NIST SP 800-53 Rev 5 MODERATE
The moderate-impact security control baseline of NIST SP 800-53B (release 5.2.0): the 287 SP 800-53 Rev 5 controls and control enhancements a federal system categorized moderate under FIPS 199 and FIPS 200 starts from before tailoring, each with its release 5.2.0 control statement, parameters organization-defined, and the SP 800-53A Rev 5 examine and test objects an assessor asks for.
NIST SP 800-53 Rev 5 MODERATE is a compliance framework from United States (federal information systems; voluntary for other organizations) with 18 domains and 287 controls that map to 3 other frameworks. The largest domains are AC: Access Control – NIST SP 800-53 Rev 5 MODERATE (39 controls), SC: System and Communications Protection – NIST SP 800-53 Rev 5 MODERATE (25 controls), CM: Configuration Management – NIST SP 800-53 Rev 5 MODERATE (24 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
AC: Access Control – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::AC-1 | AC-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::AC-11 | AC-11 Device Lock |
| nist-sp-800-53-rev-5-moderate::AC-11(1) | AC-11(1) Device Lock | Pattern-hiding Displays |
| nist-sp-800-53-rev-5-moderate::AC-12 | AC-12 Session Termination |
| nist-sp-800-53-rev-5-moderate::AC-14 | AC-14 Permitted Actions Without Identification or Authentication |
| nist-sp-800-53-rev-5-moderate::AC-17 | AC-17 Remote Access |
| nist-sp-800-53-rev-5-moderate::AC-17(1) | AC-17(1) Remote Access | Monitoring and Control |
| nist-sp-800-53-rev-5-moderate::AC-17(2) | AC-17(2) Remote Access | Protection of Confidentiality and Integrity Using Encryption |
| nist-sp-800-53-rev-5-moderate::AC-17(3) | AC-17(3) Remote Access | Managed Access Control Points |
| nist-sp-800-53-rev-5-moderate::AC-17(4) | AC-17(4) Remote Access | Privileged Commands and Access |
| nist-sp-800-53-rev-5-moderate::AC-18 | AC-18 Wireless Access |
| nist-sp-800-53-rev-5-moderate::AC-18(1) | AC-18(1) Wireless Access | Authentication and Encryption |
| nist-sp-800-53-rev-5-moderate::AC-18(3) | AC-18(3) Wireless Access | Disable Wireless Networking |
| nist-sp-800-53-rev-5-moderate::AC-19 | AC-19 Access Control for Mobile Devices |
| nist-sp-800-53-rev-5-moderate::AC-19(5) | AC-19(5) Access Control for Mobile Devices | Full Device or Container-based Encryption |
| nist-sp-800-53-rev-5-moderate::AC-2 | AC-2 Account Management |
| nist-sp-800-53-rev-5-moderate::AC-2(1) | AC-2(1) Account Management | Automated System Account Management |
| nist-sp-800-53-rev-5-moderate::AC-2(13) | AC-2(13) Account Management | Disable Accounts for High-risk Individuals |
| nist-sp-800-53-rev-5-moderate::AC-2(2) | AC-2(2) Account Management | Automated Temporary and Emergency Account Management |
| nist-sp-800-53-rev-5-moderate::AC-2(3) | AC-2(3) Account Management | Disable Accounts |
| nist-sp-800-53-rev-5-moderate::AC-2(4) | AC-2(4) Account Management | Automated Audit Actions |
| nist-sp-800-53-rev-5-moderate::AC-2(5) | AC-2(5) Account Management | Inactivity Logout |
| nist-sp-800-53-rev-5-moderate::AC-20 | AC-20 Use of External Systems |
| nist-sp-800-53-rev-5-moderate::AC-20(1) | AC-20(1) Use of External Systems | Limits on Authorized Use |
| nist-sp-800-53-rev-5-moderate::AC-20(2) | AC-20(2) Use of External Systems | Portable Storage Devices: Restricted Use |
| nist-sp-800-53-rev-5-moderate::AC-21 | AC-21 Information Sharing |
| nist-sp-800-53-rev-5-moderate::AC-22 | AC-22 Publicly Accessible Content |
| nist-sp-800-53-rev-5-moderate::AC-3 | AC-3 Access Enforcement |
| nist-sp-800-53-rev-5-moderate::AC-4 | AC-4 Information Flow Enforcement |
| nist-sp-800-53-rev-5-moderate::AC-5 | AC-5 Separation of Duties |
| nist-sp-800-53-rev-5-moderate::AC-6 | AC-6 Least Privilege |
| nist-sp-800-53-rev-5-moderate::AC-6(1) | AC-6(1) Least Privilege | Authorize Access to Security Functions |
| nist-sp-800-53-rev-5-moderate::AC-6(10) | AC-6(10) Least Privilege | Prohibit Non-privileged Users from Executing Privileged Functions |
| nist-sp-800-53-rev-5-moderate::AC-6(2) | AC-6(2) Least Privilege | Non-privileged Access for Nonsecurity Functions |
| nist-sp-800-53-rev-5-moderate::AC-6(5) | AC-6(5) Least Privilege | Privileged Accounts |
| nist-sp-800-53-rev-5-moderate::AC-6(7) | AC-6(7) Least Privilege | Review of User Privileges |
| nist-sp-800-53-rev-5-moderate::AC-6(9) | AC-6(9) Least Privilege | Log Use of Privileged Functions |
| nist-sp-800-53-rev-5-moderate::AC-7 | AC-7 Unsuccessful Logon Attempts |
| nist-sp-800-53-rev-5-moderate::AC-8 | AC-8 System Use Notification |
AT: Awareness and Training – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::AT-1 | AT-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::AT-2 | AT-2 Literacy Training and Awareness |
| nist-sp-800-53-rev-5-moderate::AT-2(2) | AT-2(2) Literacy Training and Awareness | Insider Threat |
| nist-sp-800-53-rev-5-moderate::AT-2(3) | AT-2(3) Literacy Training and Awareness | Social Engineering and Mining |
| nist-sp-800-53-rev-5-moderate::AT-3 | AT-3 Role-based Training |
| nist-sp-800-53-rev-5-moderate::AT-4 | AT-4 Training Records |
AU: Audit and Accountability – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::AU-1 | AU-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::AU-11 | AU-11 Audit Record Retention |
| nist-sp-800-53-rev-5-moderate::AU-12 | AU-12 Audit Record Generation |
| nist-sp-800-53-rev-5-moderate::AU-2 | AU-2 Event Logging |
| nist-sp-800-53-rev-5-moderate::AU-3 | AU-3 Content of Audit Records |
| nist-sp-800-53-rev-5-moderate::AU-3(1) | AU-3(1) Content of Audit Records | Additional Audit Information |
| nist-sp-800-53-rev-5-moderate::AU-4 | AU-4 Audit Log Storage Capacity |
| nist-sp-800-53-rev-5-moderate::AU-5 | AU-5 Response to Audit Logging Process Failures |
| nist-sp-800-53-rev-5-moderate::AU-6 | AU-6 Audit Record Review, Analysis, and Reporting |
| nist-sp-800-53-rev-5-moderate::AU-6(1) | AU-6(1) Audit Record Review, Analysis, and Reporting | Automated Process Integration |
| nist-sp-800-53-rev-5-moderate::AU-6(3) | AU-6(3) Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositories |
| nist-sp-800-53-rev-5-moderate::AU-7 | AU-7 Audit Record Reduction and Report Generation |
| nist-sp-800-53-rev-5-moderate::AU-7(1) | AU-7(1) Audit Record Reduction and Report Generation | Automatic Processing |
| nist-sp-800-53-rev-5-moderate::AU-8 | AU-8 Time Stamps |
| nist-sp-800-53-rev-5-moderate::AU-9 | AU-9 Protection of Audit Information |
| nist-sp-800-53-rev-5-moderate::AU-9(4) | AU-9(4) Protection of Audit Information | Access by Subset of Privileged Users |
CA: Assessment, Authorization, and Monitoring – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::CA-1 | CA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::CA-2 | CA-2 Control Assessments |
| nist-sp-800-53-rev-5-moderate::CA-2(1) | CA-2(1) Control Assessments | Independent Assessors |
| nist-sp-800-53-rev-5-moderate::CA-3 | CA-3 Information Exchange |
| nist-sp-800-53-rev-5-moderate::CA-5 | CA-5 Plan of Action and Milestones |
| nist-sp-800-53-rev-5-moderate::CA-6 | CA-6 Authorization |
| nist-sp-800-53-rev-5-moderate::CA-7 | CA-7 Continuous Monitoring |
| nist-sp-800-53-rev-5-moderate::CA-7(1) | CA-7(1) Continuous Monitoring | Independent Assessment |
| nist-sp-800-53-rev-5-moderate::CA-7(4) | CA-7(4) Continuous Monitoring | Risk Monitoring |
| nist-sp-800-53-rev-5-moderate::CA-9 | CA-9 Internal System Connections |
CM: Configuration Management – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::CM-1 | CM-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::CM-10 | CM-10 Software Usage Restrictions |
| nist-sp-800-53-rev-5-moderate::CM-11 | CM-11 User-installed Software |
| nist-sp-800-53-rev-5-moderate::CM-12 | CM-12 Information Location |
| nist-sp-800-53-rev-5-moderate::CM-12(1) | CM-12(1) Information Location | Automated Tools to Support Information Location |
| nist-sp-800-53-rev-5-moderate::CM-2 | CM-2 Baseline Configuration |
| nist-sp-800-53-rev-5-moderate::CM-2(2) | CM-2(2) Baseline Configuration | Automation Support for Accuracy and Currency |
| nist-sp-800-53-rev-5-moderate::CM-2(3) | CM-2(3) Baseline Configuration | Retention of Previous Configurations |
| nist-sp-800-53-rev-5-moderate::CM-2(7) | CM-2(7) Baseline Configuration | Configure Systems and Components for High-risk Areas |
| nist-sp-800-53-rev-5-moderate::CM-3 | CM-3 Configuration Change Control |
| nist-sp-800-53-rev-5-moderate::CM-3(2) | CM-3(2) Configuration Change Control | Testing, Validation, and Documentation of Changes |
| nist-sp-800-53-rev-5-moderate::CM-3(4) | CM-3(4) Configuration Change Control | Security and Privacy Representatives |
| nist-sp-800-53-rev-5-moderate::CM-4 | CM-4 Impact Analyses |
| nist-sp-800-53-rev-5-moderate::CM-4(2) | CM-4(2) Impact Analyses | Verification of Controls |
| nist-sp-800-53-rev-5-moderate::CM-5 | CM-5 Access Restrictions for Change |
| nist-sp-800-53-rev-5-moderate::CM-6 | CM-6 Configuration Settings |
| nist-sp-800-53-rev-5-moderate::CM-7 | CM-7 Least Functionality |
| nist-sp-800-53-rev-5-moderate::CM-7(1) | CM-7(1) Least Functionality | Periodic Review |
| nist-sp-800-53-rev-5-moderate::CM-7(2) | CM-7(2) Least Functionality | Prevent Program Execution |
| nist-sp-800-53-rev-5-moderate::CM-7(5) | CM-7(5) Least Functionality | Authorized Software: Allow-by-exception |
| nist-sp-800-53-rev-5-moderate::CM-8 | CM-8 System Component Inventory |
| nist-sp-800-53-rev-5-moderate::CM-8(1) | CM-8(1) System Component Inventory | Updates During Installation and Removal |
| nist-sp-800-53-rev-5-moderate::CM-8(3) | CM-8(3) System Component Inventory | Automated Unauthorized Component Detection |
| nist-sp-800-53-rev-5-moderate::CM-9 | CM-9 Configuration Management Plan |
CP: Contingency Planning – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::CP-1 | CP-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::CP-10 | CP-10 System Recovery and Reconstitution |
| nist-sp-800-53-rev-5-moderate::CP-10(2) | CP-10(2) System Recovery and Reconstitution | Transaction Recovery |
| nist-sp-800-53-rev-5-moderate::CP-2 | CP-2 Contingency Plan |
| nist-sp-800-53-rev-5-moderate::CP-2(1) | CP-2(1) Contingency Plan | Coordinate with Related Plans |
| nist-sp-800-53-rev-5-moderate::CP-2(3) | CP-2(3) Contingency Plan | Resume Mission and Business Functions |
| nist-sp-800-53-rev-5-moderate::CP-2(8) | CP-2(8) Contingency Plan | Identify Critical Assets |
| nist-sp-800-53-rev-5-moderate::CP-3 | CP-3 Contingency Training |
| nist-sp-800-53-rev-5-moderate::CP-4 | CP-4 Contingency Plan Testing |
| nist-sp-800-53-rev-5-moderate::CP-4(1) | CP-4(1) Contingency Plan Testing | Coordinate with Related Plans |
| nist-sp-800-53-rev-5-moderate::CP-6 | CP-6 Alternate Storage Site |
| nist-sp-800-53-rev-5-moderate::CP-6(1) | CP-6(1) Alternate Storage Site | Separation from Primary Site |
| nist-sp-800-53-rev-5-moderate::CP-6(3) | CP-6(3) Alternate Storage Site | Accessibility |
| nist-sp-800-53-rev-5-moderate::CP-7 | CP-7 Alternate Processing Site |
| nist-sp-800-53-rev-5-moderate::CP-7(1) | CP-7(1) Alternate Processing Site | Separation from Primary Site |
| nist-sp-800-53-rev-5-moderate::CP-7(2) | CP-7(2) Alternate Processing Site | Accessibility |
| nist-sp-800-53-rev-5-moderate::CP-7(3) | CP-7(3) Alternate Processing Site | Priority of Service |
| nist-sp-800-53-rev-5-moderate::CP-8 | CP-8 Telecommunications Services |
| nist-sp-800-53-rev-5-moderate::CP-8(1) | CP-8(1) Telecommunications Services | Priority of Service Provisions |
| nist-sp-800-53-rev-5-moderate::CP-8(2) | CP-8(2) Telecommunications Services | Single Points of Failure |
| nist-sp-800-53-rev-5-moderate::CP-9 | CP-9 System Backup |
| nist-sp-800-53-rev-5-moderate::CP-9(1) | CP-9(1) System Backup | Testing for Reliability and Integrity |
| nist-sp-800-53-rev-5-moderate::CP-9(8) | CP-9(8) System Backup | Cryptographic Protection |
IA: Identification and Authentication – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::IA-1 | IA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::IA-11 | IA-11 Re-authentication |
| nist-sp-800-53-rev-5-moderate::IA-12 | IA-12 Identity Proofing |
| nist-sp-800-53-rev-5-moderate::IA-12(2) | IA-12(2) Identity Proofing | Identity Evidence |
| nist-sp-800-53-rev-5-moderate::IA-12(3) | IA-12(3) Identity Proofing | Identity Evidence Validation and Verification |
| nist-sp-800-53-rev-5-moderate::IA-12(5) | IA-12(5) Identity Proofing | Address Confirmation |
| nist-sp-800-53-rev-5-moderate::IA-2 | IA-2 Identification and Authentication (Organizational Users) |
| nist-sp-800-53-rev-5-moderate::IA-2(1) | IA-2(1) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Privileged Accounts |
| nist-sp-800-53-rev-5-moderate::IA-2(12) | IA-2(12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials |
| nist-sp-800-53-rev-5-moderate::IA-2(2) | IA-2(2) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Non-privileged Accounts |
| nist-sp-800-53-rev-5-moderate::IA-2(8) | IA-2(8) Identification and Authentication (Organizational Users) | Access to Accounts: Replay Resistant |
| nist-sp-800-53-rev-5-moderate::IA-3 | IA-3 Device Identification and Authentication |
| nist-sp-800-53-rev-5-moderate::IA-4 | IA-4 Identifier Management |
| nist-sp-800-53-rev-5-moderate::IA-4(4) | IA-4(4) Identifier Management | Identify User Status |
| nist-sp-800-53-rev-5-moderate::IA-5 | IA-5 Authenticator Management |
| nist-sp-800-53-rev-5-moderate::IA-5(1) | IA-5(1) Authenticator Management | Password-based Authentication |
| nist-sp-800-53-rev-5-moderate::IA-5(2) | IA-5(2) Authenticator Management | Public Key-based Authentication |
| nist-sp-800-53-rev-5-moderate::IA-5(6) | IA-5(6) Authenticator Management | Protection of Authenticators |
| nist-sp-800-53-rev-5-moderate::IA-6 | IA-6 Authentication Feedback |
| nist-sp-800-53-rev-5-moderate::IA-7 | IA-7 Cryptographic Module Authentication |
| nist-sp-800-53-rev-5-moderate::IA-8 | IA-8 Identification and Authentication (Non-organizational Users) |
| nist-sp-800-53-rev-5-moderate::IA-8(1) | IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies |
| nist-sp-800-53-rev-5-moderate::IA-8(2) | IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators |
| nist-sp-800-53-rev-5-moderate::IA-8(4) | IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles |
IR: Incident Response – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::IR-1 | IR-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::IR-2 | IR-2 Incident Response Training |
| nist-sp-800-53-rev-5-moderate::IR-3 | IR-3 Incident Response Testing |
| nist-sp-800-53-rev-5-moderate::IR-3(2) | IR-3(2) Incident Response Testing | Coordination with Related Plans |
| nist-sp-800-53-rev-5-moderate::IR-4 | IR-4 Incident Handling |
| nist-sp-800-53-rev-5-moderate::IR-4(1) | IR-4(1) Incident Handling | Automated Incident Handling Processes |
| nist-sp-800-53-rev-5-moderate::IR-5 | IR-5 Incident Monitoring |
| nist-sp-800-53-rev-5-moderate::IR-6 | IR-6 Incident Reporting |
| nist-sp-800-53-rev-5-moderate::IR-6(1) | IR-6(1) Incident Reporting | Automated Reporting |
| nist-sp-800-53-rev-5-moderate::IR-6(3) | IR-6(3) Incident Reporting | Supply Chain Coordination |
| nist-sp-800-53-rev-5-moderate::IR-7 | IR-7 Incident Response Assistance |
| nist-sp-800-53-rev-5-moderate::IR-7(1) | IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support |
| nist-sp-800-53-rev-5-moderate::IR-8 | IR-8 Incident Response Plan |
MA: Maintenance – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::MA-1 | MA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::MA-2 | MA-2 Controlled Maintenance |
| nist-sp-800-53-rev-5-moderate::MA-3 | MA-3 Maintenance Tools |
| nist-sp-800-53-rev-5-moderate::MA-3(1) | MA-3(1) Maintenance Tools | Inspect Tools |
| nist-sp-800-53-rev-5-moderate::MA-3(2) | MA-3(2) Maintenance Tools | Inspect Media |
| nist-sp-800-53-rev-5-moderate::MA-3(3) | MA-3(3) Maintenance Tools | Prevent Unauthorized Removal |
| nist-sp-800-53-rev-5-moderate::MA-4 | MA-4 Nonlocal Maintenance |
| nist-sp-800-53-rev-5-moderate::MA-5 | MA-5 Maintenance Personnel |
| nist-sp-800-53-rev-5-moderate::MA-6 | MA-6 Timely Maintenance |
MP: Media Protection – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::MP-1 | MP-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::MP-2 | MP-2 Media Access |
| nist-sp-800-53-rev-5-moderate::MP-3 | MP-3 Media Marking |
| nist-sp-800-53-rev-5-moderate::MP-4 | MP-4 Media Storage |
| nist-sp-800-53-rev-5-moderate::MP-5 | MP-5 Media Transport |
| nist-sp-800-53-rev-5-moderate::MP-6 | MP-6 Media Sanitization |
| nist-sp-800-53-rev-5-moderate::MP-7 | MP-7 Media Use |
PE: Physical and Environmental Protection – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::PE-1 | PE-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::PE-10 | PE-10 Emergency Shutoff |
| nist-sp-800-53-rev-5-moderate::PE-11 | PE-11 Emergency Power |
| nist-sp-800-53-rev-5-moderate::PE-12 | PE-12 Emergency Lighting |
| nist-sp-800-53-rev-5-moderate::PE-13 | PE-13 Fire Protection |
| nist-sp-800-53-rev-5-moderate::PE-13(1) | PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification |
| nist-sp-800-53-rev-5-moderate::PE-14 | PE-14 Environmental Controls |
| nist-sp-800-53-rev-5-moderate::PE-15 | PE-15 Water Damage Protection |
| nist-sp-800-53-rev-5-moderate::PE-16 | PE-16 Delivery and Removal |
| nist-sp-800-53-rev-5-moderate::PE-17 | PE-17 Alternate Work Site |
| nist-sp-800-53-rev-5-moderate::PE-2 | PE-2 Physical Access Authorizations |
| nist-sp-800-53-rev-5-moderate::PE-3 | PE-3 Physical Access Control |
| nist-sp-800-53-rev-5-moderate::PE-4 | PE-4 Access Control for Transmission |
| nist-sp-800-53-rev-5-moderate::PE-5 | PE-5 Access Control for Output Devices |
| nist-sp-800-53-rev-5-moderate::PE-6 | PE-6 Monitoring Physical Access |
| nist-sp-800-53-rev-5-moderate::PE-6(1) | PE-6(1) Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment |
| nist-sp-800-53-rev-5-moderate::PE-8 | PE-8 Visitor Access Records |
| nist-sp-800-53-rev-5-moderate::PE-9 | PE-9 Power Equipment and Cabling |
PL: Planning – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::PL-1 | PL-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::PL-10 | PL-10 Baseline Selection |
| nist-sp-800-53-rev-5-moderate::PL-11 | PL-11 Baseline Tailoring |
| nist-sp-800-53-rev-5-moderate::PL-2 | PL-2 System Security and Privacy Plans |
| nist-sp-800-53-rev-5-moderate::PL-4 | PL-4 Rules of Behavior |
| nist-sp-800-53-rev-5-moderate::PL-4(1) | PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions |
| nist-sp-800-53-rev-5-moderate::PL-8 | PL-8 Security and Privacy Architectures |
PS: Personnel Security – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::PS-1 | PS-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::PS-2 | PS-2 Position Risk Designation |
| nist-sp-800-53-rev-5-moderate::PS-3 | PS-3 Personnel Screening |
| nist-sp-800-53-rev-5-moderate::PS-4 | PS-4 Personnel Termination |
| nist-sp-800-53-rev-5-moderate::PS-5 | PS-5 Personnel Transfer |
| nist-sp-800-53-rev-5-moderate::PS-6 | PS-6 Access Agreements |
| nist-sp-800-53-rev-5-moderate::PS-7 | PS-7 External Personnel Security |
| nist-sp-800-53-rev-5-moderate::PS-8 | PS-8 Personnel Sanctions |
| nist-sp-800-53-rev-5-moderate::PS-9 | PS-9 Position Descriptions |
RA: Risk Assessment – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::RA-1 | RA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::RA-2 | RA-2 Security Categorization |
| nist-sp-800-53-rev-5-moderate::RA-3 | RA-3 Risk Assessment |
| nist-sp-800-53-rev-5-moderate::RA-3(1) | RA-3(1) Risk Assessment | Supply Chain Risk Assessment |
| nist-sp-800-53-rev-5-moderate::RA-5 | RA-5 Vulnerability Monitoring and Scanning |
| nist-sp-800-53-rev-5-moderate::RA-5(11) | RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program |
| nist-sp-800-53-rev-5-moderate::RA-5(2) | RA-5(2) Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned |
| nist-sp-800-53-rev-5-moderate::RA-5(5) | RA-5(5) Vulnerability Monitoring and Scanning | Privileged Access |
| nist-sp-800-53-rev-5-moderate::RA-7 | RA-7 Risk Response |
| nist-sp-800-53-rev-5-moderate::RA-9 | RA-9 Criticality Analysis |
SA: System and Services Acquisition – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::SA-1 | SA-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::SA-10 | SA-10 Developer Configuration Management |
| nist-sp-800-53-rev-5-moderate::SA-11 | SA-11 Developer Testing and Evaluation |
| nist-sp-800-53-rev-5-moderate::SA-15 | SA-15 Development Process, Standards, and Tools |
| nist-sp-800-53-rev-5-moderate::SA-15(3) | SA-15(3) Development Process, Standards, and Tools | Criticality Analysis |
| nist-sp-800-53-rev-5-moderate::SA-2 | SA-2 Allocation of Resources |
| nist-sp-800-53-rev-5-moderate::SA-22 | SA-22 Unsupported System Components |
| nist-sp-800-53-rev-5-moderate::SA-3 | SA-3 System Development Life Cycle |
| nist-sp-800-53-rev-5-moderate::SA-4 | SA-4 Acquisition Process |
| nist-sp-800-53-rev-5-moderate::SA-4(1) | SA-4(1) Acquisition Process | Functional Properties of Controls |
| nist-sp-800-53-rev-5-moderate::SA-4(10) | SA-4(10) Acquisition Process | Use of Approved PIV Products |
| nist-sp-800-53-rev-5-moderate::SA-4(2) | SA-4(2) Acquisition Process | Design and Implementation Information for Controls |
| nist-sp-800-53-rev-5-moderate::SA-4(9) | SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use |
| nist-sp-800-53-rev-5-moderate::SA-5 | SA-5 System Documentation |
| nist-sp-800-53-rev-5-moderate::SA-8 | SA-8 Security and Privacy Engineering Principles |
| nist-sp-800-53-rev-5-moderate::SA-9 | SA-9 External System Services |
| nist-sp-800-53-rev-5-moderate::SA-9(2) | SA-9(2) External System Services | Identification of Functions, Ports, Protocols, and Services |
SC: System and Communications Protection – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::SC-1 | SC-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::SC-10 | SC-10 Network Disconnect |
| nist-sp-800-53-rev-5-moderate::SC-12 | SC-12 Cryptographic Key Establishment and Management |
| nist-sp-800-53-rev-5-moderate::SC-13 | SC-13 Cryptographic Protection |
| nist-sp-800-53-rev-5-moderate::SC-15 | SC-15 Collaborative Computing Devices and Applications |
| nist-sp-800-53-rev-5-moderate::SC-17 | SC-17 Public Key Infrastructure Certificates |
| nist-sp-800-53-rev-5-moderate::SC-18 | SC-18 Mobile Code |
| nist-sp-800-53-rev-5-moderate::SC-2 | SC-2 Separation of System and User Functionality |
| nist-sp-800-53-rev-5-moderate::SC-20 | SC-20 Secure Name/Address Resolution Service (Authoritative Source) |
| nist-sp-800-53-rev-5-moderate::SC-21 | SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| nist-sp-800-53-rev-5-moderate::SC-22 | SC-22 Architecture and Provisioning for Name/Address Resolution Service |
| nist-sp-800-53-rev-5-moderate::SC-23 | SC-23 Session Authenticity |
| nist-sp-800-53-rev-5-moderate::SC-28 | SC-28 Protection of Information at Rest |
| nist-sp-800-53-rev-5-moderate::SC-28(1) | SC-28(1) Protection of Information at Rest | Cryptographic Protection |
| nist-sp-800-53-rev-5-moderate::SC-39 | SC-39 Process Isolation |
| nist-sp-800-53-rev-5-moderate::SC-4 | SC-4 Information in Shared System Resources |
| nist-sp-800-53-rev-5-moderate::SC-5 | SC-5 Denial-of-service Protection |
| nist-sp-800-53-rev-5-moderate::SC-7 | SC-7 Boundary Protection |
| nist-sp-800-53-rev-5-moderate::SC-7(3) | SC-7(3) Boundary Protection | Access Points |
| nist-sp-800-53-rev-5-moderate::SC-7(4) | SC-7(4) Boundary Protection | External Telecommunications Services |
| nist-sp-800-53-rev-5-moderate::SC-7(5) | SC-7(5) Boundary Protection | Deny by Default: Allow by Exception |
| nist-sp-800-53-rev-5-moderate::SC-7(7) | SC-7(7) Boundary Protection | Split Tunneling for Remote Devices |
| nist-sp-800-53-rev-5-moderate::SC-7(8) | SC-7(8) Boundary Protection | Route Traffic to Authenticated Proxy Servers |
| nist-sp-800-53-rev-5-moderate::SC-8 | SC-8 Transmission Confidentiality and Integrity |
| nist-sp-800-53-rev-5-moderate::SC-8(1) | SC-8(1) Transmission Confidentiality and Integrity | Cryptographic Protection |
SI: System and Information Integrity – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::SI-1 | SI-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::SI-10 | SI-10 Information Input Validation |
| nist-sp-800-53-rev-5-moderate::SI-11 | SI-11 Error Handling |
| nist-sp-800-53-rev-5-moderate::SI-12 | SI-12 Information Management and Retention |
| nist-sp-800-53-rev-5-moderate::SI-16 | SI-16 Memory Protection |
| nist-sp-800-53-rev-5-moderate::SI-2 | SI-2 Flaw Remediation |
| nist-sp-800-53-rev-5-moderate::SI-2(2) | SI-2(2) Flaw Remediation | Automated Flaw Remediation Status |
| nist-sp-800-53-rev-5-moderate::SI-3 | SI-3 Malicious Code Protection |
| nist-sp-800-53-rev-5-moderate::SI-4 | SI-4 System Monitoring |
| nist-sp-800-53-rev-5-moderate::SI-4(2) | SI-4(2) System Monitoring | Automated Tools and Mechanisms for Real-time Analysis |
| nist-sp-800-53-rev-5-moderate::SI-4(4) | SI-4(4) System Monitoring | Inbound and Outbound Communications Traffic |
| nist-sp-800-53-rev-5-moderate::SI-4(5) | SI-4(5) System Monitoring | System-generated Alerts |
| nist-sp-800-53-rev-5-moderate::SI-5 | SI-5 Security Alerts, Advisories, and Directives |
| nist-sp-800-53-rev-5-moderate::SI-7 | SI-7 Software, Firmware, and Information Integrity |
| nist-sp-800-53-rev-5-moderate::SI-7(1) | SI-7(1) Software, Firmware, and Information Integrity | Integrity Checks |
| nist-sp-800-53-rev-5-moderate::SI-7(7) | SI-7(7) Software, Firmware, and Information Integrity | Integration of Detection and Response |
| nist-sp-800-53-rev-5-moderate::SI-8 | SI-8 Spam Protection |
| nist-sp-800-53-rev-5-moderate::SI-8(2) | SI-8(2) Spam Protection | Automatic Updates |
SR: Supply Chain Risk Management – NIST SP 800-53 Rev 5 MODERATE
| Code | Title |
|---|---|
| nist-sp-800-53-rev-5-moderate::SR-1 | SR-1 Policy and Procedures |
| nist-sp-800-53-rev-5-moderate::SR-10 | SR-10 Inspection of Systems or Components |
| nist-sp-800-53-rev-5-moderate::SR-11 | SR-11 Component Authenticity |
| nist-sp-800-53-rev-5-moderate::SR-11(1) | SR-11(1) Component Authenticity | Anti-counterfeit Training |
| nist-sp-800-53-rev-5-moderate::SR-11(2) | SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair |
| nist-sp-800-53-rev-5-moderate::SR-12 | SR-12 Component Disposal |
| nist-sp-800-53-rev-5-moderate::SR-2 | SR-2 Supply Chain Risk Management Plan |
| nist-sp-800-53-rev-5-moderate::SR-2(1) | SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team |
| nist-sp-800-53-rev-5-moderate::SR-3 | SR-3 Supply Chain Controls and Processes |
| nist-sp-800-53-rev-5-moderate::SR-5 | SR-5 Acquisition Strategies, Tools, and Methods |
| nist-sp-800-53-rev-5-moderate::SR-6 | SR-6 Supplier Assessments and Reviews |
| nist-sp-800-53-rev-5-moderate::SR-8 | SR-8 Notification Agreements |
Your Compliance Coverage
If you comply with NIST SP 800-53 Rev 5 MODERATE, you already cover:
Maps to 3 other frameworks
Coverage is not the same as your position
This page shows what NIST SP 800-53 Rev 5 MODERATE overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is NIST SP 800-53 Rev 5 MODERATE and who does it apply to?
NIST SP 800-53 Rev 5 MODERATE is a compliance framework from United States (federal information systems; voluntary for other organizations) with 18 domains and 287 controls. The moderate-impact security control baseline of NIST SP 800-53B (release 5.2.0): the 287 SP 800-53 Rev 5 controls and control enhancements a federal system categorized moderate under FIPS 199 and FIPS 200 starts from before tailoring, each with its release 5.2.0 control statement, parameters organization-defined, and the SP 800-53A Rev 5 examine and test objects an assessor asks for. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST SP 800-53 Rev 5 MODERATE actually require?
NIST SP 800-53 Rev 5 MODERATE has 287 controls organised across 18 domains. The largest domains are AC: Access Control – NIST SP 800-53 Rev 5 MODERATE (39 controls), SC: System and Communications Protection – NIST SP 800-53 Rev 5 MODERATE (25 controls), CM: Configuration Management – NIST SP 800-53 Rev 5 MODERATE (24 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST SP 800-53 Rev 5 MODERATE do I already cover?
NIST SP 800-53 Rev 5 MODERATE maps to 3 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (88% coverage), FedRAMP Moderate (88% coverage), FedRAMP High (87% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST SP 800-53 Rev 5 MODERATE?
Start your NIST SP 800-53 Rev 5 MODERATE compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-53 Rev 5 MODERATE requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 287 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required