Framework

NIST SP 800-53 Rev5

NIST SP 800-53 Rev 5 — Security and Privacy Controls

295 requirements · 158 connected unified controls

Open NIST SP 800-53 Rev5 in the map
Version
Rev. 5
Published
2020-09-23
Amendments
Release 5.2.0 (2025-08-27)

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

Access Control

RequirementUnified control and mapping
AC-1Policy and Procedures
AC-2Account Management
UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecyclePartial

Remaining requirement: periodic account review satisfied by the separate access review control

AC-3Access Enforcement
AC-4Information Flow Enforcement
AC-5Separation of Duties
AC-6Least Privilege
AC-7Unsuccessful Logon Attempts
AC-8System Use Notification
AC-9Previous Logon Notification
AC-10Concurrent Session Control
AC-11Device Lock
AC-12Session Termination
AC-14Permitted Actions Without Identification or Authentication
AC-16Security and Privacy Attributes
UC-ACCESS-05 — Enforce approved authorizations for information and functionsPartial

Remaining requirement: defining permitted attribute values and auditing/periodically reviewing attribute associations

AC-17Remote Access
AC-18Wireless Access
AC-19Access Control for Mobile Devices
AC-20Use of External Systems
AC-21Information Sharing
AC-22Publicly Accessible Content
AC-24Access Control Decisions
AC-25Reference Monitor

Awareness and Training

Audit and Accountability

RequirementUnified control and mapping
AU-1Policy and Procedures
AU-2Event Logging
AU-3Content of Audit Records
AU-4Audit Log Storage Capacity
AU-5Response to Audit Logging Process Failures
AU-6Audit Record Review, Analysis, and Reporting
AU-7Audit Record Reduction and Report Generation
AU-8Time Stamps
AU-9Protection of Audit Information
AU-10Non-repudiation
AU-11Audit Record Retention
AU-12Audit Record Generation
AU-13Monitoring for Information Disclosure
AU-14Session Audit
AU-16Cross-organizational Audit Logging

Assessment, Authorization, and Monitoring

Configuration Management

RequirementUnified control and mapping
CM-1Policy and Procedures
CM-2Baseline Configuration
CM-3Configuration Change Control
CM-4Impact Analyses
CM-5Access Restrictions for Change
CM-6Configuration Settings
CM-7Least Functionality
CM-8System Component Inventory
CM-9Configuration Management Plan
CM-10Software Usage Restrictions
CM-11User-installed Software
CM-12Information Location
UC-CONFIG-10 — Map where information resides and how data is processedPartial

Remaining requirement: documenting which users have access to components where information resides

CM-13Data Action Mapping
CM-14Signed Components

Contingency Planning

Identification and Authentication

RequirementUnified control and mapping
IA-1Policy and Procedures
IA-2Identification and Authentication (Organizational Users)
IA-3Device Identification and Authentication
IA-4Identifier Management
IA-5Authenticator Management
IA-6Authentication Feedback
IA-7Cryptographic Module Authentication
UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modulesPartial

Remaining requirement: operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication)

IA-8Identification and Authentication (Non-organizational Users)
IA-9Service Identification and Authentication
IA-10Adaptive Authentication
IA-11Re-authentication
IA-12Identity Proofing

Incident Response

Maintenance

Media Protection

Physical and Environmental Protection

RequirementUnified control and mapping
PE-1Policy and Procedures
PE-2Physical Access Authorizations
PE-3Physical Access Control
PE-4Access Control for Transmission
PE-5Access Control for Output Devices
PE-6Monitoring Physical Access
PE-8Visitor Access Records
PE-9Power Equipment and Cabling
PE-10Emergency Shutoff
PE-11Emergency Power
PE-12Emergency Lighting
PE-13Fire Protection
UC-PHYS-03 — Protect facilities against fire, water, and environmental hazardsPartial

Remaining requirement: fire detection/suppression systems must be supported by an independent energy source

PE-14Environmental Controls
PE-15Water Damage Protection
PE-16Delivery and Removal
PE-17Alternate Work Site
PE-18Location of System Components
PE-19Information Leakage
PE-20Asset Monitoring and Tracking
UC-PHYS-10 — Control and track asset delivery, removal, and movementPartial

Remaining requirement: tracking assets within defined controlled areas, not only outside them

PE-21Electromagnetic Pulse Protection
PE-22Component Marking
PE-23Facility Location

Planning

Program Management

RequirementUnified control and mapping
PM-1Information Security Program Plan
PM-2Information Security Program Leadership Role
PM-3Information Security and Privacy Resources
PM-4Plan of Action and Milestones Process
PM-5System Inventory
PM-6Measures of Performance
PM-7Enterprise Architecture
PM-8Critical Infrastructure Plan
UC-GOV-34 — Maintain business continuity and contingency planning policyPartial

Remaining requirement: a dedicated critical-infrastructure and key-resources protection plan addressing security and privacy, beyond naming critical infrastructure as a disruption source

PM-9Risk Management Strategy
PM-10Authorization Process
PM-11Mission and Business Process Definition
PM-12Insider Threat Program
PM-13Security and Privacy Workforce
PM-14Testing, Training, and Monitoring
PM-15Security and Privacy Groups and Associations
PM-16Threat Awareness Program
UC-GOV-37 — Operate insider-threat and threat-awareness programsPartial

Remaining requirement: PM-16 requires cross-organization (inter-organizational) threat-intelligence sharing, not only internal dissemination

PM-17Protecting Controlled Unclassified Information on External Systems
PM-18Privacy Program Plan
PM-19Privacy Program Leadership Role
PM-20Dissemination of Privacy Program Information
PM-21Accounting of Disclosures
PM-22Personally Identifiable Information Quality Management
PM-23Data Governance Body
PM-24Data Integrity Board
PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research
PM-26Complaint Management
PM-27Privacy Reporting
PM-28Risk Framing
PM-29Risk Management Program Leadership Roles
PM-30Supply Chain Risk Management Strategy
PM-31Continuous Monitoring Strategy
UC-GOV-33 — Maintain logging, monitoring, and system integrity policiesPartial

Remaining requirement: implementing the monitoring program - ongoing monitoring, correlation/analysis, response actions, and status reporting - satisfied by the continuous-monitoring companion control (CA-7 home)

PM-32Purposing

Personnel Security

Personally Identifiable Information Processing and Transparency

Risk Assessment

System and Services Acquisition

RequirementUnified control and mapping
SA-1Policy and Procedures
SA-2Allocation of Resources
SA-3System Development Life Cycle
SA-4Acquisition Process
SA-5System Documentation
SA-8Security and Privacy Engineering Principles
UC-SDLC-04 — Engineer systems with secure architecture and designPartial

Remaining requirement: privacy engineering principles in r5 scope (e.g., data minimization and privacy-by-default in design) satisfied by the software privacy-by-design companion control

SA-9External System Services
SA-10Developer Configuration Management
SA-11Developer Testing and Evaluation
SA-15Development Process, Standards, and Tools
SA-16Developer-provided Training
SA-17Developer Security and Privacy Architecture and Design
UC-SDLC-04 — Engineer systems with secure architecture and designPartial

Remaining requirement: developer privacy architecture and design description (SA-17 spans security AND privacy architecture) satisfied by the software privacy-by-design companion control

SA-20Customized Development of Critical Components
SA-21Developer Screening
SA-22Unsupported System Components
SA-23Specialization

System and Communications Protection

RequirementUnified control and mapping
SC-1Policy and Procedures
SC-2Separation of System and User Functionality
SC-3Security Function Isolation
SC-4Information in Shared System Resources
SC-5Denial-of-service Protection
SC-6Resource Availability
SC-7Boundary Protection
SC-8Transmission Confidentiality and Integrity
UC-CRYPTO-01 — Encrypt data at rest and in transitPartial

Remaining requirement: confidentiality of internal-network transmission - the statement scopes transit encryption to open/public/external networks, while SC-8 applies to internal paths as well

SC-10Network Disconnect
SC-11Trusted Path
SC-12Cryptographic Key Establishment and Management
SC-13Cryptographic Protection
SC-15Collaborative Computing Devices and Applications
SC-16Transmission of Security and Privacy Attributes
SC-17Public Key Infrastructure Certificates
UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecyclePartial

Remaining requirement: restricting managed trust stores to organization-approved trust anchors only

SC-18Mobile Code
SC-20Secure Name/Address Resolution Service (Authoritative Source)
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22Architecture and Provisioning for Name/Address Resolution Service
SC-23Session Authenticity
SC-24Fail in Known State
SC-25Thin Nodes
SC-26Decoys
SC-28Protection of Information at Rest
SC-29Heterogeneity
SC-30Concealment and Misdirection
SC-31Covert Channel Analysis
SC-32System Partitioning
SC-34Non-modifiable Executable Programs
SC-35External Malicious Code Identification
SC-36Distributed Processing and Storage
SC-37Out-of-band Channels
SC-38Operations Security
SC-39Process Isolation
SC-40Wireless Link Protection
SC-41Port and I/O Device Access
SC-42Sensor Capability and Data
SC-43Usage Restrictions
SC-44Detonation Chambers
SC-45System Time Synchronization
SC-46Cross Domain Policy Enforcement
SC-47Alternate Communications Paths
SC-48Sensor Relocation
SC-49Hardware-enforced Separation and Policy Enforcement
SC-50Software-enforced Separation and Policy Enforcement
SC-51Hardware-based Protection

System and Information Integrity

RequirementUnified control and mapping
SI-1Policy and Procedures
SI-2Flaw Remediation
SI-3Malicious Code Protection
SI-4System Monitoring
SI-5Security Alerts, Advisories, and Directives
SI-6Security and Privacy Function Verification
SI-7Software, Firmware, and Information Integrity
SI-8Spam Protection
SI-10Information Input Validation
SI-11Error Handling
SI-12Information Management and Retention
SI-13Predictable Failure Prevention
SI-14Non-persistence
SI-15Information Output Filtering
SI-16Memory Protection
SI-17Fail-safe Procedures
SI-18Personally Identifiable Information Quality Operations
SI-19De-identification
SI-20Tainting
SI-21Information Refresh
SI-22Information Diversity
SI-23Information Fragmentation

Supply Chain Risk Management