United States

NIST SP 800-53 Rev 5

320 controls. 281 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

320 controls 281 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-53 Rev 5 Security and Privacy Controls Evidence & Implementation Kit

320 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
NIST800-AC-1Access control policy and procedures29
NIST800-AC-10Concurrent Session Control. Limit the number of concurrent sessions for each [organization-defined] to [organization-defined]2
NIST800-AC-11Device lock16
NIST800-AC-12Session control16
NIST800-AC-14Permitted actions without identification or authentication9
NIST800-AC-16Security and Privacy Attributes. Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission; E12
NIST800-AC-17Remote access30
NIST800-AC-18Wireless access16
NIST800-AC-19Access control for mobile devices23
NIST800-AC-2Account management104
NIST800-AC-20Use of external systems97
NIST800-AC-21Information Sharing. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information's access and use restrictions for [organ19
NIST800-AC-22Publicly accessible content17
NIST800-AC-23Data Mining Protection. Employ [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining7
NIST800-AC-24Access Control Decisions. [organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement13
NIST800-AC-25Reference Monitor. Implement a reference monitor for [organization-defined] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the complet0
NIST800-AC-3Access enforcement44
NIST800-AC-4Information flow enforcement30
NIST800-AC-5Separation of duties24
NIST800-AC-6Least privilege79
NIST800-AC-7Unsuccessful logon attempts89
NIST800-AC-8System Use Notification. Display [organization-defined] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, ex11
NIST800-AC-9Previous Logon Notification. Notify the user, upon successful logon to the system, of the date and time of the last logon3
NIST800-AT-1Policy and procedures for awareness and training22
NIST800-AT-2Literacy training and awareness37
NIST800-AT-3Role-based training82
NIST800-AT-4Training records24
NIST800-AT-6Training feedback6
NIST800-AU-1Policy and procedures for audit and accountability19
NIST800-AU-10Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined]17
NIST800-AU-11Audit record retention26
NIST800-AU-12Audit record generation61
NIST800-AU-13Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an inform18
NIST800-AU-14Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, i6
NIST800-AU-16Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across 7
NIST800-AU-2Event logging67
NIST800-AU-3Content of audit records55
NIST800-AU-4Audit log storage capacity17
NIST800-AU-5Response to audit logging process failures15
NIST800-AU-6Audit record review, analysis, and reporting40
NIST800-AU-7Audit record reduction and report generation15
NIST800-AU-8Time stamps17
NIST800-AU-9Protection of audit information22
NIST800-CA-1Policy and procedures for assessment, authorization, and monitoring22
NIST800-CA-2Control assessments42
NIST800-CA-3Information exchange28
NIST800-CA-5Plan of action and milestones38
NIST800-CA-6Authorization22
NIST800-CA-7Continuous monitoring77
NIST800-CA-8Penetration testing61
NIST800-CA-9Internal system connections17
NIST800-CM-1Policy and procedures for configuration management23
NIST800-CM-10Software usage restrictions21
NIST800-CM-11User-installed software25
NIST800-CM-12Information Location. Identify and document the location of [organization-defined] and the specific system components on which the information is processed and stored; Identify and21
NIST800-CM-13Data Action Mapping. Develop and document a map of system data actions11
NIST800-CM-14Signed Components. Prevent the installation of [organization-defined] without verification that the component has been digitally signed using a certificate that is recognized and a16
NIST800-CM-2Baseline configuration29
NIST800-CM-3Configuration change control56
NIST800-CM-4Impact analyses60
NIST800-CM-5Access restrictions for change22
NIST800-CM-6Configuration settings37
NIST800-CM-7Least functionality28
NIST800-CM-8System component inventory41
NIST800-CM-9Configuration management plan58
NIST800-CP-1Policy and procedures for contingency planning24
NIST800-CP-10System recovery and reconstitution72
NIST800-CP-11Alternate Communications Protocols. Provide the capability to employ [organization-defined] in support of maintaining continuity of operations14
NIST800-CP-12Safe Mode. When [organization-defined] are detected, enter a safe mode of operation with [organization-defined]3
NIST800-CP-13Alternative Security Mechanisms. Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or 6
NIST800-CP-2Contingency plan29
NIST800-CP-3Contingency training19
NIST800-CP-4Contingency plan testing27
NIST800-CP-6Alternate storage site20
NIST800-CP-7Alternate processing site17
NIST800-CP-8Telecommunications services18
NIST800-CP-9System backup78
NIST800-IA-1Policy and procedures for identification and authentication19
NIST800-IA-10Adaptive Authentication. Require individuals accessing the system to employ [organization-defined] under specific [organization-defined]7
NIST800-IA-11Re-authentication16
NIST800-IA-12Identity proofing14
NIST800-IA-13Identity Providers and Authorization Servers. Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and ac12
NIST800-IA-2Identification and authentication of organizational users36
NIST800-IA-3Device identification and authentication21
NIST800-IA-4Identifier management78
NIST800-IA-5Authenticator management32
NIST800-IA-6Authentication feedback10
NIST800-IA-7Cryptographic module authentication107
NIST800-IA-8Identification and authentication of non-organizational users76
NIST800-IA-9Service Identification and Authentication. Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or ap15
NIST800-IR-1Policy and procedures for incident response24
NIST800-IR-2Incident response training103
NIST800-IR-3Incident response testing24
NIST800-IR-4Incident handling46
NIST800-IR-5Incident monitoring114
NIST800-IR-6Incident reporting40
NIST800-IR-7Incident response assistance104
NIST800-IR-8Incident response plan35
NIST800-IR-9Information Spillage Response. Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific13
NIST800-MA-1Policy and procedures for maintenance17
NIST800-MA-2Controlled maintenance21
NIST800-MA-3Maintenance tools12
NIST800-MA-4Nonlocal maintenance22
NIST800-MA-5Maintenance personnel16
NIST800-MA-6Timely Maintenance. Obtain maintenance support and/or spare parts for [organization-defined] within [organization-defined] of failure13
NIST800-MA-7Field Maintenance. Restrict or prohibit field maintenance on [organization-defined] to [organization-defined]5
NIST800-MP-1Policy and procedures for media protection20
NIST800-MP-2Media access21
NIST800-MP-3Media marking17
NIST800-MP-4Media storage24
NIST800-MP-5Media transport22
NIST800-MP-6Media sanitization33
NIST800-MP-7Media use19
NIST800-MP-8Media Downgrading. Establish [organization-defined] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category or classifica4
NIST800-PE-1Policy and procedures for physical and environmental protection23
NIST800-PE-10Emergency shutoff10
NIST800-PE-11Emergency power11
NIST800-PE-12Emergency lighting9
NIST800-PE-13Fire protection12
NIST800-PE-14Environmental controls33
NIST800-PE-15Water damage protection11
NIST800-PE-16Delivery and Removal. Authorize and control [organization-defined] entering and exiting the facility; and Maintain records of the system components18
NIST800-PE-17Alternate work site18
NIST800-PE-18Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthori11
NIST800-PE-19Information Leakage. Protect the system from information leakage due to electromagnetic signals emanations3
NIST800-PE-2Physical access authorizations76
NIST800-PE-20Asset Monitoring and Tracking. Employ [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined]13
NIST800-PE-21Electromagnetic Pulse Protection. Employ [organization-defined] against electromagnetic pulse damage for [organization-defined]0
NIST800-PE-22Component Marking. Mark [organization-defined] indicating the impact level or classification level of the information permitted to be processed, stored, or transmitted by the hardw7
NIST800-PE-23Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the phys11
NIST800-PE-3Physical access control45
NIST800-PE-4Access control for transmission12
NIST800-PE-5Access control for output devices12
NIST800-PE-6Monitoring physical access21
NIST800-PE-8Visitor access records17
NIST800-PE-9Power equipment and cabling12
NIST800-PL-1Policy and procedures for planning25
NIST800-PL-10Baseline selection19
NIST800-PL-11Baseline tailoring16
NIST800-PL-2System security and privacy plans34
NIST800-PL-4Rules of behavior25
NIST800-PL-7Concept of Operations. Develop a Concept of Operations (CONOPS) for the system describing how the organization intends to operate the system from the perspective of information sec7
NIST800-PL-8Security and privacy architectures25
NIST800-PL-9Central Management. Centrally manage [organization-defined]9
NIST800-PM-1Information Security Program Plan. Develop and disseminate an organization-wide information security program plan that: Provides an overview of the requirements for the security pr21
NIST800-PM-10Authorization Process. Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes; Designat10
NIST800-PM-11Mission and Business Process Definition. Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to orga17
NIST800-PM-12Insider Threat Program. Implement an insider threat program that includes a cross-discipline insider threat incident handling team15
NIST800-PM-13Security and Privacy Workforce. Establish a security and privacy workforce development and improvement program17
NIST800-PM-14Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities assoc21
NIST800-PM-15Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitat12
NIST800-PM-16Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence13
NIST800-PM-17Protecting Controlled Unclassified Information on External Systems. Establish policy and procedures to ensure that requirements for the protection of controlled unclassified inform10
NIST800-PM-18Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of th12
NIST800-PM-19Privacy Program Leadership Role. Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, appl13
NIST800-PM-2Information Security Program Leadership Role. Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an22
NIST800-PM-20Dissemination of Privacy Program Information. Maintain a central resource webpage on the organization's principal public website that serves as a central source of information abou10
NIST800-PM-21Accounting of Disclosures. Develop and maintain an accurate accounting of disclosures of personally identifiable information, including: Date, nature, and purpose of each disclosur15
NIST800-PM-22Personally Identifiable Information Quality Management. Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and c14
NIST800-PM-23Data Governance Body. Establish a Data Governance Body consisting of [organization-defined] with [organization-defined]14
NIST800-PM-24Data Integrity Board. Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching programs i5
NIST800-PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of person11
NIST800-PM-26Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practice11
NIST800-PM-27Privacy Reporting. Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; 12
NIST800-PM-28Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk m23
NIST800-PM-29Risk Management Program Leadership Roles. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes wi14
NIST800-PM-3Information Security and Privacy Resources. Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and 11
NIST800-PM-30Supply Chain Risk Management Strategy. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal23
NIST800-PM-31Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following or30
NIST800-PM-32Purposing. Analyze [organization-defined] supporting mission essential services or functions to ensure that the information resources are being used consistent with their intended 7
NIST800-PM-4Plan of Action and Milestones Process. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management pro22
NIST800-PM-5System Inventory. Develop and update [organization-defined] an inventory of organizational systems18
NIST800-PM-6Measures of Performance. Develop, monitor, and report on the results of information security and privacy measures of performance17
NIST800-PM-7Enterprise Architecture. Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations a6
NIST800-PM-8Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protect5
NIST800-PM-9Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation assoc21
NIST800-PS-1Policy and procedures for personnel security28
NIST800-PS-2Position risk designation13
NIST800-PS-3Personnel screening34
NIST800-PS-4Personnel termination25
NIST800-PS-5Personnel transfer20
NIST800-PS-6Access agreements22
NIST800-PS-7External personnel security25
NIST800-PS-8Personnel sanctions35
NIST800-PS-9Position descriptions20
NIST800-PT-1Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy t15
NIST800-PT-2Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable infor14
NIST800-PT-3Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s14
NIST800-PT-4Consent. Implement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individu12
NIST800-PT-5Privacy Notice. Provide notice to individuals about the processing of personally identifiable information that: Is available to individuals upon first interacting with an organizat16
NIST800-PT-6System of Records Notice. For systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OMB gu4
NIST800-PT-7Specific Categories of Personally Identifiable Information. Apply [organization-defined] for specific categories of personally identifiable information8
NIST800-PT-8Computer Matching Requirements. When a system or organization processes information for the purpose of conducting a matching program: Obtain approval from the Data Integrity Board 4
NIST800-RA-1Policy and procedures for risk assessment112
NIST800-RA-10Threat hunting12
NIST800-RA-2Security categorization130
NIST800-RA-3Risk assessment48
NIST800-RA-5Vulnerability monitoring and scanning125
NIST800-RA-6Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined]1
NIST800-RA-7Risk response29
NIST800-RA-8Privacy Impact Assessments. Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pers13
NIST800-RA-9Criticality analysis23
NIST800-SA-1Policy and procedures for system and services acquisition18
NIST800-SA-10Developer configuration management55
NIST800-SA-11Developer testing and evaluation28
NIST800-SA-15Development process, standards, and tools21
NIST800-SA-16Developer-provided Training. Require the developer of the system, system component, or system service to provide the following training on the correct use and operation of the impl9
NIST800-SA-17Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and 21
NIST800-SA-2Allocation of resources8
NIST800-SA-20Customized Development of Critical Components. Reimplement or custom develop the following critical system components: [organization-defined]4
NIST800-SA-21Developer Screening. Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Satisfies th13
NIST800-SA-22Unsupported System Components25
NIST800-SA-23Specialization. Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those systems or compo0
NIST800-SA-24Design For Cyber Resiliency. Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [or9
NIST800-SA-3System development life cycle25
NIST800-SA-4Acquisition process33
NIST800-SA-5System documentation19
NIST800-SA-8Security and privacy engineering principles30
NIST800-SA-9External system services36
NIST800-SC-1Policy and procedures for system and communications protection18
NIST800-SC-10Network disconnect11
NIST800-SC-11Trusted Path. Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users t1
NIST800-SC-12Cryptographic key establishment and management101
NIST800-SC-13Cryptographic protection108
NIST800-SC-15Collaborative computing devices and applications4
NIST800-SC-16Transmission of Security and Privacy Attributes. Associate [organization-defined] with information exchanged between systems and between system components7
NIST800-SC-17Public key infrastructure certificates17
NIST800-SC-18Mobile Code. Define acceptable and unacceptable mobile code and mobile code technologies; and Authorize, monitor, and control the use of mobile code within the system17
NIST800-SC-2Separation of system and user functionality16
NIST800-SC-20Secure name/address resolution service8
NIST800-SC-21Secure name/address resolution service (recursive)3
NIST800-SC-22Architecture and provisioning for name/address resolution service33
NIST800-SC-23Session authenticity17
NIST800-SC-24Fail in Known State. Fail to a [organization-defined] for the following failures on the indicated components while preserving [organization-defined] in failure: [organization-defin6
NIST800-SC-25Thin Nodes. Employ minimal functionality and information storage on the following system components: [organization-defined]3
NIST800-SC-26Decoys. Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks3
NIST800-SC-27Platform-independent Applications. Include within organizational systems the following platform independent applications: [organization-defined]1
NIST800-SC-28Protection of information at rest34
NIST800-SC-29Heterogeneity. Employ a diverse set of information technologies for the following system components in the implementation of the system: [organization-defined]2
NIST800-SC-3Security Function Isolation. Isolate security functions from nonsecurity functions15
NIST800-SC-30Concealment and Misdirection. Employ the following concealment and misdirection techniques for [organization-defined] at [organization-defined] to confuse and mislead adversaries: 3
NIST800-SC-31Covert Channel Analysis. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [organization-defined5
NIST800-SC-32System Partitioning. Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined]17
NIST800-SC-34Non-modifiable Executable Programs. For [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications9
NIST800-SC-35External Malicious Code Identification. Include system components that proactively seek to identify network-based malicious code or malicious websites13
NIST800-SC-36Distributed Processing and Storage. Distribute the following processing and storage components across multiple [organization-defined]: [organization-defined]5
NIST800-SC-37Out-of-band Channels. Employ the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [organizat2
NIST800-SC-38Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined11
NIST800-SC-39Process isolation12
NIST800-SC-4Information in shared system resources15
NIST800-SC-40Wireless Link Protection. Protect external and internal [organization-defined] from the following signal parameter attacks: [organization-defined]9
NIST800-SC-41Port and I/O Device Access. [organization-defined] disable or remove [organization-defined] on the following systems or system components: [organization-defined]8
NIST800-SC-42Sensor Capability and Data. Prohibit [organization-defined] ; and Provide an explicit indication of sensor use to [organization-defined]9
NIST800-SC-43Usage Restrictions. Establish usage restrictions and implementation guidelines for the following system components: [organization-defined] ; and Authorize, monitor, and control the10
NIST800-SC-44Detonation Chambers. Employ a detonation chamber capability within [organization-defined]3
NIST800-SC-45System Time Synchronization. Synchronize system clocks within and between systems and system components13
NIST800-SC-46Cross Domain Policy Enforcement. Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains12
NIST800-SC-47Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control11
NIST800-SC-48Sensor Relocation. Relocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined]0
NIST800-SC-49Hardware-enforced Separation and Policy Enforcement. Implement hardware-enforced separation and policy enforcement mechanisms between [organization-defined]7
NIST800-SC-5Denial-of-service protection19
NIST800-SC-50Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined]7
NIST800-SC-51Hardware-based Protection. Employ hardware-based, write-protect for [organization-defined] ; and Implement specific procedures for [organization-defined] to manually disable hardwa2
NIST800-SC-6Resource Availability. Protect the availability of resources by allocating [organization-defined] by [organization-defined]14
NIST800-SC-7Boundary protection39
NIST800-SC-8Transmission confidentiality and integrity35
NIST800-SI-1Policy and procedures for system and information integrity20
NIST800-SI-10Information input validation16
NIST800-SI-11Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages o10
NIST800-SI-12Information management and retention33
NIST800-SI-13Predictable Failure Prevention. Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [organization-defined] ; and Provid4
NIST800-SI-14Non-persistence. Implement non-persistent [organization-defined] that are initiated in a known state and terminated [organization-defined]5
NIST800-SI-15Information Output Filtering. Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected co4
NIST800-SI-16Memory protection10
NIST800-SI-17Fail-safe Procedures. Implement the indicated fail-safe procedures when the indicated failures occur: [organization-defined]5
NIST800-SI-18Personally Identifiable Information Quality Operations. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information li15
NIST800-SI-19De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectivenes14
NIST800-SI-2Flaw remediation74
NIST800-SI-20Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organizat6
NIST800-SI-21Information Refresh. Refresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed6
NIST800-SI-22Information Diversity. Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and Use an alternative information source for 3
NIST800-SI-23Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the follow0
NIST800-SI-3Malicious code protection32
NIST800-SI-4System monitoring43
NIST800-SI-5Security alerts, advisories, and directives31
NIST800-SI-6Security and Privacy Function Verification. Verify the correct operation of [organization-defined]; Perform the verification of the functions specified in SI-6a [organization-defin15
NIST800-SI-7Software, firmware, and information integrity26
NIST800-SI-8Spam Protection. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and Update spam protection mechanisms when new release16
NIST800-SR-1Policy and procedures for supply chain risk management19
NIST800-SR-10Inspection of systems or components16
NIST800-SR-11Component authenticity109
NIST800-SR-12Component disposal12
NIST800-SR-2Supply chain risk management plan25
NIST800-SR-3Supply chain controls and processes124
NIST800-SR-4Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined]19
NIST800-SR-5Acquisition strategies, tools, and methods24
NIST800-SR-6Supplier assessments and reviews29
NIST800-SR-7Supply Chain Operations Security. Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system 10
NIST800-SR-8Notification agreements112
NIST800-SR-9Tamper Resistance and Detection. Implement a tamper protection program for the system, system component, or system service10
SP800-53-ACAccess Control Family4
SP800-53-ATAwareness and Training Family14
SP800-53-AUAudit and Accountability Family8
SP800-53-CAAssessment, Authorization, and Monitoring Family6
SP800-53-CMConfiguration Management Family8
SP800-53-CPContingency Planning Family8
SP800-53-IAIdentification and Authentication Family8
SP800-53-IRIncident Response Family8
SP800-53-MAMaintenance Family4
SP800-53-MPMedia Protection Family3
SP800-53-PEPhysical and Environmental Protection Family14
SP800-53-PLPlanning Family7
SP800-53-PMProgram Management Family8
SP800-53-PSPersonnel Security Family9
SP800-53-PTPII Processing and Transparency Family6
SP800-53-RARisk Assessment Family18
SP800-53-SASystem and Services Acquisition Family10
SP800-53-SCSystem and Communications Protection Family6
SP800-53-SISystem and Information Integrity Family7
SP800-53-SRSupply Chain Risk Management Family10

Tell me when NIST SP 800-53 Rev 5 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Identity proofing records aligned to NIST SP 800-63A
  • MFA enforcement evidence per system
  • Authenticator management procedures
  • Device authentication configurations
  • Federation agreements
  • Authentication configuration
  • Incident response plan
  • Incident response plan and playbooks
  • Tabletop and functional exercise records
  • Incident reporting metrics

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-53 Rev 5, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition