What is NIST 800-53?
NIST Special Publication 800-53 provides a catalog of security and privacy controls for information systems and organizations. It's the primary security framework for US federal agencies and is widely adopted by private sector organizations as a comprehensive security baseline.
Control Families (Rev. 5)
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Assessment, Authorization (CA)
- Configuration Management (CM)
- Contingency Planning (CP)
- Identification and Authentication (IA)
- Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Physical and Environmental (PE)
- Planning (PL)
- Program Management (PM)
- Personnel Security (PS)
- PII Processing (PT) (new in Rev. 5)
- Risk Assessment (RA)
- System and Services Acquisition (SA)
- System and Communications (SC)
- System and Information Integrity (SI)
- Supply Chain Risk Management (SR) (new in Rev. 5)
Control Baselines
Low Impact: Basic controls Moderate Impact: Enhanced controls High Impact: Comprehensive controls
Key Changes in Rev. 5
- Outcome-based control language
- Privacy controls integrated
- Supply chain risk management
- State-of-the-practice updates
- Flexible implementation