Back to Frameworks

NIST SP 800-53 Rev 5 LOW

United States (federal information systems; voluntary for other organizations)
vRev 5, release 5.2.0 (SP 800-53B release 5.2.0 of 27 August 2025; allocation unchanged since the December 2020 update)
18 domains
149 controls

The low-impact security control baseline of NIST SP 800-53B (release 5.2.0): the 149 SP 800-53 Rev 5 controls and control enhancements a federal system categorized low under FIPS 199 and FIPS 200 starts from before tailoring, each with its release 5.2.0 control statement, parameters organization-defined, and the SP 800-53A Rev 5 examine and test objects an assessor asks for.

Verified

NIST SP 800-53 Rev 5 LOW is a compliance framework from United States (federal information systems; voluntary for other organizations) with 18 domains and 149 controls that map to 3 other frameworks. The largest domains are IA: Identification and Authentication – NIST SP 800-53 Rev 5 LOW (16 controls), AC: Access Control – NIST SP 800-53 Rev 5 LOW (11 controls), SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 LOW (11 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (18)

AC: Access Control – NIST SP 800-53 Rev 5 LOW

11 controls
Controls in the AC: Access Control – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 11 controls
CodeTitle
nist-sp-800-53-rev-5-low::AC-1AC-1 Policy and Procedures
nist-sp-800-53-rev-5-low::AC-14AC-14 Permitted Actions Without Identification or Authentication
nist-sp-800-53-rev-5-low::AC-17AC-17 Remote Access
nist-sp-800-53-rev-5-low::AC-18AC-18 Wireless Access
nist-sp-800-53-rev-5-low::AC-19AC-19 Access Control for Mobile Devices
nist-sp-800-53-rev-5-low::AC-2AC-2 Account Management
nist-sp-800-53-rev-5-low::AC-20AC-20 Use of External Systems
nist-sp-800-53-rev-5-low::AC-22AC-22 Publicly Accessible Content
nist-sp-800-53-rev-5-low::AC-3AC-3 Access Enforcement
nist-sp-800-53-rev-5-low::AC-7AC-7 Unsuccessful Logon Attempts
nist-sp-800-53-rev-5-low::AC-8AC-8 System Use Notification

AT: Awareness and Training – NIST SP 800-53 Rev 5 LOW

5 controls
Controls in the AT: Awareness and Training – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 5 controls
CodeTitle
nist-sp-800-53-rev-5-low::AT-1AT-1 Policy and Procedures
nist-sp-800-53-rev-5-low::AT-2AT-2 Literacy Training and Awareness
nist-sp-800-53-rev-5-low::AT-2(2)AT-2(2) Literacy Training and Awareness | Insider Threat
nist-sp-800-53-rev-5-low::AT-3AT-3 Role-based Training
nist-sp-800-53-rev-5-low::AT-4AT-4 Training Records

AU: Audit and Accountability – NIST SP 800-53 Rev 5 LOW

10 controls
Controls in the AU: Audit and Accountability – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 10 controls
CodeTitle
nist-sp-800-53-rev-5-low::AU-1AU-1 Policy and Procedures
nist-sp-800-53-rev-5-low::AU-11AU-11 Audit Record Retention
nist-sp-800-53-rev-5-low::AU-12AU-12 Audit Record Generation
nist-sp-800-53-rev-5-low::AU-2AU-2 Event Logging
nist-sp-800-53-rev-5-low::AU-3AU-3 Content of Audit Records
nist-sp-800-53-rev-5-low::AU-4AU-4 Audit Log Storage Capacity
nist-sp-800-53-rev-5-low::AU-5AU-5 Response to Audit Logging Process Failures
nist-sp-800-53-rev-5-low::AU-6AU-6 Audit Record Review, Analysis, and Reporting
nist-sp-800-53-rev-5-low::AU-8AU-8 Time Stamps
nist-sp-800-53-rev-5-low::AU-9AU-9 Protection of Audit Information

CA: Assessment, Authorization, and Monitoring – NIST SP 800-53 Rev 5 LOW

8 controls
Controls in the CA: Assessment, Authorization, and Monitoring – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 8 controls
CodeTitle
nist-sp-800-53-rev-5-low::CA-1CA-1 Policy and Procedures
nist-sp-800-53-rev-5-low::CA-2CA-2 Control Assessments
nist-sp-800-53-rev-5-low::CA-3CA-3 Information Exchange
nist-sp-800-53-rev-5-low::CA-5CA-5 Plan of Action and Milestones
nist-sp-800-53-rev-5-low::CA-6CA-6 Authorization
nist-sp-800-53-rev-5-low::CA-7CA-7 Continuous Monitoring
nist-sp-800-53-rev-5-low::CA-7(4)CA-7(4) Continuous Monitoring | Risk Monitoring
nist-sp-800-53-rev-5-low::CA-9CA-9 Internal System Connections

CM: Configuration Management – NIST SP 800-53 Rev 5 LOW

9 controls
Controls in the CM: Configuration Management – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 9 controls
CodeTitle
nist-sp-800-53-rev-5-low::CM-1CM-1 Policy and Procedures
nist-sp-800-53-rev-5-low::CM-10CM-10 Software Usage Restrictions
nist-sp-800-53-rev-5-low::CM-11CM-11 User-installed Software
nist-sp-800-53-rev-5-low::CM-2CM-2 Baseline Configuration
nist-sp-800-53-rev-5-low::CM-4CM-4 Impact Analyses
nist-sp-800-53-rev-5-low::CM-5CM-5 Access Restrictions for Change
nist-sp-800-53-rev-5-low::CM-6CM-6 Configuration Settings
nist-sp-800-53-rev-5-low::CM-7CM-7 Least Functionality
nist-sp-800-53-rev-5-low::CM-8CM-8 System Component Inventory

CP: Contingency Planning – NIST SP 800-53 Rev 5 LOW

6 controls
Controls in the CP: Contingency Planning – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 6 controls
CodeTitle
nist-sp-800-53-rev-5-low::CP-1CP-1 Policy and Procedures
nist-sp-800-53-rev-5-low::CP-10CP-10 System Recovery and Reconstitution
nist-sp-800-53-rev-5-low::CP-2CP-2 Contingency Plan
nist-sp-800-53-rev-5-low::CP-3CP-3 Contingency Training
nist-sp-800-53-rev-5-low::CP-4CP-4 Contingency Plan Testing
nist-sp-800-53-rev-5-low::CP-9CP-9 System Backup

IA: Identification and Authentication – NIST SP 800-53 Rev 5 LOW

16 controls
Controls in the IA: Identification and Authentication – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 16 controls
CodeTitle
nist-sp-800-53-rev-5-low::IA-1IA-1 Policy and Procedures
nist-sp-800-53-rev-5-low::IA-11IA-11 Re-authentication
nist-sp-800-53-rev-5-low::IA-2IA-2 Identification and Authentication (Organizational Users)
nist-sp-800-53-rev-5-low::IA-2(1)IA-2(1) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Privileged Accounts
nist-sp-800-53-rev-5-low::IA-2(12)IA-2(12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials
nist-sp-800-53-rev-5-low::IA-2(2)IA-2(2) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Non-privileged Accounts
nist-sp-800-53-rev-5-low::IA-2(8)IA-2(8) Identification and Authentication (Organizational Users) | Access to Accounts: Replay Resistant
nist-sp-800-53-rev-5-low::IA-4IA-4 Identifier Management
nist-sp-800-53-rev-5-low::IA-5IA-5 Authenticator Management
nist-sp-800-53-rev-5-low::IA-5(1)IA-5(1) Authenticator Management | Password-based Authentication
nist-sp-800-53-rev-5-low::IA-6IA-6 Authentication Feedback
nist-sp-800-53-rev-5-low::IA-7IA-7 Cryptographic Module Authentication
nist-sp-800-53-rev-5-low::IA-8IA-8 Identification and Authentication (Non-organizational Users)
nist-sp-800-53-rev-5-low::IA-8(1)IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies
nist-sp-800-53-rev-5-low::IA-8(2)IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators
nist-sp-800-53-rev-5-low::IA-8(4)IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles

IR: Incident Response – NIST SP 800-53 Rev 5 LOW

7 controls
Controls in the IR: Incident Response – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 7 controls
CodeTitle
nist-sp-800-53-rev-5-low::IR-1IR-1 Policy and Procedures
nist-sp-800-53-rev-5-low::IR-2IR-2 Incident Response Training
nist-sp-800-53-rev-5-low::IR-4IR-4 Incident Handling
nist-sp-800-53-rev-5-low::IR-5IR-5 Incident Monitoring
nist-sp-800-53-rev-5-low::IR-6IR-6 Incident Reporting
nist-sp-800-53-rev-5-low::IR-7IR-7 Incident Response Assistance
nist-sp-800-53-rev-5-low::IR-8IR-8 Incident Response Plan

MA: Maintenance – NIST SP 800-53 Rev 5 LOW

4 controls
Controls in the MA: Maintenance – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 4 controls
CodeTitle
nist-sp-800-53-rev-5-low::MA-1MA-1 Policy and Procedures
nist-sp-800-53-rev-5-low::MA-2MA-2 Controlled Maintenance
nist-sp-800-53-rev-5-low::MA-4MA-4 Nonlocal Maintenance
nist-sp-800-53-rev-5-low::MA-5MA-5 Maintenance Personnel

MP: Media Protection – NIST SP 800-53 Rev 5 LOW

4 controls
Controls in the MP: Media Protection – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 4 controls
CodeTitle
nist-sp-800-53-rev-5-low::MP-1MP-1 Policy and Procedures
nist-sp-800-53-rev-5-low::MP-2MP-2 Media Access
nist-sp-800-53-rev-5-low::MP-6MP-6 Media Sanitization
nist-sp-800-53-rev-5-low::MP-7MP-7 Media Use

PE: Physical and Environmental Protection – NIST SP 800-53 Rev 5 LOW

10 controls
Controls in the PE: Physical and Environmental Protection – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 10 controls
CodeTitle
nist-sp-800-53-rev-5-low::PE-1PE-1 Policy and Procedures
nist-sp-800-53-rev-5-low::PE-12PE-12 Emergency Lighting
nist-sp-800-53-rev-5-low::PE-13PE-13 Fire Protection
nist-sp-800-53-rev-5-low::PE-14PE-14 Environmental Controls
nist-sp-800-53-rev-5-low::PE-15PE-15 Water Damage Protection
nist-sp-800-53-rev-5-low::PE-16PE-16 Delivery and Removal
nist-sp-800-53-rev-5-low::PE-2PE-2 Physical Access Authorizations
nist-sp-800-53-rev-5-low::PE-3PE-3 Physical Access Control
nist-sp-800-53-rev-5-low::PE-6PE-6 Monitoring Physical Access
nist-sp-800-53-rev-5-low::PE-8PE-8 Visitor Access Records

PL: Planning – NIST SP 800-53 Rev 5 LOW

6 controls
Controls in the PL: Planning – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 6 controls
CodeTitle
nist-sp-800-53-rev-5-low::PL-1PL-1 Policy and Procedures
nist-sp-800-53-rev-5-low::PL-10PL-10 Baseline Selection
nist-sp-800-53-rev-5-low::PL-11PL-11 Baseline Tailoring
nist-sp-800-53-rev-5-low::PL-2PL-2 System Security and Privacy Plans
nist-sp-800-53-rev-5-low::PL-4PL-4 Rules of Behavior
nist-sp-800-53-rev-5-low::PL-4(1)PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions

PS: Personnel Security – NIST SP 800-53 Rev 5 LOW

9 controls
Controls in the PS: Personnel Security – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 9 controls
CodeTitle
nist-sp-800-53-rev-5-low::PS-1PS-1 Policy and Procedures
nist-sp-800-53-rev-5-low::PS-2PS-2 Position Risk Designation
nist-sp-800-53-rev-5-low::PS-3PS-3 Personnel Screening
nist-sp-800-53-rev-5-low::PS-4PS-4 Personnel Termination
nist-sp-800-53-rev-5-low::PS-5PS-5 Personnel Transfer
nist-sp-800-53-rev-5-low::PS-6PS-6 Access Agreements
nist-sp-800-53-rev-5-low::PS-7PS-7 External Personnel Security
nist-sp-800-53-rev-5-low::PS-8PS-8 Personnel Sanctions
nist-sp-800-53-rev-5-low::PS-9PS-9 Position Descriptions

RA: Risk Assessment – NIST SP 800-53 Rev 5 LOW

8 controls
Controls in the RA: Risk Assessment – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 8 controls
CodeTitle
nist-sp-800-53-rev-5-low::RA-1RA-1 Policy and Procedures
nist-sp-800-53-rev-5-low::RA-2RA-2 Security Categorization
nist-sp-800-53-rev-5-low::RA-3RA-3 Risk Assessment
nist-sp-800-53-rev-5-low::RA-3(1)RA-3(1) Risk Assessment | Supply Chain Risk Assessment
nist-sp-800-53-rev-5-low::RA-5RA-5 Vulnerability Monitoring and Scanning
nist-sp-800-53-rev-5-low::RA-5(11)RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program
nist-sp-800-53-rev-5-low::RA-5(2)RA-5(2) Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned
nist-sp-800-53-rev-5-low::RA-7RA-7 Risk Response

SA: System and Services Acquisition – NIST SP 800-53 Rev 5 LOW

9 controls
Controls in the SA: System and Services Acquisition – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 9 controls
CodeTitle
nist-sp-800-53-rev-5-low::SA-1SA-1 Policy and Procedures
nist-sp-800-53-rev-5-low::SA-2SA-2 Allocation of Resources
nist-sp-800-53-rev-5-low::SA-22SA-22 Unsupported System Components
nist-sp-800-53-rev-5-low::SA-3SA-3 System Development Life Cycle
nist-sp-800-53-rev-5-low::SA-4SA-4 Acquisition Process
nist-sp-800-53-rev-5-low::SA-4(10)SA-4(10) Acquisition Process | Use of Approved PIV Products
nist-sp-800-53-rev-5-low::SA-5SA-5 System Documentation
nist-sp-800-53-rev-5-low::SA-8SA-8 Security and Privacy Engineering Principles
nist-sp-800-53-rev-5-low::SA-9SA-9 External System Services

SC: System and Communications Protection – NIST SP 800-53 Rev 5 LOW

10 controls
Controls in the SC: System and Communications Protection – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 10 controls
CodeTitle
nist-sp-800-53-rev-5-low::SC-1SC-1 Policy and Procedures
nist-sp-800-53-rev-5-low::SC-12SC-12 Cryptographic Key Establishment and Management
nist-sp-800-53-rev-5-low::SC-13SC-13 Cryptographic Protection
nist-sp-800-53-rev-5-low::SC-15SC-15 Collaborative Computing Devices and Applications
nist-sp-800-53-rev-5-low::SC-20SC-20 Secure Name/Address Resolution Service (Authoritative Source)
nist-sp-800-53-rev-5-low::SC-21SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
nist-sp-800-53-rev-5-low::SC-22SC-22 Architecture and Provisioning for Name/Address Resolution Service
nist-sp-800-53-rev-5-low::SC-39SC-39 Process Isolation
nist-sp-800-53-rev-5-low::SC-5SC-5 Denial-of-service Protection
nist-sp-800-53-rev-5-low::SC-7SC-7 Boundary Protection

SI: System and Information Integrity – NIST SP 800-53 Rev 5 LOW

6 controls
Controls in the SI: System and Information Integrity – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 6 controls
CodeTitle
nist-sp-800-53-rev-5-low::SI-1SI-1 Policy and Procedures
nist-sp-800-53-rev-5-low::SI-12SI-12 Information Management and Retention
nist-sp-800-53-rev-5-low::SI-2SI-2 Flaw Remediation
nist-sp-800-53-rev-5-low::SI-3SI-3 Malicious Code Protection
nist-sp-800-53-rev-5-low::SI-4SI-4 System Monitoring
nist-sp-800-53-rev-5-low::SI-5SI-5 Security Alerts, Advisories, and Directives

SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 LOW

11 controls
Controls in the SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 LOW domain of NIST SP 800-53 Rev 5 LOW — 11 controls
CodeTitle
nist-sp-800-53-rev-5-low::SR-1SR-1 Policy and Procedures
nist-sp-800-53-rev-5-low::SR-10SR-10 Inspection of Systems or Components
nist-sp-800-53-rev-5-low::SR-11SR-11 Component Authenticity
nist-sp-800-53-rev-5-low::SR-11(1)SR-11(1) Component Authenticity | Anti-counterfeit Training
nist-sp-800-53-rev-5-low::SR-11(2)SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair
nist-sp-800-53-rev-5-low::SR-12SR-12 Component Disposal
nist-sp-800-53-rev-5-low::SR-2SR-2 Supply Chain Risk Management Plan
nist-sp-800-53-rev-5-low::SR-2(1)SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team
nist-sp-800-53-rev-5-low::SR-3SR-3 Supply Chain Controls and Processes
nist-sp-800-53-rev-5-low::SR-5SR-5 Acquisition Strategies, Tools, and Methods
nist-sp-800-53-rev-5-low::SR-8SR-8 Notification Agreements

Maps to 3 other frameworks

189 total controls
NIST SP 800-53 Rev 5
149 source controls mapped|149 target controls covered
79%
FedRAMP Moderate
149 source controls mapped|149 target controls covered
79%
FedRAMP High
148 source controls mapped|148 target controls covered
78%

Coverage is not the same as your position

This page shows what NIST SP 800-53 Rev 5 LOW overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is NIST SP 800-53 Rev 5 LOW and who does it apply to?

NIST SP 800-53 Rev 5 LOW is a compliance framework from United States (federal information systems; voluntary for other organizations) with 18 domains and 149 controls. The low-impact security control baseline of NIST SP 800-53B (release 5.2.0): the 149 SP 800-53 Rev 5 controls and control enhancements a federal system categorized low under FIPS 199 and FIPS 200 starts from before tailoring, each with its release 5.2.0 control statement, parameters organization-defined, and the SP 800-53A Rev 5 examine and test objects an assessor asks for. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIST SP 800-53 Rev 5 LOW actually require?

NIST SP 800-53 Rev 5 LOW has 149 controls organised across 18 domains. The largest domains are IA: Identification and Authentication – NIST SP 800-53 Rev 5 LOW (16 controls), AC: Access Control – NIST SP 800-53 Rev 5 LOW (11 controls), SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 LOW (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIST SP 800-53 Rev 5 LOW do I already cover?

NIST SP 800-53 Rev 5 LOW maps to 3 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (79% coverage), FedRAMP Moderate (79% coverage), FedRAMP High (78% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIST SP 800-53 Rev 5 LOW?

Start your NIST SP 800-53 Rev 5 LOW compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-53 Rev 5 LOW requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 149 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required