United States

NIST SP 800-53 Revision 5.1 HIGH

317 controls. 299 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

317 controls 299 frameworks share controls with it United States held in the corpus

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
AC-1Policy and Procedures20
AC-10Concurrent Session Control0
AC-11Device Lock12
AC-11(1)Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image8
AC-12Session Termination10
AC-14Permitted Actions Without Identification or Authentication3
AC-17Remote Access20
AC-17(1)Monitoring and Control13
AC-17(2)Protection of Confidentiality and Integrity Using Encryption16
AC-17(3)Managed Access Control Points16
AC-17(4)Privileged Commands and Access12
AC-18Wireless Access9
AC-18(1)Authentication and Encryption10
AC-18(3)Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployme7
AC-19Access Control for Mobile Devices16
AC-19(5)Full Device or Container-Based Encryption14
AC-2Account Management95
AC-2(1)Automated System Account Management9
AC-2(11)Usage Conditions0
AC-2(12)Account Monitoring for Atypical Usage15
AC-2(13)Disable Accounts for High-Risk Individuals13
AC-2(2)Automated Temporary and Emergency Account Management10
AC-2(3)Disable Accounts19
AC-2(4)Automated Audit Actions12
AC-2(5)Inactivity Logout12
AC-20Use of External Systems17
AC-20(1)Limits on Authorized Use14
AC-20(2)Portable Storage Devices Restricted Use13
AC-21Information Sharing14
AC-22Publicly Accessible Content11
AC-3Access Enforcement36
AC-4Information Flow Enforcement22
AC-4(4)Flow Control of Encrypted Information0
AC-5Separation of Duties19
AC-6Least Privilege26
AC-6(1)Authorize Access to Security Functions14
AC-6(10)Prohibit Non-Privileged Users from Executing Privileged Functions15
AC-6(2)Non-Privileged Access for Nonsecurity Functions15
AC-6(3)Network Access to Privileged Commands0
AC-6(5)Privileged Accounts16
AC-6(7)Review of User Privileges20
AC-6(9)Log Use of Privileged Functions14
AC-7Unsuccessful Logon Attempts14
AC-8System Use Notification5
AT-1Policy and Procedures17
AT-2Literacy Training and Awareness31
AT-2(2)Insider Threat13
AT-2(3)Social Engineering and Mining13
AT-3Role-Based Training29
AT-4Training Records19
AU-1Policy and Procedures15
AU-10Non-Repudiation0
AU-11Audit Record Retention16
AU-12Audit Record Generation23
AU-12(1)System-wide and Time-correlated Audit Trail0
AU-12(3)Changes by Authorized Individuals0
AU-2Event Logging23
AU-3Content of Audit Records19
AU-3(1)Additional Audit Information12
AU-4Audit Log Storage Capacity12
AU-5Response to Audit Logging Process Failures11
AU-5(1)Storage Capacity Warning0
AU-5(2)Real-Time Alerts0
AU-6Audit Record Review, Analysis, and Reporting27
AU-6(1)Automated Process Integration18
AU-6(3)Correlate Audit Record Repositories18
AU-6(5)Integrated Analysis of Audit Records0
AU-6(6)Correlation with Physical Monitoring0
AU-7Audit Record Reduction and Report Generation12
AU-7(1)Automatic Processing12
AU-8Time Stamps12
AU-9Protection of Audit Information18
AU-9(2)Store on Separate Physical Systems or Components0
AU-9(3)Cryptographic Protection0
AU-9(4)Access by Subset of Privileged Users13
CA-1Policy and Procedures18
CA-2Control Assessments33
CA-2(1)Independent Assessors23
CA-3Information Exchange18
CA-5Plan of Action and Milestones30
CA-6Authorization19
CA-7Continuous Monitoring33
CA-7(1)Independent Assessment13
CA-7(4)Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring;17
CA-8Penetration Testing65
CA-9Internal System Connections163
CM-1Policy and Procedures13
CM-10Software Usage Restrictions17
CM-11User-Installed Software22
CM-12Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is process20
CM-12(1)Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assig11
CM-2Baseline Configuration19
CM-2(2)Automation Support for Accuracy and Currency12
CM-2(3)Retention of Previous Configurations11
CM-2(7)Configure Systems and Components for High-Risk Areas5
CM-3Configuration Change Control18
CM-3(1)Automated Documentation, Notification, and Prohibition0
CM-3(2)Testing, Validation, and Documentation of Changes14
CM-3(4)Security and Privacy Representatives9
CM-3(6)Cryptography Management1
CM-4Impact Analyses17
CM-4(2)Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outc14
CM-5Access Restrictions for Change19
CM-5(1)Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and 14
CM-6Configuration Settings23
CM-7Least Functionality20
CM-7(1)Periodic Review17
CM-7(2)Prevent Program Execution16
CM-7(5)Authorized Software Allow-by-Exception18
CM-8System Component Inventory26
CM-8(1)Updates During Installation and Removal13
CM-8(3)Automated Unauthorized Component Detection14
CM-8(4)Accountability Information1
CM-9Configuration Management Plan14
CP-1Policy and Procedures17
CP-10System Recovery and Reconstitution21
CP-10(2)System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based7
CP-10(4)Restore Within Time Period0
CP-2Contingency Plan24
CP-2(1)Coordinate with Related Plans10
CP-2(2)Capacity Planning0
CP-2(3)Resume Mission and Business Functions13
CP-2(5)Continue Mission and Business Functions0
CP-2(8)Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions15
CP-3Contingency Training15
CP-3(1)Simulated Events0
CP-4Contingency Plan Testing24
CP-4(1)Coordinate with Related Plans12
CP-4(2)Alternate Processing Site0
CP-6Alternate Storage Site18
CP-6(1)Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to t9
CP-6(2)Recovery Time and Recovery Point Objectives0
CP-6(3)Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline expl5
CP-7Alternate Processing Site15
CP-7(1)Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibi6
CP-7(2)Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines 7
CP-7(3)Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requiremen6
CP-7(4)Preparation for Use0
CP-8Telecommunications Services10
CP-8(1)Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in6
CP-8(2)Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary tele9
CP-8(3)Separation of Primary and Alternate Providers0
CP-8(4)Provider Contingency Plan0
CP-9System Backup23
CP-9(1)Testing for Reliability and Integrity19
CP-9(2)Test Restoration Using Sampling0
CP-9(3)Separate Storage for Critical Information0
CP-9(5)Transfer to Alternate Storage Site0
CP-9(8)System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup informa16
IA-1Policy and Procedures13
IA-10Adaptive Authentication0
IA-11Re-Authentication11
IA-12Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable10
IA-2Identification and Authentication (Organizational Users)24
IA-3Device Identification and Authentication16
IA-4Identifier Management22
IA-5Authenticator Management23
IA-6Authentication Feedback8
IA-7Cryptographic Module Authentication10
IA-8Identification and Authentication (Non-Organizational Users)19
IR-1Policy and Procedures19
IR-2Incident Response Training39
IR-3Incident Response Testing23
IR-4Incident Handling68
IR-5Incident Monitoring27
IR-6Incident Reporting31
IR-7Incident Response Assistance16
IR-8Incident Response Plan29
MA-1Policy and Procedures8
MA-2Controlled Maintenance14
MA-3Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-define9
MA-4Nonlocal Maintenance15
MA-5Maintenance Personnel12
MA-6Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of 7
MP-1Policy and Procedures14
MP-2Media Access13
MP-3Media Marking13
MP-4Media Storage17
MP-5Media Transport16
MP-6Media Sanitization25
MP-7Media Use13
PE-1Policy and Procedures14
PE-10Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place em6
PE-11Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate 8
PE-12Emergency Lighting5
PE-13Fire Protection10
PE-14Environmental Controls8
PE-15Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and know7
PE-16Delivery and Removal13
PE-17Alternate Work Site15
PE-18Location of System Components0
PE-19Information Leakage0
PE-2Physical Access Authorizations15
PE-20Asset Monitoring and Tracking0
PE-3Physical Access Control19
PE-4Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [As9
PE-5Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the o10
PE-6Monitoring Physical Access16
PE-8Visitor Access Records12
PE-9Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction8
PL-1Policy and Procedures18
PL-10Baseline Selection. Select a control baseline for the system13
PL-11Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions9
PL-2System Security and Privacy Plans28
PL-4Rules of Behavior19
PL-8Security and Privacy Architectures16
PM-1Information Security Program Plan0
PM-10Authorization Process0
PM-11Mission and Business Process Definition0
PM-12Insider Threat Program0
PM-13Security and Privacy Workforce0
PM-14Testing, Training, and Monitoring0
PM-15Security and Privacy Groups and Associations0
PM-16Threat Awareness Program0
PM-17Protecting CUI on External Systems0
PM-18Privacy Program Plan0
PM-19Privacy Program Leadership Role0
PM-2Information Security Program Leadership Role0
PM-20Dissemination of Privacy Program Information0
PM-21Accounting of Disclosures0
PM-22Personally Identifiable Information Quality Management0
PM-23Data Governance Body0
PM-24Data Integrity Board0
PM-25Minimization of PII Used in Testing, Training, and Research0
PM-26Complaint Management0
PM-27Privacy Reporting0
PM-28Risk Framing0
PM-29Risk Management Program Leadership Roles0
PM-3Information Security and Privacy Resources0
PM-30Supply Chain Risk Management Strategy0
PM-31Continuous Monitoring Strategy0
PM-32Purposing0
PM-4Plan of Action and Milestones Process0
PM-5System Inventory0
PM-6Measures of Performance0
PM-7Enterprise Architecture0
PM-8Critical Infrastructure Plan0
PM-9Risk Management Strategy0
PS-1Policy and Procedures14
PS-2Position Risk Designation10
PS-3Personnel Screening20
PS-4Personnel Termination20
PS-5Personnel Transfer18
PS-6Access Agreements15
PS-7External Personnel Security19
PS-8Personnel Sanctions12
PS-9Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions22
PT-1Policy and Procedures0
PT-2Authority to Process PII0
PT-3PII Processing Purposes0
PT-4Consent0
PT-5Privacy Notice0
PT-6System of Records Notice0
PT-7Specific Categories of PII0
PT-8Computer Matching Requirements0
RA-1Policy and Procedures86
RA-2Security Categorization28
RA-3Risk Assessment33
RA-5Vulnerability Monitoring and Scanning28
RA-7Risk Response11
RA-9Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or sy18
SA-1Policy and Procedures18
SA-10Developer Configuration Management13
SA-11Developer Testing and Evaluation19
SA-15Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitl16
SA-16Developer-Provided Training0
SA-17Developer Security and Privacy Architecture and Design0
SA-2Allocation of Resources11
SA-22Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the fo18
SA-3System Development Life Cycle21
SA-4Acquisition Process22
SA-5System Documentation13
SA-8Security and Privacy Engineering Principles19
SA-9External System Services30
SC-1Policy and Procedures13
SC-10Network Disconnect10
SC-12Cryptographic Key Establishment and Management15
SC-13Cryptographic Protection22
SC-15Collaborative Computing Devices and Applications5
SC-17Public Key Infrastructure Certificates9
SC-18Mobile Code12
SC-2Separation of System and User Functionality13
SC-20Secure Name/Address Resolution Service (Authoritative)5
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)6
SC-22Architecture and Provisioning for Name/Address Resolution Service5
SC-23Session Authenticity17
SC-24Fail in Known State0
SC-28Protection of Information at Rest23
SC-3Security Function Isolation0
SC-39Process Isolation9
SC-4Information in Shared System Resources11
SC-5Denial-of-Service Protection15
SC-7Boundary Protection25
SC-8Transmission Confidentiality and Integrity26
SI-1Policy and Procedures14
SI-10Information Input Validation13
SI-11Error Handling6
SI-12Information Management and Retention26
SI-14Non-persistence0
SI-16Memory Protection8
SI-2Flaw Remediation26
SI-3Malicious Code Protection25
SI-4System Monitoring24
SI-5Security Alerts, Advisories, and Directives23
SI-6Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the10
SI-7Software, Firmware, and Information Integrity18
SI-8Spam Protection12
SR-1Policy and Procedures (SR-1)17
SR-10Inspection of Systems or Components (SR-10)8
SR-11Component Authenticity (SR-11)12
SR-12Component Disposal (SR-12)16
SR-2Supply Chain Risk Management Plan (SR-2)18
SR-3Supply Chain Controls and Processes (SR-3)27
SR-5Acquisition Strategies, Tools, and Methods (SR-5)20
SR-6Supplier Assessments and Reviews (SR-6)26
SR-8Notification Agreements (SR-8)15
SR-9Tamper Resistance and Detection (SR-9)0

Tell me when NIST SP 800-53 Revision 5.1 HIGH files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Lawful basis register per processing
  • Lawful basis register
  • Consent records (explicit + verifiable + withdrawable)
  • Direct marketing opt-in evidence
  • Consent UX
  • Granular preference centre
  • Audit trail of consents
  • Withdrawal mechanism as easy as giving
  • Consent records (granular and withdrawable)
  • Risk monitoring procedure

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-53 Revision 5.1 HIGH, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition