Back to Frameworks

NIST SP 800-53A Rev. 5

United States
vRev 5
19 domains
48 controls

Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Guideline for Conducting Security Assessments

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (19)

Assessment Governance

1 controls
Controls in the Assessment Governance domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-ASSESSOR-INDEPEstablish Assessor Independence

Assessment Methods

4 controls
Controls in the Assessment Methods domain of NIST SP 800-53A Rev. 54 controls
CodeTitle
53A-METHOD-EXAMINEApply the Examine Assessment Method
53A-METHOD-INTERVIEWApply the Interview Assessment Method
53A-METHOD-TESTApply the Test Assessment Method
53A-SAMPLINGApply Sampling for Population Assessments

Assessment Planning

2 controls
Controls in the Assessment Planning domain of NIST SP 800-53A Rev. 52 controls
CodeTitle
53A-ASMT-PLANDevelop a Security and Privacy Assessment Plan
53A-OBJECT-INVENTORYIdentify Assessment Objects

Assessment Procedures

1 controls
Controls in the Assessment Procedures domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-OBJECTIVEDefine Assessment Objectives and Determination Statements

Assessment Rigor

1 controls
Controls in the Assessment Rigor domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-DEPTH-COVERAGEDetermine Assessment Depth and Coverage

Automation

1 controls
Controls in the Automation domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-AUTOMATED-EVIDUse Automated Evidence Collection

Control Inheritance

1 controls
Controls in the Control Inheritance domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-CONTROL-INHERITAssess Inherited and Hybrid Controls

Evidence Management

1 controls
Controls in the Evidence Management domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-EVIDENCE-CHAINMaintain Evidence Chain of Custody

NIST SP 800-53A: Access Control & Identity

6 controls

Managing access to information systems (NIST SP 800-53A)

Controls in the NIST SP 800-53A: Access Control & Identity domain of NIST SP 800-53A Rev. 56 controls
CodeTitle
SP800-53A-METHOD-EXAMINEAssessment Method: Examine
SP800-53A-METHOD-INTERVIEWAssessment Method: Interview
SP800-53A-METHOD-TESTAssessment Method: Test
SP800-53A-OBJECTSAssessment Objects
SP800-53A-STEP-PLANDevelop Security and Privacy Assessment Plans
SP800-53A-STEP-PREPAREPrepare for Control Assessments

NIST SP 800-53A: Audit & Accountability

3 controls

Audit logging and accountability measures (NIST SP 800-53A)

Controls in the NIST SP 800-53A: Audit & Accountability domain of NIST SP 800-53A Rev. 53 controls
CodeTitle
SP800-53A-FAM-SCAssessment Procedures: System and Communications Protection (SC)
SP800-53A-FAM-SIAssessment Procedures: System and Information Integrity (SI)
SP800-53A-FAM-SRAssessment Procedures: Supply Chain Risk Management (SR)

NIST SP 800-53A: Configuration Management

5 controls

Managing system configurations securely (NIST SP 800-53A)

Controls in the NIST SP 800-53A: Configuration Management domain of NIST SP 800-53A Rev. 55 controls
CodeTitle
SP800-53A-FAM-PMAssessment Procedures: Program Management (PM)
SP800-53A-FAM-PSAssessment Procedures: Personnel Security (PS)
SP800-53A-FAM-PTAssessment Procedures: PII Processing and Transparency (PT)
SP800-53A-FAM-RAAssessment Procedures: Risk Assessment (RA)
SP800-53A-FAM-SAAssessment Procedures: System and Services Acquisition (SA)

NIST SP 800-53A: Incident Response

5 controls

Detecting and responding to security incidents (NIST SP 800-53A)

Controls in the NIST SP 800-53A: Incident Response domain of NIST SP 800-53A Rev. 55 controls
CodeTitle
SP800-53A-FAM-IRAssessment Procedures: Incident Response (IR)
SP800-53A-FAM-MAAssessment Procedures: Maintenance (MA)
SP800-53A-FAM-MPAssessment Procedures: Media Protection (MP)
SP800-53A-FAM-PEAssessment Procedures: Physical and Environmental Protection (PE)
SP800-53A-FAM-PLAssessment Procedures: Planning (PL)

NIST SP 800-53A: Risk Assessment & Management

5 controls

Identifying and managing cybersecurity risks (NIST SP 800-53A)

Controls in the NIST SP 800-53A: Risk Assessment & Management domain of NIST SP 800-53A Rev. 55 controls
CodeTitle
SP800-53A-FAM-AUAssessment Procedures: Audit and Accountability (AU)
SP800-53A-FAM-CAAssessment Procedures: Assessment, Authorization, and Monitoring (CA)
SP800-53A-FAM-CMAssessment Procedures: Configuration Management (CM)
SP800-53A-FAM-CPAssessment Procedures: Contingency Planning (CP)
SP800-53A-FAM-IAAssessment Procedures: Identification and Authentication (IA)

NIST SP 800-53A: System & Communications Protection

6 controls

Protecting systems and communications (NIST SP 800-53A)

Controls in the NIST SP 800-53A: System & Communications Protection domain of NIST SP 800-53A Rev. 56 controls
CodeTitle
SP800-53A-FAM-ACAssessment Procedures: Access Control (AC)
SP800-53A-FAM-ATAssessment Procedures: Awareness and Training (AT)
SP800-53A-STEP-ANALYZEAnalyze Assessment Report Results
SP800-53A-STEP-CAPABILITYAssess Security and Privacy Capabilities
SP800-53A-STEP-CONDUCTConduct Control Assessments
SP800-53A-STEP-SELECTSelect and Tailor Assessment Procedures

Ongoing Assessment

1 controls
Controls in the Ongoing Assessment domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-CONTINUOUSSupport Continuous Control Monitoring

Privacy Assessment

1 controls
Controls in the Privacy Assessment domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-PRIVACY-ASMTAssess Privacy Controls

Remediation Validation

1 controls
Controls in the Remediation Validation domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-RETESTRetest After Remediation

Reporting

2 controls
Controls in the Reporting domain of NIST SP 800-53A Rev. 52 controls
CodeTitle
53A-FINDINGSDocument Assessment Findings and Recommendations
53A-SARProduce Security and Privacy Assessment Report

Supply Chain

1 controls
Controls in the Supply Chain domain of NIST SP 800-53A Rev. 51 controls
CodeTitle
53A-SUPPLY-CHAINAssess Supply Chain Risk Management Controls

Maps to 1 other framework

48 total controls
NIST SP 800-53 Rev 5
30 source controls mapped|22 target controls covered
63%

Frequently Asked Questions

What is NIST SP 800-53A Rev. 5?

NIST SP 800-53A Rev. 5 is a compliance framework from United States with 19 domains and 48 controls. Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Guideline for Conducting Security Assessments It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-53A Rev. 5 have?

NIST SP 800-53A Rev. 5 has 48 controls organised across 19 domains. The largest domains are NIST SP 800-53A: Access Control & Identity (6 controls), NIST SP 800-53A: System & Communications Protection (6 controls), NIST SP 800-53A: Configuration Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-53A Rev. 5 map to?

NIST SP 800-53A Rev. 5 maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-53A Rev. 5 compliance?

Start your NIST SP 800-53A Rev. 5 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-53A Rev. 5 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required