their controls are assessed. Being familiar with the examine, interview, and test approach helps them anticipate evidence requests, though the precise application, scope, and any tailoring will depend on the program and the current authoritative guidance, which they should verify.

Inside Assessment Method (Examine, Interview, Test)

Examine
An assessment method that involves reviewing, inspecting, observing, studying, or analyzing one or more assessment objects such as documents, mechanisms, or activities. Examples of objects examined generally include policies, procedures, system security plans, configuration settings, and records. This method is typically used to gather evidence that supports a determination of control effectiveness, but it does not by itself confirm that a control operates as intended in practice.
Interview
An assessment method that involves holding discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or obtain evidence. Objects of interviews are people, such as system owners, administrators, or users. Interviews generally supplement examination and testing by clarifying how controls are understood and executed, but responses reflect stated practice that may require corroboration through other methods.
Test
An assessment method that involves exercising one or more assessment objects, such as mechanisms or activities, under specified conditions to compare actual behavior with expected behavior. Testing generally provides more direct evidence of whether a control functions as designed, and is often used to validate findings from examination and interview.
Assessment objects
The specifications, mechanisms, activities, and individuals to which the methods are applied. Specifications and mechanisms are typically examined or tested, activities may be examined or tested, and individuals are interviewed. Matching the appropriate method to the appropriate object is a core element of assessment planning.
Depth and coverage attributes
Attributes that characterize the rigor and scope of how each method is applied. Depth addresses the level of detail and thoroughness, while coverage addresses the breadth of objects assessed. These attributes are generally tailored to the impact level or assurance requirements of the system, so the same method can be applied with differing intensity.

Common questions

Answers to the questions practitioners most commonly ask about Assessment Method (Examine, Interview, Test).

Does performing an assessment using Examine, Interview, and Test methods mean my system is authorized to operate?
No. Applying assessment methods produces evidence about whether controls are implemented and effective, but assessment is distinct from authorization. An assessment informs the authorizing official's risk-based decision, but only the authorizing official can grant an Authority to Operate (ATO). Confusing assessment with authorization is a common mistake; the two are separate steps, and a completed assessment does not by itself convey authorization.
If a control passes the Test method, does that prove the system is secure?
Not necessarily. A successful test indicates that a specific control or control element functioned as expected under the conditions examined at that point in time. Compliance evidence from assessment methods should not be equated with overall security. Controls change, configurations drift, and threats evolve, which is why assessment results generally feed into continuous monitoring rather than serving as a permanent assurance of security.
How do I decide whether to Examine, Interview, or Test a given control?
The choice generally depends on the assessment objective, the nature of the control, the required depth and coverage, and any tailoring in the applicable assessment plan. Examine typically applies to reviewing documents, mechanisms, or artifacts; Interview applies to gathering information from personnel; and Test applies to exercising objects to observe actual behavior. In many implementations a single control objective is evaluated using more than one method to strengthen the evidence. Confirm the specific expectations against the current governing assessment guidance and any agency-specific tailoring.
Can a single assessment method satisfy an assessment objective on its own?
Sometimes, but assessors often combine methods to obtain sufficient, corroborating evidence. Whether one method is adequate generally depends on the assurance requirements, the impact level, and how the assessment procedures are tailored. Where higher assurance is expected, assessors typically apply methods with greater depth and broader coverage, which may involve using multiple methods for the same objective.
What kinds of evidence support each method during an assessment?
Examine generally relies on artifacts such as policies, procedures, configuration settings, and system documentation. Interview relies on statements from individuals who perform or oversee relevant functions. Test relies on the results of exercising a mechanism, process, or activity to observe its actual operation. The specific evidence expected should be defined in the assessment plan and verified against current authoritative assessment procedures.
How do depth and coverage relate to the assessment methods?
Depth refers to the rigor and detail applied when using a method, and coverage refers to the breadth of objects assessed. Both attributes generally scale with the assurance needed, which often corresponds to system impact level and agency tailoring. Assessors should confirm the required depth and coverage values for each method against the applicable assessment guidance, as these expectations can vary by revision and by organizational tailoring rather than being fixed.

Common misconceptions

Any single method, such as examining documentation, is sufficient to determine that a control is effective.
The three methods are generally intended to be used in combination, with the appropriate mix selected based on the object being assessed and the required level of assurance. Examining a policy, for instance, does not confirm that the corresponding mechanism actually functions, which is why testing may be needed to corroborate documented or stated practice.
Applying an assessment method is equivalent to authorizing the system or confirming it is secure.
Assessment methods produce evidence used to determine control effectiveness; they are part of assessment, which is distinct from authorization. A favorable assessment result informs, but does not by itself grant, an authorization decision, and compliance evidenced through these methods is not the same as security.
The methods are applied at a fixed, uniform level of rigor for every system.
The application of Examine, Interview, and Test is generally tailored using depth and coverage attributes according to the system's impact level or assurance needs. The intensity and breadth of each method can therefore vary across systems and across revisions of the applicable guidance, which the reader should verify against the current authoritative text.

Best practices

Map each assessment method to the appropriate assessment object type, applying Examine and Test to specifications, mechanisms, and activities, and reserving Interview for individuals.
Combine methods rather than relying on a single one, using interviews and examination to understand intended operation and testing to validate that controls actually function as described.
Define depth and coverage explicitly during assessment planning, tailoring the rigor and breadth of each method to the system's impact level and assurance requirements.
Document the specific objects examined, individuals interviewed, and mechanisms tested so that findings are traceable and reproducible for auditors and authorizing officials.
Corroborate stated practices obtained through interviews with independent evidence from examination or testing before reaching a determination on control effectiveness.
Verify the current authoritative guidance for the applicable revision, since the definitions, attributes, and expected rigor of these methods may change and may be tailored by the responsible agency.