NIST SP 800-53 Rev 5 LOW
The low-impact security control baseline of NIST SP 800-53B (release 5.2.0): the 149 SP 800-53 Rev 5 controls and control enhancements a federal system categorized low under FIPS 199 and FIPS 200 starts from before tailoring, each with its release 5.2.0 control statement, parameters organization-defined, and the SP 800-53A Rev 5 examine and test objects an assessor asks for.
NIST SP 800-53 Rev 5 LOW is a compliance framework from United States (federal information systems; voluntary for other organizations) with 18 domains and 149 controls that map to 3 other frameworks. The largest domains are IA: Identification and Authentication – NIST SP 800-53 Rev 5 LOW (16 controls), AC: Access Control – NIST SP 800-53 Rev 5 LOW (11 controls), SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 LOW (11 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
AC: Access Control – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::AC-1 | AC-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::AC-14 | AC-14 Permitted Actions Without Identification or Authentication |
| nist-sp-800-53-rev-5-low::AC-17 | AC-17 Remote Access |
| nist-sp-800-53-rev-5-low::AC-18 | AC-18 Wireless Access |
| nist-sp-800-53-rev-5-low::AC-19 | AC-19 Access Control for Mobile Devices |
| nist-sp-800-53-rev-5-low::AC-2 | AC-2 Account Management |
| nist-sp-800-53-rev-5-low::AC-20 | AC-20 Use of External Systems |
| nist-sp-800-53-rev-5-low::AC-22 | AC-22 Publicly Accessible Content |
| nist-sp-800-53-rev-5-low::AC-3 | AC-3 Access Enforcement |
| nist-sp-800-53-rev-5-low::AC-7 | AC-7 Unsuccessful Logon Attempts |
| nist-sp-800-53-rev-5-low::AC-8 | AC-8 System Use Notification |
AT: Awareness and Training – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::AT-1 | AT-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::AT-2 | AT-2 Literacy Training and Awareness |
| nist-sp-800-53-rev-5-low::AT-2(2) | AT-2(2) Literacy Training and Awareness | Insider Threat |
| nist-sp-800-53-rev-5-low::AT-3 | AT-3 Role-based Training |
| nist-sp-800-53-rev-5-low::AT-4 | AT-4 Training Records |
AU: Audit and Accountability – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::AU-1 | AU-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::AU-11 | AU-11 Audit Record Retention |
| nist-sp-800-53-rev-5-low::AU-12 | AU-12 Audit Record Generation |
| nist-sp-800-53-rev-5-low::AU-2 | AU-2 Event Logging |
| nist-sp-800-53-rev-5-low::AU-3 | AU-3 Content of Audit Records |
| nist-sp-800-53-rev-5-low::AU-4 | AU-4 Audit Log Storage Capacity |
| nist-sp-800-53-rev-5-low::AU-5 | AU-5 Response to Audit Logging Process Failures |
| nist-sp-800-53-rev-5-low::AU-6 | AU-6 Audit Record Review, Analysis, and Reporting |
| nist-sp-800-53-rev-5-low::AU-8 | AU-8 Time Stamps |
| nist-sp-800-53-rev-5-low::AU-9 | AU-9 Protection of Audit Information |
CA: Assessment, Authorization, and Monitoring – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::CA-1 | CA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::CA-2 | CA-2 Control Assessments |
| nist-sp-800-53-rev-5-low::CA-3 | CA-3 Information Exchange |
| nist-sp-800-53-rev-5-low::CA-5 | CA-5 Plan of Action and Milestones |
| nist-sp-800-53-rev-5-low::CA-6 | CA-6 Authorization |
| nist-sp-800-53-rev-5-low::CA-7 | CA-7 Continuous Monitoring |
| nist-sp-800-53-rev-5-low::CA-7(4) | CA-7(4) Continuous Monitoring | Risk Monitoring |
| nist-sp-800-53-rev-5-low::CA-9 | CA-9 Internal System Connections |
CM: Configuration Management – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::CM-1 | CM-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::CM-10 | CM-10 Software Usage Restrictions |
| nist-sp-800-53-rev-5-low::CM-11 | CM-11 User-installed Software |
| nist-sp-800-53-rev-5-low::CM-2 | CM-2 Baseline Configuration |
| nist-sp-800-53-rev-5-low::CM-4 | CM-4 Impact Analyses |
| nist-sp-800-53-rev-5-low::CM-5 | CM-5 Access Restrictions for Change |
| nist-sp-800-53-rev-5-low::CM-6 | CM-6 Configuration Settings |
| nist-sp-800-53-rev-5-low::CM-7 | CM-7 Least Functionality |
| nist-sp-800-53-rev-5-low::CM-8 | CM-8 System Component Inventory |
CP: Contingency Planning – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::CP-1 | CP-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::CP-10 | CP-10 System Recovery and Reconstitution |
| nist-sp-800-53-rev-5-low::CP-2 | CP-2 Contingency Plan |
| nist-sp-800-53-rev-5-low::CP-3 | CP-3 Contingency Training |
| nist-sp-800-53-rev-5-low::CP-4 | CP-4 Contingency Plan Testing |
| nist-sp-800-53-rev-5-low::CP-9 | CP-9 System Backup |
IA: Identification and Authentication – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::IA-1 | IA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::IA-11 | IA-11 Re-authentication |
| nist-sp-800-53-rev-5-low::IA-2 | IA-2 Identification and Authentication (Organizational Users) |
| nist-sp-800-53-rev-5-low::IA-2(1) | IA-2(1) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Privileged Accounts |
| nist-sp-800-53-rev-5-low::IA-2(12) | IA-2(12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials |
| nist-sp-800-53-rev-5-low::IA-2(2) | IA-2(2) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Non-privileged Accounts |
| nist-sp-800-53-rev-5-low::IA-2(8) | IA-2(8) Identification and Authentication (Organizational Users) | Access to Accounts: Replay Resistant |
| nist-sp-800-53-rev-5-low::IA-4 | IA-4 Identifier Management |
| nist-sp-800-53-rev-5-low::IA-5 | IA-5 Authenticator Management |
| nist-sp-800-53-rev-5-low::IA-5(1) | IA-5(1) Authenticator Management | Password-based Authentication |
| nist-sp-800-53-rev-5-low::IA-6 | IA-6 Authentication Feedback |
| nist-sp-800-53-rev-5-low::IA-7 | IA-7 Cryptographic Module Authentication |
| nist-sp-800-53-rev-5-low::IA-8 | IA-8 Identification and Authentication (Non-organizational Users) |
| nist-sp-800-53-rev-5-low::IA-8(1) | IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies |
| nist-sp-800-53-rev-5-low::IA-8(2) | IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators |
| nist-sp-800-53-rev-5-low::IA-8(4) | IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles |
IR: Incident Response – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::IR-1 | IR-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::IR-2 | IR-2 Incident Response Training |
| nist-sp-800-53-rev-5-low::IR-4 | IR-4 Incident Handling |
| nist-sp-800-53-rev-5-low::IR-5 | IR-5 Incident Monitoring |
| nist-sp-800-53-rev-5-low::IR-6 | IR-6 Incident Reporting |
| nist-sp-800-53-rev-5-low::IR-7 | IR-7 Incident Response Assistance |
| nist-sp-800-53-rev-5-low::IR-8 | IR-8 Incident Response Plan |
MA: Maintenance – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::MA-1 | MA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::MA-2 | MA-2 Controlled Maintenance |
| nist-sp-800-53-rev-5-low::MA-4 | MA-4 Nonlocal Maintenance |
| nist-sp-800-53-rev-5-low::MA-5 | MA-5 Maintenance Personnel |
MP: Media Protection – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::MP-1 | MP-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::MP-2 | MP-2 Media Access |
| nist-sp-800-53-rev-5-low::MP-6 | MP-6 Media Sanitization |
| nist-sp-800-53-rev-5-low::MP-7 | MP-7 Media Use |
PE: Physical and Environmental Protection – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::PE-1 | PE-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::PE-12 | PE-12 Emergency Lighting |
| nist-sp-800-53-rev-5-low::PE-13 | PE-13 Fire Protection |
| nist-sp-800-53-rev-5-low::PE-14 | PE-14 Environmental Controls |
| nist-sp-800-53-rev-5-low::PE-15 | PE-15 Water Damage Protection |
| nist-sp-800-53-rev-5-low::PE-16 | PE-16 Delivery and Removal |
| nist-sp-800-53-rev-5-low::PE-2 | PE-2 Physical Access Authorizations |
| nist-sp-800-53-rev-5-low::PE-3 | PE-3 Physical Access Control |
| nist-sp-800-53-rev-5-low::PE-6 | PE-6 Monitoring Physical Access |
| nist-sp-800-53-rev-5-low::PE-8 | PE-8 Visitor Access Records |
PL: Planning – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::PL-1 | PL-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::PL-10 | PL-10 Baseline Selection |
| nist-sp-800-53-rev-5-low::PL-11 | PL-11 Baseline Tailoring |
| nist-sp-800-53-rev-5-low::PL-2 | PL-2 System Security and Privacy Plans |
| nist-sp-800-53-rev-5-low::PL-4 | PL-4 Rules of Behavior |
| nist-sp-800-53-rev-5-low::PL-4(1) | PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions |
PS: Personnel Security – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::PS-1 | PS-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::PS-2 | PS-2 Position Risk Designation |
| nist-sp-800-53-rev-5-low::PS-3 | PS-3 Personnel Screening |
| nist-sp-800-53-rev-5-low::PS-4 | PS-4 Personnel Termination |
| nist-sp-800-53-rev-5-low::PS-5 | PS-5 Personnel Transfer |
| nist-sp-800-53-rev-5-low::PS-6 | PS-6 Access Agreements |
| nist-sp-800-53-rev-5-low::PS-7 | PS-7 External Personnel Security |
| nist-sp-800-53-rev-5-low::PS-8 | PS-8 Personnel Sanctions |
| nist-sp-800-53-rev-5-low::PS-9 | PS-9 Position Descriptions |
RA: Risk Assessment – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::RA-1 | RA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::RA-2 | RA-2 Security Categorization |
| nist-sp-800-53-rev-5-low::RA-3 | RA-3 Risk Assessment |
| nist-sp-800-53-rev-5-low::RA-3(1) | RA-3(1) Risk Assessment | Supply Chain Risk Assessment |
| nist-sp-800-53-rev-5-low::RA-5 | RA-5 Vulnerability Monitoring and Scanning |
| nist-sp-800-53-rev-5-low::RA-5(11) | RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program |
| nist-sp-800-53-rev-5-low::RA-5(2) | RA-5(2) Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned |
| nist-sp-800-53-rev-5-low::RA-7 | RA-7 Risk Response |
SA: System and Services Acquisition – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::SA-1 | SA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::SA-2 | SA-2 Allocation of Resources |
| nist-sp-800-53-rev-5-low::SA-22 | SA-22 Unsupported System Components |
| nist-sp-800-53-rev-5-low::SA-3 | SA-3 System Development Life Cycle |
| nist-sp-800-53-rev-5-low::SA-4 | SA-4 Acquisition Process |
| nist-sp-800-53-rev-5-low::SA-4(10) | SA-4(10) Acquisition Process | Use of Approved PIV Products |
| nist-sp-800-53-rev-5-low::SA-5 | SA-5 System Documentation |
| nist-sp-800-53-rev-5-low::SA-8 | SA-8 Security and Privacy Engineering Principles |
| nist-sp-800-53-rev-5-low::SA-9 | SA-9 External System Services |
SC: System and Communications Protection – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::SC-1 | SC-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::SC-12 | SC-12 Cryptographic Key Establishment and Management |
| nist-sp-800-53-rev-5-low::SC-13 | SC-13 Cryptographic Protection |
| nist-sp-800-53-rev-5-low::SC-15 | SC-15 Collaborative Computing Devices and Applications |
| nist-sp-800-53-rev-5-low::SC-20 | SC-20 Secure Name/Address Resolution Service (Authoritative Source) |
| nist-sp-800-53-rev-5-low::SC-21 | SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| nist-sp-800-53-rev-5-low::SC-22 | SC-22 Architecture and Provisioning for Name/Address Resolution Service |
| nist-sp-800-53-rev-5-low::SC-39 | SC-39 Process Isolation |
| nist-sp-800-53-rev-5-low::SC-5 | SC-5 Denial-of-service Protection |
| nist-sp-800-53-rev-5-low::SC-7 | SC-7 Boundary Protection |
SI: System and Information Integrity – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::SI-1 | SI-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::SI-12 | SI-12 Information Management and Retention |
| nist-sp-800-53-rev-5-low::SI-2 | SI-2 Flaw Remediation |
| nist-sp-800-53-rev-5-low::SI-3 | SI-3 Malicious Code Protection |
| nist-sp-800-53-rev-5-low::SI-4 | SI-4 System Monitoring |
| nist-sp-800-53-rev-5-low::SI-5 | SI-5 Security Alerts, Advisories, and Directives |
SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 LOW
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-low::SR-1 | SR-1 Policy and Procedures |
| nist-sp-800-53-rev-5-low::SR-10 | SR-10 Inspection of Systems or Components |
| nist-sp-800-53-rev-5-low::SR-11 | SR-11 Component Authenticity |
| nist-sp-800-53-rev-5-low::SR-11(1) | SR-11(1) Component Authenticity | Anti-counterfeit Training |
| nist-sp-800-53-rev-5-low::SR-11(2) | SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair |
| nist-sp-800-53-rev-5-low::SR-12 | SR-12 Component Disposal |
| nist-sp-800-53-rev-5-low::SR-2 | SR-2 Supply Chain Risk Management Plan |
| nist-sp-800-53-rev-5-low::SR-2(1) | SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team |
| nist-sp-800-53-rev-5-low::SR-3 | SR-3 Supply Chain Controls and Processes |
| nist-sp-800-53-rev-5-low::SR-5 | SR-5 Acquisition Strategies, Tools, and Methods |
| nist-sp-800-53-rev-5-low::SR-8 | SR-8 Notification Agreements |
Your Compliance Coverage
If you comply with NIST SP 800-53 Rev 5 LOW, you already cover:
Maps to 3 other frameworks
Coverage is not the same as your position
This page shows what NIST SP 800-53 Rev 5 LOW overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is NIST SP 800-53 Rev 5 LOW and who does it apply to?
NIST SP 800-53 Rev 5 LOW is a compliance framework from United States (federal information systems; voluntary for other organizations) with 18 domains and 149 controls. The low-impact security control baseline of NIST SP 800-53B (release 5.2.0): the 149 SP 800-53 Rev 5 controls and control enhancements a federal system categorized low under FIPS 199 and FIPS 200 starts from before tailoring, each with its release 5.2.0 control statement, parameters organization-defined, and the SP 800-53A Rev 5 examine and test objects an assessor asks for. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST SP 800-53 Rev 5 LOW actually require?
NIST SP 800-53 Rev 5 LOW has 149 controls organised across 18 domains. The largest domains are IA: Identification and Authentication – NIST SP 800-53 Rev 5 LOW (16 controls), AC: Access Control – NIST SP 800-53 Rev 5 LOW (11 controls), SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 LOW (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST SP 800-53 Rev 5 LOW do I already cover?
NIST SP 800-53 Rev 5 LOW maps to 3 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (79% coverage), FedRAMP Moderate (79% coverage), FedRAMP High (78% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST SP 800-53 Rev 5 LOW?
Start your NIST SP 800-53 Rev 5 LOW compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-53 Rev 5 LOW requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 149 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required