Indicators of Good Practice are the evidence markers used to judge whether an organisation is meeting a CAF outcome. They translate broad resilience expectations into observable practices, documentation, and operational signals. Practitioners use them to self-assess, compare progress over time, and show regulators that security efforts are measurable and repeatable.
Expanded Definition
Indicators of Good Practice are observable evidence points that show whether an organisation is moving toward a CAF outcome, rather than merely claiming intent. In NHI security and Agentic AI governance, they function as practical proof that controls are implemented, repeatable, and reviewable over time. Definitions vary across vendors and assurance programs, but the core idea is consistent: the indicator must be specific enough to verify and useful enough to support self-assessment.
Practitioners often map these indicators to control evidence such as policy artifacts, logging coverage, review cadence, ownership assignments, and remediation records. That makes the concept closely related to measurement language in NIST SP 800-53 Rev 5 Security and Privacy Controls, but Indicators of Good Practice are not the controls themselves. They are the proof signals that controls are operating as expected. The most common misapplication is treating a single document or checklist as sufficient evidence, which occurs when teams confuse stated policy with demonstrated operational performance.
Examples and Use Cases
Implementing Indicators of Good Practice rigorously often introduces evidence-collection overhead, requiring organisations to weigh assurance value against the time needed to gather and maintain proof.
- A service account inventory shows named owners, approved purposes, and last-review dates, demonstrating that identities are tracked rather than left to drift.
- Secrets rotation logs confirm that API keys and certificates are rotated on schedule, which provides a concrete signal that credential lifecycle controls are active. This aligns well with guidance in the Ultimate Guide to NHIs.
- Access reviews are documented with evidence of challenge, approval, and removal of unused privileges, showing that review is a real process rather than a paper exercise.
- Operational dashboards show alerting coverage for anomalous NHI activity, supporting the claim that monitoring is continuous and not limited to periodic audits.
- Change records include testing, approval, and rollback evidence for automation that interacts with secrets or service identities, which helps demonstrate controlled release behavior under NIST SP 800-53 Rev 5 Security and Privacy Controls.
Why It Matters in NHI Security
Indicators of Good Practice matter because NHI environments fail quietly when ownership, rotation, or visibility are weak. A control can exist on paper while service accounts remain untracked, secrets remain exposed, or access reviews never happen. NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, which means many teams cannot even prove the basic conditions needed for assurance. The same research also shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, underscoring why evidence must be operational, not theoretical.
For governance teams, this concept turns ambition into auditability. It helps connect NHI hygiene to measurable outcomes such as rotation discipline, offboarding, and privilege reduction, which are central to the Ultimate Guide to NHIs. Organisational reporting becomes stronger when it shows repeatable practice rather than one-time remediation. Organisations typically encounter the need for indicators only after an incident report, a failed audit, or an executive challenge, at which point good practice evidence becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-03 | Good practice indicators support measurable risk governance and recurring review evidence. |
| NIST SP 800-63 | Identity assurance guidance depends on observable evidence of identity lifecycle handling. | |
| NIST Zero Trust (SP 800-207) | Zero trust requires evidence that access decisions are continuously verified, not assumed. | |
| OWASP Non-Human Identity Top 10 | NHI-02 | Secret and credential hygiene are common evidence points for NHI good practice. |
| NIST AI RMF | AI governance relies on measurable controls and documented monitoring evidence. |
Use indicators to prove governance activities are recurring, documented, and tied to risk decisions.