Back to Frameworks

NIST SP 800-150

United States
v2016
12 domains
35 controls

Guide to Cyber Threat Information Sharing

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (12)

Establishing Sharing Relationships

3 controls
Controls in the Establishing Sharing Relationships domain of NIST SP 800-1503 controls
CodeTitle
TIS-1Threat Information Sharing Goals and Objectives
TIS-2Roles and Responsibilities for Threat Sharing
TIS-3Threat Information Sharing Plan

Information Acquisition

3 controls
Controls in the Information Acquisition domain of NIST SP 800-1503 controls
CodeTitle
TIS-7Threat Information Sources and Feeds
TIS-8Threat Information Production and Curation
TIS-9Indicator and Observable Management

Information Dissemination

3 controls
Controls in the Information Dissemination domain of NIST SP 800-1503 controls
CodeTitle
TIS-10Threat Information Sharing Channels
TIS-11Trust Establishment with Sharing Partners
TIS-12Anonymisation and Attribution Controls

Information Use

2 controls
Controls in the Information Use domain of NIST SP 800-1502 controls
CodeTitle
TIS-13Consumption and Integration of Threat Information
TIS-14Feedback to Producers and Communities

NIST SP 800-150: Access Control

5 controls

Logical and physical access controls (NIST SP 800-150)

Controls in the NIST SP 800-150: Access Control domain of NIST SP 800-1505 controls
CodeTitle
SP800-150-ALERTSConsume and Respond to Security Alerts
SP800-150-COMMUNICATEEngage in Ongoing Communication
SP800-150-INDICATORS-USEConsume and Use Indicators
SP800-150-JOINJoin a Sharing Community
SP800-150-SUPPORTPlan for Ongoing Support

NIST SP 800-150: Asset Management

5 controls

Information asset management (NIST SP 800-150)

Controls in the NIST SP 800-150: Asset Management domain of NIST SP 800-1505 controls
CodeTitle
SP800-150-DESIGNATIONSSharing Designations
SP800-150-EXTERNALIdentify External Sources of Cyber Threat Information
SP800-150-PROCEDURESSharing and Tracking Procedures
SP800-150-RULESEstablish Information Sharing Rules
SP800-150-SENSITIVITYInformation Sensitivity and Privacy

NIST SP 800-150: Communications Security

0 controls

Network and communications security (NIST SP 800-150)

NIST SP 800-150: Cryptography

2 controls

Cryptographic controls (NIST SP 800-150)

Controls in the NIST SP 800-150: Cryptography domain of NIST SP 800-1502 controls
CodeTitle
SP800-150-PRODUCEProduce and Publish Indicators
SP800-150-STOREOrganize and Store Cyber Threat Information

NIST SP 800-150: Information Security Policies

5 controls

Organizational information security policies (NIST SP 800-150)

Controls in the NIST SP 800-150: Information Security Policies domain of NIST SP 800-1505 controls
CodeTitle
SP800-150-BENEFITSBenefits of Information Sharing
SP800-150-CHALLENGESChallenges to Information Sharing
SP800-150-GOALSDefine Information Sharing Goals and Objectives
SP800-150-INFO-TYPESThreat Information Types
SP800-150-INTERNALIdentify Internal Sources of Cyber Threat Information

NIST SP 800-150: Operations Security

0 controls

Secure operations and monitoring (NIST SP 800-150)

Pre-Sharing Considerations

3 controls
Controls in the Pre-Sharing Considerations domain of NIST SP 800-1503 controls
CodeTitle
TIS-4Legal, Regulatory, and Contractual Review
TIS-5Information Handling and Sensitivity Marking
TIS-6Data Minimisation and Sanitisation

Programme Operations

4 controls
Controls in the Programme Operations domain of NIST SP 800-1504 controls
CodeTitle
TIS-15Operational Security of Sharing Activities
TIS-16Threat Sharing Programme Metrics
TIS-17Incident-Driven Sharing
TIS-18Continuous Improvement and Programme Review

Maps to 1 other framework

35 total controls
NIST SP 800-53 Rev 5
17 source controls mapped|6 target controls covered
49%

Frequently Asked Questions

What is NIST SP 800-150?

NIST SP 800-150 is a compliance framework from United States with 12 domains and 35 controls. Guide to Cyber Threat Information Sharing It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-150 have?

NIST SP 800-150 has 35 controls organised across 12 domains. The largest domains are NIST SP 800-150: Access Control (5 controls), NIST SP 800-150: Asset Management (5 controls), NIST SP 800-150: Information Security Policies (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-150 map to?

NIST SP 800-150 maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (49% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-150 compliance?

Start your NIST SP 800-150 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-150 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required