Security standard

NIST 800-53

NIST SP 800-53 Rev. 5 is the most comprehensive publicly available catalogue of security and privacy controls — over a thousand controls and enhancements across 20 families. It is mandatory for US federal systems and underpins FedRAMP, while commercially it serves as the most detailed reference for mature security programmes.

Start assessmentRead about the standard
186
controls in Guardiso
30
free-test questions
PL · EN
two languages

What is NIST SP 800-53?

Special Publication 800-53, “Security and Privacy Controls for Information Systems and Organizations”, is a control catalogue developed by the US National Institute of Standards and Technology. The current Revision 5 was published in September 2020 (with a later 5.1.1 update). Unlike framework-level documents such as the NIST CSF, 800-53 goes down to the level of individual, precisely defined safeguards — from access control policy to cryptographic requirements — along with control enhancements that raise the rigour of a given control.

Revision 5 introduced significant changes: it removed the word “federal” from the title, deliberately opening the catalogue to all organisations; integrated privacy controls with security controls (including the new PT family on personal data processing); added the SR family dedicated to supply chain risk; and reworded controls in an outcome-based style. The publication is accompanied by two sister documents: SP 800-53A (control assessment procedures) and SP 800-53B (control baselines). The entire catalogue is free and publicly available.

Who is it for?

For US federal agencies, 800-53 is mandatory: the FISMA statute and OMB policy require it, and the controls are implemented through the Risk Management Framework (NIST SP 800-37). The obligation extends to providers operating federal systems — in particular cloud providers, who must obtain a FedRAMP authorization built on the 800-53 controls. The related publication SP 800-171, required of contractors handling Controlled Unclassified Information (CUI), is also derived from this catalogue.

Outside the federal sector, 800-53 is chosen by organisations with high requirements: critical infrastructure, defence, finance, and technology companies planning to sell to the US government. The catalogue is also used as a “treasury” of controls — an organisation running its programme on ISO 27001 or the NIST CSF reaches into 800-53 for detailed requirements wherever more precision is needed. For a European SaaS company, familiarity with 800-53 becomes a practical necessity the moment it enters the US public sector market.

Control families and catalogue structure

The catalogue is organised into 20 control families identified by two-letter codes. Each control has an identifier (for example AC-2), base text, optional enhancements (for example AC-2(1)) and parameters that the organisation tailors for itself (for example review frequency). The most important families are:

  • AC — access control; IA — identification and authentication (including MFA); AU — audit and accountability (event logging).
  • CM — configuration management (baselines, changes, inventory); SI — system and information integrity (patching, anti-malware, monitoring); RA — risk assessment and vulnerability scanning.
  • IR — incident response; CP — contingency planning (contingency plans, backups); PE — physical protection; MP — media protection; PS — personnel security.
  • SC — system and communications protection (network boundaries, cryptography); SA — system acquisition and secure development; SR — supply chain risk (new in Rev. 5).
  • AT — awareness and training; CA — assessment, authorization and monitoring; PL — planning; PM — programme management; PT — PII processing and transparency (new in Rev. 5).

The Low / Moderate / High baselines

Nobody implements the entire catalogue at once. NIST SP 800-53B defines three security baselines — Low, Moderate and High — curated sets of controls corresponding to the impact that a loss of the system’s confidentiality, integrity or availability would have. System categorisation follows the FIPS 199 standard: a system whose compromise would have limited impact lands in the Low baseline; serious impact — Moderate; catastrophic — High. A separate privacy baseline covers controls related to personal data processing.

A baseline is a starting point, not a final answer: the organisation performs tailoring — adapting the control set to its own risk by adding, removing (with justification) and parameterising controls. As an order of magnitude: the Low baseline is roughly 150 controls, Moderate around 300, and High over 400 (exact numbers depend on the baseline version and whether enhancements are counted). In commercial practice the Moderate baseline is chosen most often — it matches a typical system processing sensitive but not life- or national-security-critical data.

Relationship to FedRAMP and the RMF

FedRAMP (the Federal Risk and Authorization Management Program) is the US government’s authorization programme for cloud services — and in practice the most important commercial pathway for applying 800-53. The FedRAMP baselines (Low, Moderate, High) are built from 800-53 Rev. 5 controls with additional parameters and programme requirements. The road to authorization includes preparing full documentation (above all the System Security Plan), an independent assessment by an accredited 3PAO, remediation of findings, and authorization; afterwards continuous monitoring applies — including monthly vulnerability scans and annual reassessments. It is a months-long, costly process, but it opens the US federal procurement market.

The operational frame for 800-53 is the Risk Management Framework (NIST SP 800-37): seven steps — prepare, categorise the system, select controls (baseline + tailoring), implement, assess (per SP 800-53A procedures), authorize to operate (ATO) and continuously monitor. The characteristic artefacts of this world are the SSP (System Security Plan), the SAR (Security Assessment Report) and the POA&M (Plan of Action and Milestones for open weaknesses) — the same documents every 800-53 assessor asks for, including outside the public sector.

How does Guardiso help?

Guardiso turns the vast 800-53 catalogue into a manageable programme: controls with owners and statuses, evidence collected continuously, and mappings so that work done for other standards counts towards 800-53 requirements.

  • NIST 800-53 Rev. 5 controls seeded automatically when you enable the standard — the full MODERATE baseline per SP 800-53B (177 base controls) plus the PM and PT families, with implementation statuses and assigned owners.
  • A per-area self-assessment showing maturity against the catalogue — a quick answer to “how far are we from the Moderate baseline”.
  • A risk register supporting categorisation and tailoring — control selection decisions documented and tied to risk.
  • A control register with statuses and evidence acting as a working counterpart of the SSP, with open gaps tracked like POA&M items — with owners and deadlines.
  • Evidence collected in one place: access reviews, training, vulnerability scans, restore tests, the incident register.
  • Cross-mapping to ISO 27001, SOC 2 and the NIST CSF — an implemented control counts towards the overlapping requirements of the other frameworks, without duplicate work.
  • A supplier register with risk assessment supporting the SA and SR families — contractual requirements and periodic supplier reviews.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
NIST 800-53 readiness score
0/30 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards