Version: 1.0
Published: May 2026
Author: Brandon J. Johnson
Framework: NIST SP 800-53 Rev. 5
Controls reviewed: ~310 primary controls
Controls implemented: 14
TABLE OF CONTENTS
Disclaimer: This whitepaper and all DeFi Sentinel Watch audit reports are for informational and security analysis purposes only. They do not constitute financial or investment advice. Security assessments do not guarantee the safety of any protocol or the preservation of capital.

Abstract

This whitepaper describes the methodology used by DeFi Sentinel Watch to apply NIST Special Publication 800-53 Revision 5 — the United States federal government's security controls framework — to decentralized finance (DeFi) liquidity pools on the Flare Network.

We present a systematic adaptation of 14 NIST 800-53 security controls to the unique technical architecture of automated market maker (AMM) liquidity pools, including the specific on-chain data queries, evaluation criteria, and rating methodology used in our weekly automated audit program.

To our knowledge, this framework represents one of the first systematic applications of NIST 800-53 to DeFi liquidity pool security intelligence at scale. We are not aware of any published methodology applying this framework to on-chain smart contract security assessment at this time.

1. Introduction

1.1 The DeFi Security Gap

Decentralized finance protocols collectively hold billions of dollars in user assets. Unlike traditional financial institutions, these protocols operate without central governance, regulatory oversight, or mandatory security disclosure requirements. Liquidity providers bear direct security risk with limited tools to assess it.

Traditional security audit firms provide point-in-time assessments costing $10,000–$50,000 per engagement. These audits are valuable but insufficient for continuous security monitoring of live protocols.

1.2 Why NIST SP 800-53

We selected NIST 800-53 for three reasons:

2. Framework Overview

2.1 Selected Controls

FamilyControlName
Access ControlAC-2Account Management
Access ControlAC-3Access Enforcement
Access ControlAC-6Least Privilege
Audit & AccountabilityAU-2Audit Events
Audit & AccountabilityAU-6Audit Review
System & Comm. ProtectionSC-5DoS Protection
System & Comm. ProtectionSC-8Transmission Integrity
System & Info. IntegritySI-2Flaw Remediation
System & Info. IntegritySI-7Software Integrity
Incident ResponseIR-4Incident Handling
Configuration ManagementCM-6Configuration Management
Risk AssessmentRA-3Oracle Integrity
Contingency PlanningCP-9State Recovery
System & Services AcquisitionSA-11Security Testing

2.2 Rating Methodology

Each control is rated PASS, PARTIAL, or FAIL. A composite risk score is calculated using weighted scoring: PASS = 1 point, PARTIAL = 5 points, FAIL = 8 points. Scores of 1.0–3.0 indicate Low Risk; 3.1–5.0 Moderate Risk; 5.1–8.0 High Risk.

3. Control Adaptations

Each of the 14 selected controls required adaptation from its traditional IT context to the DeFi smart contract domain. Key adaptations include:

Full technical implementation details including RPC function selectors and code implementations are available upon request for institutional subscribers.

4. Audit Process

4.1 Pool Selection

DeFi Sentinel Watch monitors the top 10 liquidity pools by Total Value Locked (TVL) from both SparkDex V3 and V4 — 20 pools in total. Pool rankings are reviewed quarterly and the monitored list is updated if TVL rankings have materially changed, ensuring we are always auditing the highest-value pools in the SparkDex ecosystem.

4.2 Weekly Rotating Audits

Each week we audit 6 pools — 3 from SparkDex V4 and 3 from SparkDex V3 — selected in order of TVL ranking. The pools rotate each week so that after 3 to 4 weeks the full set of 20 pools has been audited and the cycle starts over from the beginning. No pool goes more than 30 days without a fresh audit. PDF reports are generated every Sunday at midnight UTC and delivered to the subscriber portal.

Subscribers can access their full report archive at any time, enabling side-by-side comparison of audit results across cycles to identify security trends, configuration changes, or emerging risk patterns over time.

4.3 Continuous Monitoring

Our AI agent polls all actively monitored pools every 15 minutes checking bytecode hashes (SI-7), fee tiers (CM-6), and tick spacing (CM-6) against established baselines. Any detected change triggers an immediate full 14-control audit and subscriber notification — regardless of where the pool sits in the weekly rotation.

4.4 Quarterly Pool Review

Every quarter we conduct a full review of the top 10 liquidity pools by TVL for both SparkDex V3 and V4. If pool rankings have changed materially, the monitored pool list is updated and new baselines are established for any newly added pools. This ensures our audit program remains focused on the highest-value pools in the ecosystem.

4.5 Baseline Management

Security baselines are established on initial audit and refreshed immediately following a verified announced protocol upgrade or quarterly pool list review.

5. Limitations

Appendix A: Comprehensive Control Selection Analysis

The following summarizes our systematic review of all 20 NIST SP 800-53 Rev. 5 control families and approximately 310 primary controls.

14
Controls fully implemented
~29
Controls partially incorporated
~16
Controls for future development
~251
Controls not applicable
FamilyControlsIncludedReason for Exclusions
AC — Access Control173 includedSession, device, and wireless controls have no smart contract equivalent
AT — Awareness & Training50 includedOrganizational human behavior — no on-chain equivalent
AU — Audit & Accountability162 includedBlockchain immutability handles retention; session audit N/A
CA — Assessment & Monitoring90 formalCA-7 incorporated into AU-6/SI-7; no formal ATO equivalent
CM — Configuration Mgmt141 includedProcurement and development lifecycle controls N/A for deployed contracts
CP — Contingency Planning131 includedOrganizational plans and physical site controls N/A; blockchain is distributed
IA — Identification & Auth120 includedNo sessions, logins, or device auth in smart contracts; wallet addresses assessed in AC-2
IR — Incident Response101 includedOrganizational training and planning N/A; monitoring assessed in IR-4
MA — Maintenance60 includedPhysical maintenance N/A; upgrade maintenance in SI-2
MP — Media Protection80 includedPhysical media N/A; blockchain data is public and immutable
PE — Physical & Environmental200 includedNo physical location; blockchain is globally distributed
PL — Planning120 includedOrganizational planning documents — no on-chain equivalent
PM — Program Management320 includedOrganizational governance — outside scope of on-chain assessment
PS — Personnel Security90 includedPermissionless DeFi — no formal personnel structure; teams often pseudonymous
PT — PII Processing80 includedDeFi protocols do not collect PII by design
RA — Risk Assessment101 includedOracle integrity directly assessable; formal risk categorization is organizational
SA — System & Services Acq.231 includedProcurement and development lifecycle N/A for deployed contracts
SC — System & Comm. Protection512 includedNetwork architecture controls (firewalls, VPNs, wireless) N/A to permissionless blockchain
SI — System & Info. Integrity232 includedMalware, spam, session controls N/A; core integrity controls implemented
SR — Supply Chain Risk Mgmt120 formalPartially incorporated into SI-7; full supply chain analysis is future capability

Future Development Roadmap

The following controls are identified for future implementation as tooling matures:

© 2026 DeFi Sentinel Watch · Brandon J. Johnson · This whitepaper is for informational purposes only. It does not constitute financial or investment advice. Security assessments do not guarantee the safety of any protocol or the preservation of capital. DeFi Sentinel Watch has no financial relationship with any protocol it audits.

See the methodology in action

Free weekly audit reports applying these 14 controls to 6 SparkDex pools — no credit card required.

Subscribe free →