Control Narratives
Control narratives describe how your organization implements each NIST 800-53 security control. This guide explains how to manage control narratives in Complinist.
Overview
For each applicable control in your baseline, you need to document:
- How you implement the control
- What systems or processes support it
- Who is responsible
- Where it applies (which devices/boundaries)
Accessing Control Narratives
- Click Narratives in the top navigation
- Browse controls by family or search
- Click on a control to view/edit its narrative
Control Families
NIST 800-53 Rev 5 organizes controls into 20 families:
| Family | Name | Focus |
|---|---|---|
| AC | Access Control | Who can access what |
| AT | Awareness and Training | Security training |
| AU | Audit and Accountability | Logging and monitoring |
| CA | Assessment and Authorization | Security assessments |
| CM | Configuration Management | System configurations |
| CP | Contingency Planning | Backup and recovery |
| IA | Identification and Authentication | Login and identity |
| IR | Incident Response | Security incidents |
| MA | Maintenance | System maintenance |
| MP | Media Protection | Storage media |
| PE | Physical Security | Physical access |
| PL | Planning | Security planning |
| PM | Program Management | Security program |
| PS | Personnel Security | People security |
| PT | PII Processing | Privacy controls |
| RA | Risk Assessment | Identifying risks |
| SA | System Acquisition | Procurement |
| SC | System and Communications | Network security |
| SI | System Integrity | Malware, patching |
| SR | Supply Chain | Vendor risks |
Writing Effective Narratives
Structure of a Good Narrative
- What - What do you do to meet the control?
- How - How is it implemented technically?
- Who - Who is responsible?
- When - How often (if applicable)?
- Where - What systems does it apply to?
Example: AC-2 Account Management
"We manage user accounts."
"The organization manages information system accounts using Microsoft Active Directory (AD). New accounts require documented approval from the user's manager via ServiceNow ticket (INC-XXXX format) before IT creates the account. Accounts are provisioned with role-based access using AD security groups aligned to job functions. System administrators review and update account privileges quarterly using the Identity Governance tool. Temporary accounts are assigned expiration dates at creation and automatically disabled. Inactive accounts (90+ days) are automatically disabled by AD policy and flagged for review."
Key Elements
- Name specific systems - "Microsoft Active Directory" not "directory service"
- Include procedures - "via ServiceNow ticket" not "through a process"
- Mention frequencies - "quarterly review" not "periodic review"
- Reference devices - Link to devices in your topology
Editing Narratives
Basic Editing
- Navigate to the control
- Click in the narrative text area
- Edit the text
- Click Save or press Ctrl+S
Rich Text Formatting
The narrative editor supports:
- Bold and italic text
- Bullet lists
- Numbered lists
- Links
Linking to Devices
Reference specific devices from your topology:
- Mention the device by name: "Firewall FW-01"
- Use the device linking feature to create direct links
- Device properties will be included in SSP
Control Status
Track the status of each control:
| Status | Meaning |
|---|---|
| Not Started | No narrative written |
| In Progress | Narrative being developed |
| Complete | Narrative finalized |
| Not Applicable | Control doesn't apply |
Not Applicable Controls
If a control doesn't apply to your system:
- Set status to "Not Applicable"
- Document why it doesn't apply
- This becomes part of your SSP
Writing Narratives
Use the control narrative editor to document implementations:
Start a New Narrative
- Open a control in the editor
- Describe how your system implements the requirement
- Link relevant devices from your topology
- Set the control status when complete
Improve Existing Narratives
- Review narratives against your current topology
- Update device references when architecture changes
- Regenerate the SSP to keep documentation in sync
See SSP Generation for export details.
Inherited Controls
Some controls may be inherited from cloud service providers, shared services, or parent organizations.
Documenting Inherited Controls
- Note the control is inherited
- Reference the provider's authorization
- Describe any customer responsibilities
- Include provider documentation references
"This control is partially inherited from AWS under FedRAMP Moderate authorization (JAB P-ATO). AWS provides physical security for data centers (PE-2, PE-3, PE-6). The customer responsibility includes managing logical access to AWS resources, implemented through IAM policies and security groups as described in AC-3."
Control Enhancements
Many controls have enhancements that provide additional requirements:
- AC-2(1) - Automated Account Management
- AC-2(2) - Automated Temporary Accounts
- AC-2(3) - Disable Accounts
Handling Enhancements
- Each enhancement may need its own narrative
- Check your baseline for required enhancements
- Document how you meet enhanced requirements
Best Practices
Do's
- Be specific about systems and tools
- Include frequencies and timelines
- Reference actual procedures
- Link to topology devices
- Update when implementations change
Don'ts
- Use vague language ("appropriate measures")
- Copy generic text without customizing
- Leave controls incomplete
- Forget to update after changes
- Skip documenting N/A justifications
Review Checklist
Before generating your SSP, verify:
- All applicable controls have narratives
- Narratives reference specific systems
- Inherited controls are documented
- N/A controls have justifications
- Devices are linked where appropriate
- Statuses are accurate
- Content is current
Common Control Examples
| Control | Focus Areas |
|---|---|
| AC-2: Account Management | Account lifecycle, approval process, reviews |
| AU-2: Audit Events | What's logged, where logs go, retention |
| CM-6: Configuration Settings | Baselines, STIGs, hardening guides |
| IA-2: Identification and Authentication | MFA, authentication methods, credentials |
| SC-7: Boundary Protection | Firewalls, network segmentation, monitoring |
| SI-2: Flaw Remediation | Patching process, timelines, testing |
Troubleshooting
Narrative Not Saving
- Ensure auto-save completed (wait a moment after editing)
- Check for special characters that may cause issues
- Try saving a shorter version first
Control Not Showing
- Verify control is in your baseline
- Check if it was marked as not applicable
- Ensure baseline hasn't changed