United States

NIST SP 800-53 Rev 5 LOW

173 controls. 293 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

173 controls 293 frameworks share controls with it United States held in the corpus

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
AC-1Policy and Procedures20
AC-14Permitted Actions Without Identification or Authentication3
AC-17Remote Access20
AC-18Wireless Access9
AC-19Access Control for Mobile Devices16
AC-2Account Management95
AC-20Use of External Systems17
AC-22Publicly Accessible Content11
AC-3Access Enforcement36
AC-7Unsuccessful Logon Attempts14
AC-8System Use Notification5
AT-1Policy and Procedures17
AT-2Literacy Training and Awareness31
AT-2(2)Insider Threat13
AT-3Role-Based Training29
AT-4Training Records19
AU-1Policy and Procedures15
AU-11Audit Record Retention16
AU-12Audit Record Generation23
AU-2Event Logging23
AU-3Content of Audit Records19
AU-4Audit Log Storage Capacity12
AU-5Response to Audit Logging Process Failures11
AU-6Audit Record Review, Analysis, and Reporting27
AU-8Time Stamps12
AU-9Protection of Audit Information18
CA-1Policy and Procedures18
CA-2Control Assessments33
CA-3Information Exchange18
CA-5Plan of Action and Milestones30
CA-6Authorization19
CA-7Continuous Monitoring33
CA-7(4)Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring;17
CA-9Internal System Connections163
CM-1Policy and Procedures13
CM-10Software Usage Restrictions17
CM-11User-Installed Software22
CM-2Baseline Configuration19
CM-4Impact Analyses17
CM-5Access Restrictions for Change19
CM-6Configuration Settings23
CM-7Least Functionality20
CM-8System Component Inventory26
CP-1Policy and Procedures17
CP-10System Recovery and Reconstitution21
CP-2Contingency Plan24
CP-3Contingency Training15
CP-4Contingency Plan Testing24
CP-9System Backup23
IA-1Policy and Procedures13
IA-11Re-Authentication11
IA-2Identification and Authentication (Organizational Users)24
IA-4Identifier Management22
IA-5Authenticator Management23
IA-6Authentication Feedback8
IA-7Cryptographic Module Authentication10
IA-8Identification and Authentication (Non-Organizational Users)19
IR-1Policy and Procedures19
IR-2Incident Response Training39
IR-4Incident Handling69
IR-5Incident Monitoring27
IR-6Incident Reporting31
IR-7Incident Response Assistance16
IR-8Incident Response Plan29
MA-1Policy and Procedures8
MA-2Controlled Maintenance14
MA-4Nonlocal Maintenance15
MA-5Maintenance Personnel12
MP-1Policy and Procedures14
MP-2Media Access13
MP-6Media Sanitization25
MP-7Media Use13
PE-1Policy and Procedures14
PE-12Emergency Lighting5
PE-13Fire Protection10
PE-14Environmental Controls8
PE-15Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and know7
PE-16Delivery and Removal13
PE-2Physical Access Authorizations15
PE-3Physical Access Control19
PE-6Monitoring Physical Access16
PE-8Visitor Access Records12
PL-1Policy and Procedures18
PL-10Baseline Selection. Select a control baseline for the system13
PL-11Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions9
PL-2System Security and Privacy Plans28
PL-4Rules of Behavior19
PM-1Information Security Program Plan0
PM-10Authorization Process0
PM-11Mission and Business Process Definition0
PM-12Insider Threat Program0
PM-13Security and Privacy Workforce0
PM-14Testing, Training, and Monitoring0
PM-15Security and Privacy Groups and Associations0
PM-16Threat Awareness Program0
PM-17Protecting CUI on External Systems0
PM-18Privacy Program Plan0
PM-19Privacy Program Leadership Role0
PM-2Information Security Program Leadership Role0
PM-20Dissemination of Privacy Program Information0
PM-21Accounting of Disclosures0
PM-22Personally Identifiable Information Quality Management0
PM-23Data Governance Body0
PM-24Data Integrity Board0
PM-25Minimization of PII Used in Testing, Training, and Research0
PM-26Complaint Management0
PM-27Privacy Reporting0
PM-28Risk Framing0
PM-29Risk Management Program Leadership Roles0
PM-3Information Security and Privacy Resources0
PM-30Supply Chain Risk Management Strategy0
PM-31Continuous Monitoring Strategy0
PM-32Purposing0
PM-4Plan of Action and Milestones Process0
PM-5System Inventory0
PM-6Measures of Performance0
PM-7Enterprise Architecture0
PM-8Critical Infrastructure Plan0
PM-9Risk Management Strategy0
PS-1Policy and Procedures14
PS-2Position Risk Designation10
PS-3Personnel Screening20
PS-4Personnel Termination20
PS-5Personnel Transfer18
PS-6Access Agreements15
PS-7External Personnel Security19
PS-8Personnel Sanctions12
PS-9Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions22
PT-1Policy and Procedures0
PT-2Authority to Process PII0
PT-3PII Processing Purposes0
PT-4Consent0
PT-5Privacy Notice0
PT-6System of Records Notice0
PT-7Specific Categories of PII0
PT-8Computer Matching Requirements0
RA-1Policy and Procedures86
RA-2Security Categorization28
RA-3Risk Assessment33
RA-5Vulnerability Monitoring and Scanning28
RA-7Risk Response11
SA-1Policy and Procedures18
SA-2Allocation of Resources11
SA-22Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the fo18
SA-3System Development Life Cycle21
SA-4Acquisition Process22
SA-5System Documentation13
SA-8Security and Privacy Engineering Principles19
SA-9External System Services30
SC-1Policy and Procedures13
SC-12Cryptographic Key Establishment and Management15
SC-13Cryptographic Protection22
SC-15Collaborative Computing Devices and Applications5
SC-20Secure Name/Address Resolution Service (Authoritative)5
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)6
SC-22Architecture and Provisioning for Name/Address Resolution Service5
SC-39Process Isolation9
SC-5Denial-of-Service Protection15
SC-7Boundary Protection25
SI-1Policy and Procedures14
SI-12Information Management and Retention26
SI-2Flaw Remediation26
SI-3Malicious Code Protection25
SI-4System Monitoring24
SI-5Security Alerts, Advisories, and Directives23
SR-1Policy and Procedures (SR-1)17
SR-10Inspection of Systems or Components (SR-10)8
SR-11Component Authenticity (SR-11)12
SR-12Component Disposal (SR-12)16
SR-2Supply Chain Risk Management Plan (SR-2)18
SR-3Supply Chain Controls and Processes (SR-3)27
SR-5Acquisition Strategies, Tools, and Methods (SR-5)20
SR-8Notification Agreements (SR-8)15

Tell me when NIST SP 800-53 Rev 5 LOW files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Lawful basis register per processing
  • Lawful basis register
  • Consent records (explicit + verifiable + withdrawable)
  • Direct marketing opt-in evidence
  • Consent UX
  • Granular preference centre
  • Audit trail of consents
  • Withdrawal mechanism as easy as giving
  • Consent records (granular and withdrawable)
  • Risk monitoring procedure

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-53 Rev 5 LOW, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition