Framework
NIST SP 800-53 Rev5
NIST SP 800-53 Rev 5 — Security and Privacy Controls
295 requirements · 158 connected unified controls
Open NIST SP 800-53 Rev5 in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
Access Control
Awareness and Training
| Requirement | Unified control and mapping |
|---|---|
| AT-1Policy and Procedures | |
| AT-2Literacy Training and Awareness | |
| AT-3Role-based Training | |
| AT-4Training Records | |
| AT-6Training Feedback |
Audit and Accountability
| Requirement | Unified control and mapping |
|---|---|
| AU-1Policy and Procedures | |
| AU-2Event Logging | |
| AU-3Content of Audit Records | |
| AU-4Audit Log Storage Capacity | |
| AU-5Response to Audit Logging Process Failures | |
| AU-6Audit Record Review, Analysis, and Reporting | |
| AU-7Audit Record Reduction and Report Generation | |
| AU-8Time Stamps | |
| AU-9Protection of Audit Information | |
| AU-10Non-repudiation | |
| AU-11Audit Record Retention | |
| AU-12Audit Record Generation | |
| AU-13Monitoring for Information Disclosure | |
| AU-14Session Audit | |
| AU-16Cross-organizational Audit Logging |
Assessment, Authorization, and Monitoring
| Requirement | Unified control and mapping |
|---|---|
| CA-1Policy and Procedures | |
| CA-2Control Assessments | |
| CA-3Information Exchange | |
| CA-5Plan of Action and Milestones | |
| CA-6Authorization | |
| CA-7Continuous Monitoring | |
| CA-8Penetration Testing | |
| CA-9Internal System Connections | UC-AUDIT-26 — Authorize systems and internal connections before operationPartial Remaining requirement: periodic review of each internal connection's continued need and termination when no longer required (CA-9(c)-(d)) |
Configuration Management
| Requirement | Unified control and mapping |
|---|---|
| CM-1Policy and Procedures | |
| CM-2Baseline Configuration | |
| CM-3Configuration Change Control | |
| CM-4Impact Analyses | |
| CM-5Access Restrictions for Change | |
| CM-6Configuration Settings | |
| CM-7Least Functionality | |
| CM-8System Component Inventory | |
| CM-9Configuration Management Plan | |
| CM-10Software Usage Restrictions | |
| CM-11User-installed Software | |
| CM-12Information Location | UC-CONFIG-10 — Map where information resides and how data is processedPartial Remaining requirement: documenting which users have access to components where information resides |
| CM-13Data Action Mapping | |
| CM-14Signed Components |
Contingency Planning
| Requirement | Unified control and mapping |
|---|---|
| CP-1Policy and Procedures | |
| CP-2Contingency Plan | |
| CP-3Contingency Training | |
| CP-4Contingency Plan Testing | |
| CP-6Alternate Storage Site | |
| CP-7Alternate Processing Site | |
| CP-8Telecommunications Services | |
| CP-9System Backup | |
| CP-10System Recovery and Reconstitution | |
| CP-11Alternate Communications Protocols | |
| CP-12Safe Mode | |
| CP-13Alternative Security Mechanisms |
Identification and Authentication
| Requirement | Unified control and mapping |
|---|---|
| IA-1Policy and Procedures | |
| IA-2Identification and Authentication (Organizational Users) | |
| IA-3Device Identification and Authentication | |
| IA-4Identifier Management | |
| IA-5Authenticator Management | |
| IA-6Authentication Feedback | |
| IA-7Cryptographic Module Authentication | UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modulesPartial Remaining requirement: operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication) |
| IA-8Identification and Authentication (Non-organizational Users) | |
| IA-9Service Identification and Authentication | |
| IA-10Adaptive Authentication | |
| IA-11Re-authentication | |
| IA-12Identity Proofing |
Incident Response
| Requirement | Unified control and mapping |
|---|---|
| IR-1Policy and Procedures | |
| IR-2Incident Response Training | |
| IR-3Incident Response Testing | |
| IR-4Incident Handling | UC-IR-06 — Respond to, contain, and eradicate declared incidentsPartial Remaining requirement: IR-4's preparation and detection/analysis phases satisfied by the IR-planning and continuous-monitoring companion controls; this UC begins at incident declaration |
| IR-5Incident Monitoring | |
| IR-6Incident Reporting | |
| IR-7Incident Response Assistance | |
| IR-8Incident Response Plan | |
| IR-9Information Spillage Response |
Maintenance
| Requirement | Unified control and mapping |
|---|---|
| MA-1Policy and Procedures | |
| MA-2Controlled Maintenance | |
| MA-3Maintenance Tools | |
| MA-4Nonlocal Maintenance | |
| MA-5Maintenance Personnel | |
| MA-6Timely Maintenance | |
| MA-7Field Maintenance | UC-CONFIG-07 — Perform controlled, timely maintenance of systems and hardwarePartial Remaining requirement: restricting or prohibiting field maintenance to designated trusted maintenance facilities |
Media Protection
| Requirement | Unified control and mapping |
|---|---|
| MP-1Policy and Procedures | |
| MP-2Media Access | |
| MP-3Media Marking | |
| MP-4Media Storage | |
| MP-5Media Transport | |
| MP-6Media Sanitization | |
| MP-7Media Use | |
| MP-8Media Downgrading |
Physical and Environmental Protection
Planning
| Requirement | Unified control and mapping |
|---|---|
| PL-1Policy and Procedures | |
| PL-2System Security and Privacy Plans | |
| PL-4Rules of Behavior | |
| PL-7Concept of Operations | |
| PL-8Security and Privacy Architectures | |
| PL-9Central Management | |
| PL-10Baseline Selection | |
| PL-11Baseline Tailoring |
Program Management
Personnel Security
| Requirement | Unified control and mapping |
|---|---|
| PS-1Policy and Procedures | |
| PS-2Position Risk Designation | |
| PS-3Personnel Screening | |
| PS-4Personnel Termination | |
| PS-5Personnel Transfer | |
| PS-6Access Agreements | |
| PS-7External Personnel Security | |
| PS-8Personnel Sanctions | |
| PS-9Position Descriptions |
Personally Identifiable Information Processing and Transparency
| Requirement | Unified control and mapping |
|---|---|
| PT-1Policy and Procedures | UC-GOV-26 — Enforce personal-data processing principles and minimizationPartial Remaining requirement: PT-family policy governance of transparency mechanisms - consent, privacy notices, and system-of-records notices - satisfied by the companion notice and consent controls |
| PT-2Authority to Process Personally Identifiable Information | |
| PT-3Personally Identifiable Information Processing Purposes | |
| PT-4Consent | |
| PT-5Privacy Notice | |
| PT-6System of Records Notice | |
| PT-7Specific Categories of Personally Identifiable Information | |
| PT-8Computer Matching Requirements |
Risk Assessment
| Requirement | Unified control and mapping |
|---|---|
| RA-1Policy and Procedures | |
| RA-2Security Categorization | |
| RA-3Risk Assessment | |
| RA-5Vulnerability Monitoring and Scanning | |
| RA-7Risk Response | |
| RA-8Privacy Impact Assessments | UC-RISK-16 — Conduct privacy impact assessments for high-risk processingPartial Remaining requirement: RA-8 mandates PIAs for any PII-processing IT and new collections, not only high-risk |
| RA-9Criticality Analysis | |
| RA-10Threat Hunting |
System and Services Acquisition
System and Communications Protection
System and Information Integrity
| Requirement | Unified control and mapping |
|---|---|
| SI-1Policy and Procedures | |
| SI-2Flaw Remediation | |
| SI-3Malicious Code Protection | |
| SI-4System Monitoring | |
| SI-5Security Alerts, Advisories, and Directives | |
| SI-6Security and Privacy Function Verification | |
| SI-7Software, Firmware, and Information Integrity | |
| SI-8Spam Protection | |
| SI-10Information Input Validation | |
| SI-11Error Handling | |
| SI-12Information Management and Retention | |
| SI-13Predictable Failure Prevention | |
| SI-14Non-persistence | |
| SI-15Information Output Filtering | |
| SI-16Memory Protection | |
| SI-17Fail-safe Procedures | |
| SI-18Personally Identifiable Information Quality Operations | |
| SI-19De-identification | |
| SI-20Tainting | |
| SI-21Information Refresh | |
| SI-22Information Diversity | |
| SI-23Information Fragmentation |
Supply Chain Risk Management
| Requirement | Unified control and mapping |
|---|---|
| SR-1Policy and Procedures | |
| SR-2Supply Chain Risk Management Plan | |
| SR-3Supply Chain Controls and Processes | |
| SR-4Provenance | |
| SR-5Acquisition Strategies, Tools, and Methods | |
| SR-6Supplier Assessments and Reviews | |
| SR-7Supply Chain Operations Security | |
| SR-8Notification Agreements | |
| SR-9Tamper Resistance and Detection | |
| SR-10Inspection of Systems or Components | |
| SR-11Component Authenticity | |
| SR-12Component Disposal |