Back to Frameworks

NIST SP 800-53A Rev. 5

United States
vRev 5
4 domains
30 controls

NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations. This node models the assessment methodology the publication defines: how a control decomposes into determination statements, the examine, interview and test methods with their depth and coverage attributes, and the process of preparing, planning, tailoring, conducting, analysing and reporting an assessment. The per-control assessment procedures in Chapter Four map one-to-one onto SP 800-53 Rev 5 controls and are held on that framework node.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Appendices D to F: Penetration Testing, Reporting and Ongoing Assessment

3 controls
Controls in the Appendices D to F: Penetration Testing, Reporting and Ongoing Assessment domain of NIST SP 800-53A Rev. 53 controls
CodeTitle
53A-DPenetration Testing
53A-EAssessment Reports
53A-FOngoing Assessment and Automation

Appendix C: Assessment Methods and Attributes

5 controls
Controls in the Appendix C: Assessment Methods and Attributes domain of NIST SP 800-53A Rev. 55 controls
CodeTitle
53A-C-COVERAGEAssessment Attribute: Coverage
53A-C-DEPTHAssessment Attribute: Depth
53A-C-EXAMINEAssessment Method: Examine
53A-C-INTERVIEWAssessment Method: Interview
53A-C-TESTAssessment Method: Test

Chapter Three: The Assessment Process

16 controls
Controls in the Chapter Three: The Assessment Process domain of NIST SP 800-53A Rev. 516 controls
CodeTitle
53A-3.1Prepare for Control Assessments
53A-3.2.1Determine Which Controls Are to Be Assessed
53A-3.2.2Select Procedures to Assess the Controls
53A-3.2.3Tailor Assessment Procedures
53A-3.2.3.1Method and Object Considerations in Tailoring
53A-3.2.3.2Depth and Coverage Considerations in Tailoring
53A-3.2.3.3Common Control Considerations in Tailoring
53A-3.2.3.4System, Platform and Organization Considerations in Tailoring
53A-3.2.3.5Reuse of Assessment Evidence
53A-3.2.3.6External System Considerations
53A-3.2.4Develop Procedures for Organization-Specific Controls
53A-3.2.5Optimize Selected Assessment Procedures
53A-3.2.6Finalize the Assessment Plan and Obtain Approval
53A-3.3Conduct Control Assessments
53A-3.4Analyze Assessment Report Results
53A-3.5Assess Security and Privacy Capabilities

Chapter Two: The Fundamentals

6 controls
Controls in the Chapter Two: The Fundamentals domain of NIST SP 800-53A Rev. 56 controls
CodeTitle
53A-2.1Assessments Within the System Development Life Cycle
53A-2.2Control Structure and Organization
53A-2.3Building an Effective Assurance Case
53A-2.4.1Assessment Objects
53A-2.4.2Assessment Methods
53A-2.4.3Assessment Objectives and Determination Statements

Your Compliance Coverage

If you comply with NIST SP 800-53A Rev. 5, you already cover:

Maps to 19 other frameworks

30 total controls
FedRAMP Moderate
14 source controls mapped|15 target controls covered
47%
FedRAMP High
14 source controls mapped|15 target controls covered
47%
NIST SP 800-53 Rev 5
11 source controls mapped|9 target controls covered
37%
NIST SP 800-53 Revision 5.1 HIGH
10 source controls mapped|11 target controls covered
33%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
9 source controls mapped|7 target controls covered
30%
NIST SP 800-53 Rev 5 MODERATE
8 source controls mapped|9 target controls covered
27%
NIST SP 800-53 Rev 5 LOW
6 source controls mapped|6 target controls covered
20%
SOC 2
5 source controls mapped|2 target controls covered
17%
NIST SP 800-171 Rev 3
5 source controls mapped|3 target controls covered
17%
CMMC 2.0
5 source controls mapped|3 target controls covered
17%
NIST Cybersecurity Framework 2.0
5 source controls mapped|3 target controls covered
17%
ISO 27002:2022
5 source controls mapped|2 target controls covered
17%
ISO 27001:2022
5 source controls mapped|2 target controls covered
17%
CIS Controls v8
5 source controls mapped|5 target controls covered
17%
PCI DSS 4.0
4 source controls mapped|5 target controls covered
13%
ISO 22301:2019
4 source controls mapped|4 target controls covered
13%
HIPAA Security Rule
3 source controls mapped|1 target controls covered
10%
NIST SP 800-66 Rev 2
3 source controls mapped|1 target controls covered
10%
Azure Security Benchmark
1 source controls mapped|2 target controls covered
3%

Frequently Asked Questions

What is NIST SP 800-53A Rev. 5?

NIST SP 800-53A Rev. 5 is a compliance framework from United States with 4 domains and 30 controls. NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations. This node models the assessment methodology the publication defines: how a control decomposes into determination statements, the examine, interview and test methods with their depth and coverage attributes, and the process of preparing, planning, tailoring, conducting, analysing and reporting an assessment. The per-control assessment procedures in Chapter Four map one-to-one onto SP 800-53 Rev 5 controls and are held on that framework node. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-53A Rev. 5 have?

NIST SP 800-53A Rev. 5 has 30 controls organised across 4 domains. The largest domains are Chapter Three: The Assessment Process (16 controls), Chapter Two: The Fundamentals (6 controls), Appendix C: Assessment Methods and Attributes (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-53A Rev. 5 map to?

NIST SP 800-53A Rev. 5 maps to 19 other compliance frameworks. The top mapping partners are FedRAMP Moderate (47% coverage), FedRAMP High (47% coverage), NIST SP 800-53 Rev 5 (37% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-53A Rev. 5 compliance?

Start your NIST SP 800-53A Rev. 5 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-53A Rev. 5 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required