NIST SP 800-53 Rev 5
Security and privacy controls for information systems and organizations
NIST SP 800-53 Rev 5 is a compliance framework from United States with 24 domains and 320 controls that map to 285 other frameworks. The largest domains are SC - System and Communications Protection (47 controls), PM - Program Management (32 controls), AC - Access Control (23 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
AC - Access Control
Policies and procedures for access control
| Code | Title |
|---|---|
| NIST800-AC-1 | Access control policy and procedures |
| NIST800-AC-10 | Concurrent Session Control. Limit the number of concurrent sessions for each [organization-defined] to [organization-defined] |
| NIST800-AC-11 | Device lock |
| NIST800-AC-12 | Session control |
| NIST800-AC-14 | Permitted actions without identification or authentication |
| NIST800-AC-16 | Security and Privacy Attributes. Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission; Ensure that the attribute associations are made and retained with the information; Establish |
| NIST800-AC-17 | Remote access |
| NIST800-AC-18 | Wireless access |
| NIST800-AC-19 | Access control for mobile devices |
| NIST800-AC-2 | Account management |
| NIST800-AC-20 | Use of external systems |
| NIST800-AC-21 | Information Sharing. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information's access and use restrictions for [organization-defined] ; and Employ [organization-defined] to assist users in making information |
| NIST800-AC-22 | Publicly accessible content |
| NIST800-AC-23 | Data Mining Protection. Employ [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining |
| NIST800-AC-24 | Access Control Decisions. [organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement |
| NIST800-AC-25 | Reference Monitor. Implement a reference monitor for [organization-defined] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured |
| NIST800-AC-3 | Access enforcement |
| NIST800-AC-4 | Information flow enforcement |
| NIST800-AC-5 | Separation of duties |
| NIST800-AC-6 | Least privilege |
| NIST800-AC-7 | Unsuccessful logon attempts |
| NIST800-AC-8 | System Use Notification. Display [organization-defined] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that: |
| NIST800-AC-9 | Previous Logon Notification. Notify the user, upon successful logon to the system, of the date and time of the last logon |
AT - Awareness and Training
Security awareness and training programs
| Code | Title |
|---|---|
| NIST800-AT-1 | Policy and procedures for awareness and training |
| NIST800-AT-2 | Literacy training and awareness |
| NIST800-AT-3 | Role-based training |
| NIST800-AT-4 | Training records |
| NIST800-AT-6 | Training feedback |
AU - Audit and Accountability
Audit and accountability controls
| Code | Title |
|---|---|
| NIST800-AU-1 | Policy and procedures for audit and accountability |
| NIST800-AU-10 | Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined] |
| NIST800-AU-11 | Audit record retention |
| NIST800-AU-12 | Audit record generation |
| NIST800-AU-13 | Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [organization-defined] ; and Take the following additional actions: [organization-defined] |
| NIST800-AU-14 | Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and |
| NIST800-AU-16 | Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries |
| NIST800-AU-2 | Event logging |
| NIST800-AU-3 | Content of audit records |
| NIST800-AU-4 | Audit log storage capacity |
| NIST800-AU-5 | Response to audit logging process failures |
| NIST800-AU-6 | Audit record review, analysis, and reporting |
| NIST800-AU-7 | Audit record reduction and report generation |
| NIST800-AU-8 | Time stamps |
| NIST800-AU-9 | Protection of audit information |
CA - Assessment, Authorization, and Monitoring
Security assessment, authorization, and monitoring
| Code | Title |
|---|---|
| NIST800-CA-1 | Policy and procedures for assessment, authorization, and monitoring |
| NIST800-CA-2 | Control assessments |
| NIST800-CA-3 | Information exchange |
| NIST800-CA-5 | Plan of action and milestones |
| NIST800-CA-6 | Authorization |
| NIST800-CA-7 | Continuous monitoring |
| NIST800-CA-8 | Penetration testing |
| NIST800-CA-9 | Internal system connections |
CM - Configuration Management
Configuration management controls
| Code | Title |
|---|---|
| NIST800-CM-1 | Policy and procedures for configuration management |
| NIST800-CM-10 | Software usage restrictions |
| NIST800-CM-11 | User-installed software |
| NIST800-CM-12 | Information Location. Identify and document the location of [organization-defined] and the specific system components on which the information is processed and stored; Identify and document the users who have access to the system and |
| NIST800-CM-13 | Data Action Mapping. Develop and document a map of system data actions |
| NIST800-CM-14 | Signed Components. Prevent the installation of [organization-defined] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization |
| NIST800-CM-2 | Baseline configuration |
| NIST800-CM-3 | Configuration change control |
| NIST800-CM-4 | Impact analyses |
| NIST800-CM-5 | Access restrictions for change |
| NIST800-CM-6 | Configuration settings |
| NIST800-CM-7 | Least functionality |
| NIST800-CM-8 | System component inventory |
| NIST800-CM-9 | Configuration management plan |
CP - Contingency Planning
Contingency planning controls
| Code | Title |
|---|---|
| NIST800-CP-1 | Policy and procedures for contingency planning |
| NIST800-CP-10 | System recovery and reconstitution |
| NIST800-CP-11 | Alternate Communications Protocols. Provide the capability to employ [organization-defined] in support of maintaining continuity of operations |
| NIST800-CP-12 | Safe Mode. When [organization-defined] are detected, enter a safe mode of operation with [organization-defined] |
| NIST800-CP-13 | Alternative Security Mechanisms. Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or compromised |
| NIST800-CP-2 | Contingency plan |
| NIST800-CP-3 | Contingency training |
| NIST800-CP-4 | Contingency plan testing |
| NIST800-CP-6 | Alternate storage site |
| NIST800-CP-7 | Alternate processing site |
| NIST800-CP-8 | Telecommunications services |
| NIST800-CP-9 | System backup |
IA - Identification and Authentication
Identification and authentication controls
| Code | Title |
|---|---|
| NIST800-IA-1 | Policy and procedures for identification and authentication |
| NIST800-IA-10 | Adaptive Authentication. Require individuals accessing the system to employ [organization-defined] under specific [organization-defined] |
| NIST800-IA-11 | Re-authentication |
| NIST800-IA-12 | Identity proofing |
| NIST800-IA-13 | Identity Providers and Authorization Servers. Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance with [organization-defined] using |
| NIST800-IA-2 | Identification and authentication of organizational users |
| NIST800-IA-3 | Device identification and authentication |
| NIST800-IA-4 | Identifier management |
| NIST800-IA-5 | Authenticator management |
| NIST800-IA-6 | Authentication feedback |
| NIST800-IA-7 | Cryptographic module authentication |
| NIST800-IA-8 | Identification and authentication of non-organizational users |
| NIST800-IA-9 | Service Identification and Authentication. Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications |
IR - Incident Response
Incident response controls
| Code | Title |
|---|---|
| NIST800-IR-1 | Policy and procedures for incident response |
| NIST800-IR-2 | Incident response training |
| NIST800-IR-3 | Incident response testing |
| NIST800-IR-4 | Incident handling |
| NIST800-IR-5 | Incident monitoring |
| NIST800-IR-6 | Incident reporting |
| NIST800-IR-7 | Incident response assistance |
| NIST800-IR-8 | Incident response plan |
| NIST800-IR-9 | Information Spillage Response. Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific information involved in the system contamination; Alerting [organization-defined] of the information spill using a |
MA - Maintenance
System maintenance controls
| Code | Title |
|---|---|
| NIST800-MA-1 | Policy and procedures for maintenance |
| NIST800-MA-2 | Controlled maintenance |
| NIST800-MA-3 | Maintenance tools |
| NIST800-MA-4 | Nonlocal maintenance |
| NIST800-MA-5 | Maintenance personnel |
| NIST800-MA-6 | Timely Maintenance. Obtain maintenance support and/or spare parts for [organization-defined] within [organization-defined] of failure |
| NIST800-MA-7 | Field Maintenance. Restrict or prohibit field maintenance on [organization-defined] to [organization-defined] |
MP - Media Protection
Media protection controls
| Code | Title |
|---|---|
| NIST800-MP-1 | Policy and procedures for media protection |
| NIST800-MP-2 | Media access |
| NIST800-MP-3 | Media marking |
| NIST800-MP-4 | Media storage |
| NIST800-MP-5 | Media transport |
| NIST800-MP-6 | Media sanitization |
| NIST800-MP-7 | Media use |
| NIST800-MP-8 | Media Downgrading. Establish [organization-defined] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category or classification of the information; Verify that the system media downgrading process is commensurate with the |
Management
Operational
PE - Physical and Environmental Protection
Physical and environmental protection controls
| Code | Title |
|---|---|
| NIST800-PE-1 | Policy and procedures for physical and environmental protection |
| NIST800-PE-10 | Emergency shutoff |
| NIST800-PE-11 | Emergency power |
| NIST800-PE-12 | Emergency lighting |
| NIST800-PE-13 | Fire protection |
| NIST800-PE-14 | Environmental controls |
| NIST800-PE-15 | Water damage protection |
| NIST800-PE-16 | Delivery and Removal. Authorize and control [organization-defined] entering and exiting the facility; and Maintain records of the system components |
| NIST800-PE-17 | Alternate work site |
| NIST800-PE-18 | Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access |
| NIST800-PE-19 | Information Leakage. Protect the system from information leakage due to electromagnetic signals emanations |
| NIST800-PE-2 | Physical access authorizations |
| NIST800-PE-20 | Asset Monitoring and Tracking. Employ [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined] |
| NIST800-PE-21 | Electromagnetic Pulse Protection. Employ [organization-defined] against electromagnetic pulse damage for [organization-defined] |
| NIST800-PE-22 | Component Marking. Mark [organization-defined] indicating the impact level or classification level of the information permitted to be processed, stored, or transmitted by the hardware component |
| NIST800-PE-23 | Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the physical and environmental hazards in the organizational risk management |
| NIST800-PE-3 | Physical access control |
| NIST800-PE-4 | Access control for transmission |
| NIST800-PE-5 | Access control for output devices |
| NIST800-PE-6 | Monitoring physical access |
| NIST800-PE-8 | Visitor access records |
| NIST800-PE-9 | Power equipment and cabling |
PL - Planning
Security planning controls
| Code | Title |
|---|---|
| NIST800-PL-1 | Policy and procedures for planning |
| NIST800-PL-10 | Baseline selection |
| NIST800-PL-11 | Baseline tailoring |
| NIST800-PL-2 | System security and privacy plans |
| NIST800-PL-4 | Rules of behavior |
| NIST800-PL-7 | Concept of Operations. Develop a Concept of Operations (CONOPS) for the system describing how the organization intends to operate the system from the perspective of information security and privacy; and Review and update the |
| NIST800-PL-8 | Security and privacy architectures |
| NIST800-PL-9 | Central Management. Centrally manage [organization-defined] |
PM - Program Management
| Code | Title |
|---|---|
| NIST800-PM-1 | Information Security Program Plan. Develop and disseminate an organization-wide information security program plan that: Provides an overview of the requirements for the security program and a description of the security program management controls and |
| NIST800-PM-10 | Authorization Process. Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes; Designate individuals to fulfill specific roles and responsibilities within the organizational risk |
| NIST800-PM-11 | Mission and Business Process Definition. Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation; and |
| NIST800-PM-12 | Insider Threat Program. Implement an insider threat program that includes a cross-discipline insider threat incident handling team |
| NIST800-PM-13 | Security and Privacy Workforce. Establish a security and privacy workforce development and improvement program |
| NIST800-PM-14 | Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be |
| NIST800-PM-15 | Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitate ongoing security and privacy education and training for organizational personnel; To |
| NIST800-PM-16 | Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence |
| NIST800-PM-17 | Protecting Controlled Unclassified Information on External Systems. Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or transmitted on external systems, are implemented in |
| NIST800-PM-18 | Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and the resources |
| NIST800-PM-19 | Privacy Program Leadership Role. Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applicable privacy requirements and manage privacy risks through the organization-wide privacy |
| NIST800-PM-2 | Information Security Program Leadership Role. Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program |
| NIST800-PM-20 | Dissemination of Privacy Program Information. Maintain a central resource webpage on the organization's principal public website that serves as a central source of information about the organization's privacy program and that: Ensures that the |
| NIST800-PM-21 | Accounting of Disclosures. Develop and maintain an accurate accounting of disclosures of personally identifiable information, including: Date, nature, and purpose of each disclosure; and Name and address, or other contact information of the individual |
| NIST800-PM-22 | Personally Identifiable Information Quality Management. Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle; Correcting or deleting inaccurate |
| NIST800-PM-23 | Data Governance Body. Establish a Data Governance Body consisting of [organization-defined] with [organization-defined] |
| NIST800-PM-24 | Data Integrity Board. Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching programs in which the agency has participated |
| NIST800-PM-25 | Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or |
| NIST800-PM-26 | Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes: Mechanisms that are easy to use and readily accessible |
| NIST800-PM-27 | Privacy Reporting. Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; and [organization-defined] and other personnel with responsibility for monitoring privacy program compliance; and Review and update |
| NIST800-PM-28 | Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk monitoring; Priorities and trade-offs considered by the organization for managing risk; and |
| NIST800-PM-29 | Risk Management Program Leadership Roles. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and Establish a Risk Executive |
| NIST800-PM-3 | Information Security and Privacy Resources. Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document all exceptions to this requirement; Prepare documentation required for |
| NIST800-PM-30 | Supply Chain Risk Management Strategy. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services; Implement the supply chain risk |
| NIST800-PM-31 | Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring |
| NIST800-PM-32 | Purposing. Analyze [organization-defined] supporting mission essential services or functions to ensure that the information resources are being used consistent with their intended purpose |
| NIST800-PM-4 | Plan of Action and Milestones Process. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems: Are developed |
| NIST800-PM-5 | System Inventory. Develop and update [organization-defined] an inventory of organizational systems |
| NIST800-PM-6 | Measures of Performance. Develop, monitor, and report on the results of information security and privacy measures of performance |
| NIST800-PM-7 | Enterprise Architecture. Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations and assets, individuals, other organizations, and the Nation |
| NIST800-PM-8 | Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan |
| NIST800-PM-9 | Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk |
PS - Personnel Security
Personnel security controls
| Code | Title |
|---|---|
| NIST800-PS-1 | Policy and procedures for personnel security |
| NIST800-PS-2 | Position risk designation |
| NIST800-PS-3 | Personnel screening |
| NIST800-PS-4 | Personnel termination |
| NIST800-PS-5 | Personnel transfer |
| NIST800-PS-6 | Access agreements |
| NIST800-PS-7 | External personnel security |
| NIST800-PS-8 | Personnel sanctions |
| NIST800-PS-9 | Position descriptions |
PT - PII Processing and Transparency
| Code | Title |
|---|---|
| NIST800-PT-1 | Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent |
| NIST800-PT-2 | Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-defined] of personally identifiable information to only that which is authorized |
| NIST800-PT-3 | Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [organization-defined] of personally identifiable |
| NIST800-PT-4 | Consent. Implement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals' informed decision-making |
| NIST800-PT-5 | Privacy Notice. Provide notice to individuals about the processing of personally identifiable information that: Is available to individuals upon first interacting with an organization, and subsequently at [organization-defined]; Is clear and easy-to-understand, expressing information |
| NIST800-PT-6 | System of Records Notice. For systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OMB guidance and submit new and |
| NIST800-PT-7 | Specific Categories of Personally Identifiable Information. Apply [organization-defined] for specific categories of personally identifiable information |
| NIST800-PT-8 | Computer Matching Requirements. When a system or organization processes information for the purpose of conducting a matching program: Obtain approval from the Data Integrity Board to conduct the matching program; Develop and enter into |
Privacy
RA - Risk Assessment
Risk assessment controls
| Code | Title |
|---|---|
| NIST800-RA-1 | Policy and procedures for risk assessment |
| NIST800-RA-10 | Threat hunting |
| NIST800-RA-2 | Security categorization |
| NIST800-RA-3 | Risk assessment |
| NIST800-RA-5 | Vulnerability monitoring and scanning |
| NIST800-RA-6 | Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined] |
| NIST800-RA-7 | Risk response |
| NIST800-RA-8 | Privacy Impact Assessments. Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes personally identifiable information; and Initiating a new collection of personally identifiable information that: |
| NIST800-RA-9 | Criticality analysis |
SA - System and Services Acquisition
System and services acquisition controls
| Code | Title |
|---|---|
| NIST800-SA-1 | Policy and procedures for system and services acquisition |
| NIST800-SA-10 | Developer configuration management |
| NIST800-SA-11 | Developer testing and evaluation |
| NIST800-SA-15 | Development process, standards, and tools |
| NIST800-SA-16 | Developer-provided Training. Require the developer of the system, system component, or system service to provide the following training on the correct use and operation of the implemented security and privacy functions, controls, and/or mechanisms: |
| NIST800-SA-17 | Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization's |
| NIST800-SA-2 | Allocation of resources |
| NIST800-SA-20 | Customized Development of Critical Components. Reimplement or custom develop the following critical system components: [organization-defined] |
| NIST800-SA-21 | Developer Screening. Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Satisfies the following additional personnel screening criteria: [organization-defined] |
| NIST800-SA-22 | Unsupported System Components |
| NIST800-SA-23 | Specialization. Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those systems or components |
| NIST800-SA-24 | Design For Cyber Resiliency. Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [organization-defined]. Defining the following cyber resiliency objectives: [organization-defined]. Defining the following |
| NIST800-SA-3 | System development life cycle |
| NIST800-SA-4 | Acquisition process |
| NIST800-SA-5 | System documentation |
| NIST800-SA-8 | Security and privacy engineering principles |
| NIST800-SA-9 | External system services |
SC - System and Communications Protection
System and communications protection controls
| Code | Title |
|---|---|
| NIST800-SC-1 | Policy and procedures for system and communications protection |
| NIST800-SC-10 | Network disconnect |
| NIST800-SC-11 | Trusted Path. Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the |
| NIST800-SC-12 | Cryptographic key establishment and management |
| NIST800-SC-13 | Cryptographic protection |
| NIST800-SC-15 | Collaborative computing devices and applications |
| NIST800-SC-16 | Transmission of Security and Privacy Attributes. Associate [organization-defined] with information exchanged between systems and between system components |
| NIST800-SC-17 | Public key infrastructure certificates |
| NIST800-SC-18 | Mobile Code. Define acceptable and unacceptable mobile code and mobile code technologies; and Authorize, monitor, and control the use of mobile code within the system |
| NIST800-SC-2 | Separation of system and user functionality |
| NIST800-SC-20 | Secure name/address resolution service |
| NIST800-SC-21 | Secure name/address resolution service (recursive) |
| NIST800-SC-22 | Architecture and provisioning for name/address resolution service |
| NIST800-SC-23 | Session authenticity |
| NIST800-SC-24 | Fail in Known State. Fail to a [organization-defined] for the following failures on the indicated components while preserving [organization-defined] in failure: [organization-defined] |
| NIST800-SC-25 | Thin Nodes. Employ minimal functionality and information storage on the following system components: [organization-defined] |
| NIST800-SC-26 | Decoys. Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks |
| NIST800-SC-27 | Platform-independent Applications. Include within organizational systems the following platform independent applications: [organization-defined] |
| NIST800-SC-28 | Protection of information at rest |
| NIST800-SC-29 | Heterogeneity. Employ a diverse set of information technologies for the following system components in the implementation of the system: [organization-defined] |
| NIST800-SC-3 | Security Function Isolation. Isolate security functions from nonsecurity functions |
| NIST800-SC-30 | Concealment and Misdirection. Employ the following concealment and misdirection techniques for [organization-defined] at [organization-defined] to confuse and mislead adversaries: [organization-defined] |
| NIST800-SC-31 | Covert Channel Analysis. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [organization-defined] channels; and Estimate the maximum bandwidth of those channels |
| NIST800-SC-32 | System Partitioning. Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined] |
| NIST800-SC-34 | Non-modifiable Executable Programs. For [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications from hardware-enforced, read-only media: [organization-defined] |
| NIST800-SC-35 | External Malicious Code Identification. Include system components that proactively seek to identify network-based malicious code or malicious websites |
| NIST800-SC-36 | Distributed Processing and Storage. Distribute the following processing and storage components across multiple [organization-defined]: [organization-defined] |
| NIST800-SC-37 | Out-of-band Channels. Employ the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [organization-defined] |
| NIST800-SC-38 | Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined] |
| NIST800-SC-39 | Process isolation |
| NIST800-SC-4 | Information in shared system resources |
| NIST800-SC-40 | Wireless Link Protection. Protect external and internal [organization-defined] from the following signal parameter attacks: [organization-defined] |
| NIST800-SC-41 | Port and I/O Device Access. [organization-defined] disable or remove [organization-defined] on the following systems or system components: [organization-defined] |
| NIST800-SC-42 | Sensor Capability and Data. Prohibit [organization-defined] ; and Provide an explicit indication of sensor use to [organization-defined] |
| NIST800-SC-43 | Usage Restrictions. Establish usage restrictions and implementation guidelines for the following system components: [organization-defined] ; and Authorize, monitor, and control the use of such components within the system |
| NIST800-SC-44 | Detonation Chambers. Employ a detonation chamber capability within [organization-defined] |
| NIST800-SC-45 | System Time Synchronization. Synchronize system clocks within and between systems and system components |
| NIST800-SC-46 | Cross Domain Policy Enforcement. Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains |
| NIST800-SC-47 | Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control |
| NIST800-SC-48 | Sensor Relocation. Relocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined] |
| NIST800-SC-49 | Hardware-enforced Separation and Policy Enforcement. Implement hardware-enforced separation and policy enforcement mechanisms between [organization-defined] |
| NIST800-SC-5 | Denial-of-service protection |
| NIST800-SC-50 | Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined] |
| NIST800-SC-51 | Hardware-based Protection. Employ hardware-based, write-protect for [organization-defined] ; and Implement specific procedures for [organization-defined] to manually disable hardware write-protect for firmware modifications and re-enable the write-protect prior to returning to operational mode |
| NIST800-SC-6 | Resource Availability. Protect the availability of resources by allocating [organization-defined] by [organization-defined] |
| NIST800-SC-7 | Boundary protection |
| NIST800-SC-8 | Transmission confidentiality and integrity |
SI - System and Information Integrity
System and information integrity controls
| Code | Title |
|---|---|
| NIST800-SI-1 | Policy and procedures for system and information integrity |
| NIST800-SI-10 | Information input validation |
| NIST800-SI-11 | Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined] |
| NIST800-SI-12 | Information management and retention |
| NIST800-SI-13 | Predictable Failure Prevention. Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [organization-defined] ; and Provide substitute system components and a means to exchange active and standby |
| NIST800-SI-14 | Non-persistence. Implement non-persistent [organization-defined] that are initiated in a known state and terminated [organization-defined] |
| NIST800-SI-15 | Information Output Filtering. Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected content: [organization-defined] |
| NIST800-SI-16 | Memory protection |
| NIST800-SI-17 | Fail-safe Procedures. Implement the indicated fail-safe procedures when the indicated failures occur: [organization-defined] |
| NIST800-SI-18 | Personally Identifiable Information Quality Operations. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [organization-defined] ; and Correct or delete inaccurate or outdated personally identifiable information |
| NIST800-SI-19 | De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectiveness of de-identification |
| NIST800-SI-2 | Flaw remediation |
| NIST800-SI-20 | Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organization: [organization-defined] |
| NIST800-SI-21 | Information Refresh. Refresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed |
| NIST800-SI-22 | Information Diversity. Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and Use an alternative information source for the execution of essential functions or services on [organization-defined] when the primary source of |
| NIST800-SI-23 | Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the following systems or system components: [organization-defined] |
| NIST800-SI-3 | Malicious code protection |
| NIST800-SI-4 | System monitoring |
| NIST800-SI-5 | Security alerts, advisories, and directives |
| NIST800-SI-6 | Security and Privacy Function Verification. Verify the correct operation of [organization-defined]; Perform the verification of the functions specified in SI-6a [organization-defined]; Alert [organization-defined] to failed security and privacy verification tests; and [organization-defined] when anomalies |
| NIST800-SI-7 | Software, firmware, and information integrity |
| NIST800-SI-8 | Spam Protection. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and Update spam protection mechanisms when new releases are available in accordance with organizational configuration |
SR - Supply Chain Risk Management
Supply chain risk management controls
| Code | Title |
|---|---|
| NIST800-SR-1 | Policy and procedures for supply chain risk management |
| NIST800-SR-10 | Inspection of systems or components |
| NIST800-SR-11 | Component authenticity |
| NIST800-SR-12 | Component disposal |
| NIST800-SR-2 | Supply chain risk management plan |
| NIST800-SR-3 | Supply chain controls and processes |
| NIST800-SR-4 | Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined] |
| NIST800-SR-5 | Acquisition strategies, tools, and methods |
| NIST800-SR-6 | Supplier assessments and reviews |
| NIST800-SR-7 | Supply Chain Operations Security. Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: [organization-defined] |
| NIST800-SR-8 | Notification agreements |
| NIST800-SR-9 | Tamper Resistance and Detection. Implement a tamper protection program for the system, system component, or system service |
Technical
Your Compliance Coverage
If you comply with NIST SP 800-53 Rev 5, you already cover:
SOC 2
89%
266 controls mapped
Compare →ISO 27002:2022
87%
262 controls mapped
Compare →ISO 27001:2022
84%
253 controls mapped
Compare →+ 282 more: NIST Cybersecurity Framework 2.0 (79%), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (69%)
See all 285 mapped frameworks ↓Maps to 285 other frameworks
What is NIST SP 800-53 Rev 5 and who does it apply to?
NIST SP 800-53 Rev 5 is a compliance framework from United States with 24 domains and 320 controls. Security and privacy controls for information systems and organizations It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST SP 800-53 Rev 5 actually require?
NIST SP 800-53 Rev 5 has 320 controls organised across 24 domains. The largest domains are SC - System and Communications Protection (47 controls), PM - Program Management (32 controls), AC - Access Control (23 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST SP 800-53 Rev 5 do I already cover?
NIST SP 800-53 Rev 5 maps to 285 other compliance frameworks. The top mapping partners are SOC 2 (89% coverage), ISO 27002:2022 (87% coverage), ISO 27001:2022 (84% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST SP 800-53 Rev 5?
Start your NIST SP 800-53 Rev 5 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-53 Rev 5 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 320 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required