Control Narratives

Control narratives describe how your organization implements each NIST 800-53 security control. This guide explains how to manage control narratives in Complinist.

Overview

For each applicable control in your baseline, you need to document:

  • How you implement the control
  • What systems or processes support it
  • Who is responsible
  • Where it applies (which devices/boundaries)

Accessing Control Narratives

  1. Click Narratives in the top navigation
  2. Browse controls by family or search
  3. Click on a control to view/edit its narrative

Control Families

NIST 800-53 Rev 5 organizes controls into 20 families:

FamilyNameFocus
ACAccess ControlWho can access what
ATAwareness and TrainingSecurity training
AUAudit and AccountabilityLogging and monitoring
CAAssessment and AuthorizationSecurity assessments
CMConfiguration ManagementSystem configurations
CPContingency PlanningBackup and recovery
IAIdentification and AuthenticationLogin and identity
IRIncident ResponseSecurity incidents
MAMaintenanceSystem maintenance
MPMedia ProtectionStorage media
PEPhysical SecurityPhysical access
PLPlanningSecurity planning
PMProgram ManagementSecurity program
PSPersonnel SecurityPeople security
PTPII ProcessingPrivacy controls
RARisk AssessmentIdentifying risks
SASystem AcquisitionProcurement
SCSystem and CommunicationsNetwork security
SISystem IntegrityMalware, patching
SRSupply ChainVendor risks

Writing Effective Narratives

Structure of a Good Narrative

  1. What - What do you do to meet the control?
  2. How - How is it implemented technically?
  3. Who - Who is responsible?
  4. When - How often (if applicable)?
  5. Where - What systems does it apply to?

Example: AC-2 Account Management

Weak narrative:

"We manage user accounts."

Strong narrative:

"The organization manages information system accounts using Microsoft Active Directory (AD). New accounts require documented approval from the user's manager via ServiceNow ticket (INC-XXXX format) before IT creates the account. Accounts are provisioned with role-based access using AD security groups aligned to job functions. System administrators review and update account privileges quarterly using the Identity Governance tool. Temporary accounts are assigned expiration dates at creation and automatically disabled. Inactive accounts (90+ days) are automatically disabled by AD policy and flagged for review."

Key Elements

  1. Name specific systems - "Microsoft Active Directory" not "directory service"
  2. Include procedures - "via ServiceNow ticket" not "through a process"
  3. Mention frequencies - "quarterly review" not "periodic review"
  4. Reference devices - Link to devices in your topology

Editing Narratives

Basic Editing

  1. Navigate to the control
  2. Click in the narrative text area
  3. Edit the text
  4. Click Save or press Ctrl+S

Rich Text Formatting

The narrative editor supports:

  • Bold and italic text
  • Bullet lists
  • Numbered lists
  • Links

Linking to Devices

Reference specific devices from your topology:

  1. Mention the device by name: "Firewall FW-01"
  2. Use the device linking feature to create direct links
  3. Device properties will be included in SSP

Control Status

Track the status of each control:

StatusMeaning
Not StartedNo narrative written
In ProgressNarrative being developed
CompleteNarrative finalized
Not ApplicableControl doesn't apply

Not Applicable Controls

If a control doesn't apply to your system:

  1. Set status to "Not Applicable"
  2. Document why it doesn't apply
  3. This becomes part of your SSP

Writing Narratives

Use the control narrative editor to document implementations:

Start a New Narrative

  1. Open a control in the editor
  2. Describe how your system implements the requirement
  3. Link relevant devices from your topology
  4. Set the control status when complete

Improve Existing Narratives

  1. Review narratives against your current topology
  2. Update device references when architecture changes
  3. Regenerate the SSP to keep documentation in sync

See SSP Generation for export details.

Inherited Controls

Some controls may be inherited from cloud service providers, shared services, or parent organizations.

Documenting Inherited Controls

  1. Note the control is inherited
  2. Reference the provider's authorization
  3. Describe any customer responsibilities
  4. Include provider documentation references
Example:

"This control is partially inherited from AWS under FedRAMP Moderate authorization (JAB P-ATO). AWS provides physical security for data centers (PE-2, PE-3, PE-6). The customer responsibility includes managing logical access to AWS resources, implemented through IAM policies and security groups as described in AC-3."

Control Enhancements

Many controls have enhancements that provide additional requirements:

  • AC-2(1) - Automated Account Management
  • AC-2(2) - Automated Temporary Accounts
  • AC-2(3) - Disable Accounts

Handling Enhancements

  1. Each enhancement may need its own narrative
  2. Check your baseline for required enhancements
  3. Document how you meet enhanced requirements

Best Practices

Do's

  • Be specific about systems and tools
  • Include frequencies and timelines
  • Reference actual procedures
  • Link to topology devices
  • Update when implementations change

Don'ts

  • Use vague language ("appropriate measures")
  • Copy generic text without customizing
  • Leave controls incomplete
  • Forget to update after changes
  • Skip documenting N/A justifications

Review Checklist

Before generating your SSP, verify:

  • All applicable controls have narratives
  • Narratives reference specific systems
  • Inherited controls are documented
  • N/A controls have justifications
  • Devices are linked where appropriate
  • Statuses are accurate
  • Content is current

Common Control Examples

ControlFocus Areas
AC-2: Account ManagementAccount lifecycle, approval process, reviews
AU-2: Audit EventsWhat's logged, where logs go, retention
CM-6: Configuration SettingsBaselines, STIGs, hardening guides
IA-2: Identification and AuthenticationMFA, authentication methods, credentials
SC-7: Boundary ProtectionFirewalls, network segmentation, monitoring
SI-2: Flaw RemediationPatching process, timelines, testing

Troubleshooting

Narrative Not Saving

  • Ensure auto-save completed (wait a moment after editing)
  • Check for special characters that may cause issues
  • Try saving a shorter version first

Control Not Showing

  • Verify control is in your baseline
  • Check if it was marked as not applicable
  • Ensure baseline hasn't changed