Directive NIS2 European Union
Revision 5 · Rev. 5

NIST SP 800-53 — Security and Privacy Controls for Information Systems and Organizations

NIS2 says what you must achieve, never how you demonstrate it. NIST 800-53 is the reference published for that purpose. If you operate there, this is what your regulator reads.

Assurance levels
3
Controls at High
370
Member states using it
0

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

NIST SP 800-53 is a US federal control catalogue. It is not a European compliance route and no supervisor will accept it as one: it carries no certification, and mapping to it does not evidence NIS2 compliance. Its value here is different and real — a group that already operates an 800-53 control set, typically because of US federal or defence work, can see which families already carry each article 21(2) measure instead of rebuilding from nothing.

We put that first because it is the most expensive misunderstanding about any national framework. For a European compliance route use ISO/IEC 27001 or the national framework. Use 800-53 to reuse work already done, not to demonstrate compliance.

Assurance levels

3 tiers, cumulative


Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.

NIST 800-53 levels with the number of controls each adds and the cumulative total
Level Adds Cumulative Intended for
Low 149 149 Systems whose loss would have limited adverse impact
Moderate 138 287 Systems whose loss would have serious adverse impact
High 83 370 Systems whose loss would have severe or catastrophic impact
Low · +149 controls

The smallest baseline of SP 800-53B. It is a selection from the catalogue, not the catalogue itself.

Moderate · +138 controls

Adds 138 controls and enhancements on top of Low, and contains it entirely.

High · +83 controls

Adds 83 further controls. The remaining controls of the catalogue belong to no baseline at all and are selected by tailoring.

What it is built on

NIST 800-53 does not invent its own taxonomy. It sits on A control catalogue organised into families, with baselines selected by system impact level.

Revision 5 organises the catalogue into 20 control families, up from 18 in Rev. 4: PT (PII processing and transparency) and SR (supply chain risk management) were added. Controls are selected through baselines and tailoring rather than adopted wholesale.

Mapping

How it covers the ten NIS2 measures


Article 21(2) is the article of NIS2 — Directive (EU) 2022/2555 — that lists the ten risk-management measures every entity in scope owes, lettered (a) to (j). Those ten letters are the first column of each table on this page, and the keys every mapping we publish hangs off. The ten measures, one by one.

Basis

Family-level mapping. Each article 21(2) measure is mapped to the families that carry the relevant controls. Family identifiers are stable across the revision and publicly documented.

Limit of this mapping

Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Mapped at the level of
NIST SP 800-53 Rev. 5 control family
Units in the framework
20
Units carrying article 21(2)
19
Each of the ten risk-management measures of article 21(2), mapped to the NIST SP 800-53 Rev. 5 control family units of NIST 800-53
NIS2 art. 21(2) Directive (EU) 2022/2555 Measure NIST 800-53 — NIST SP 800-53 Rev. 5 control family
(a) Risk analysis and security policies RA PL PM
(b) Incident handling IR AU SI
(c) Business continuity CP PE
(d) Supply chain security SR SA
(e) Security in acquisition, development and maintenance SA CM MA RA SI
(f) Assessing the effectiveness of the measures CA PM
(g) Basic cyber hygiene and cybersecurity training AT SI CM
(h) Cryptography and encryption SC
(i) Human resources security, access control and asset management PS AC IA CM MP PE
(j) Multi-factor authentication and secured communications IA AC SC
20 NIST SP 800-53 Rev. 5 control family units, in full
  • AC — Access Control
  • AT — Awareness and Training
  • AU — Audit and Accountability
  • CA — Assessment, Authorization and Monitoring
  • CM — Configuration Management
  • CP — Contingency Planning
  • IA — Identification and Authentication
  • IR — Incident Response
  • MA — Maintenance
  • MP — Media Protection
  • PE — Physical and Environmental Protection
  • PL — Planning
  • PM — Program Management
  • PS — Personnel Security
  • PT — PII Processing and Transparency
  • RA — Risk Assessment
  • SA — System and Services Acquisition
  • SC — System and Communications Protection
  • SI — System and Information Integrity
  • SR — Supply Chain Risk Management
Measure catalogue

1196 controls, and the level each one enters at


A mapping says which of the ten measures a framework serves. A catalogue says which control, at which level. Here are all 1196, as National Institute of Standards and Technology (NIST) publishes them.

Controls
1196
Families
20
Base controls
324
In no level
826

Published by National Institute of Standards and Technology (NIST), under Work of the US federal government: not subject to copyright in the United States, and published for reuse.

NIST, SP 800-53 Rev. 5 and SP 800-53B baselines — Work of the US federal government: not subject to copyright in the United States, and published for reuse.. Structure and counts here are derived from that publication; identifiers and wording are theirs.

  • NIST, SP 800-53 Rev. 5 control catalogue, OSCAL edition 5.2.0
  • NIST, SP 800-53B control baselines (Low, Moderate, High), OSCAL profiles

Get the official documents from https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final — the framework and everything published with it belong to its owner, and that publication is the version that binds. Work of the US federal government: public domain.

  • Levels here are the SP 800-53B baselines. They are strictly nested — Low is contained in Moderate, Moderate in High — which is checked on every extraction.
  • 826 controls sit in no baseline at all: they are selected by tailoring, and 182 of those are withdrawn controls kept for traceability.
  • Control titles are reproduced; the full control text is not. It is public domain and one click away at NIST, and 1,196 statements would bury the page.
  • NIST publishes no crosswalk to article 21(2). The letters shown on the page are our own thematic mapping, at family level, and they are not part of this file.

What each level adds

Depth here is one thing: how many more controls the next level pulls in. Each level contains everything below it, which is checked on every extraction.

NIST 800-53 levels: controls added, cumulative total
Level Adds Cumulative
Low +149 149
Moderate +138 287
High +83 370
In no levelselected by tailoring +826 1196

The catalogue, control by control

20 families, 20 families, 1196 controls. Each row carries the level at which it becomes due.

Access Control  · 147 controls

Access Control (AC)

Our thematic mapping puts this group against (i) (j)

NIST 800-53 controls in AC, Access Control
Control Level Title
AC-01 Low Policy and Procedures
AC-02 Low Account Management
AC-02(01) Moderate Automated System Account Management
AC-02(02) Moderate Automated Temporary and Emergency Account Management
AC-02(03) Moderate Disable Accounts
AC-02(04) Moderate Automated Audit Actions
AC-02(05) Moderate Inactivity Logout
AC-02(06) Tailoring only Dynamic Privilege Management
AC-02(07) Tailoring only Privileged User Accounts
AC-02(08) Tailoring only Dynamic Account Management
AC-02(09) Tailoring only Restrictions on Use of Shared and Group Accounts
AC-02(10) withdrawn → AC-2_SMT.K Tailoring only Shared and Group Account Credential Change
AC-02(11) High Usage Conditions
AC-02(12) High Account Monitoring for Atypical Usage
AC-02(13) Moderate Disable Accounts for High-risk Individuals
AC-03 Low Access Enforcement
AC-03(01) withdrawn → AC-06 Tailoring only Restricted Access to Privileged Functions
AC-03(02) Tailoring only Dual Authorization
AC-03(03) Tailoring only Mandatory Access Control
AC-03(04) Tailoring only Discretionary Access Control
AC-03(05) Tailoring only Security-relevant Information
AC-03(06) withdrawn → MP-04, SC-28 Tailoring only Protection of User and System Information
AC-03(07) Tailoring only Role-based Access Control
AC-03(08) Tailoring only Revocation of Access Authorizations
AC-03(09) Tailoring only Controlled Release
AC-03(10) Tailoring only Audited Override of Access Control Mechanisms
AC-03(11) Tailoring only Restrict Access to Specific Information Types
AC-03(12) Tailoring only Assert and Enforce Application Access
AC-03(13) Tailoring only Attribute-based Access Control
AC-03(14) Tailoring only Individual Access
AC-03(15) Tailoring only Discretionary and Mandatory Access Control
AC-04 Moderate Information Flow Enforcement
AC-04(01) Tailoring only Object Security and Privacy Attributes
AC-04(02) Tailoring only Processing Domains
AC-04(03) Tailoring only Dynamic Information Flow Control
AC-04(04) High Flow Control of Encrypted Information
AC-04(05) Tailoring only Embedded Data Types
AC-04(06) Tailoring only Metadata
AC-04(07) Tailoring only One-way Flow Mechanisms
AC-04(08) Tailoring only Security and Privacy Policy Filters
AC-04(09) Tailoring only Human Reviews
AC-04(10) Tailoring only Enable and Disable Security or Privacy Policy Filters
AC-04(11) Tailoring only Configuration of Security or Privacy Policy Filters
AC-04(12) Tailoring only Data Type Identifiers
AC-04(13) Tailoring only Decomposition into Policy-relevant Subcomponents
AC-04(14) Tailoring only Security or Privacy Policy Filter Constraints
AC-04(15) Tailoring only Detection of Unsanctioned Information
AC-04(16) withdrawn → AC-04 Tailoring only Information Transfers on Interconnected Systems
AC-04(17) Tailoring only Domain Authentication
AC-04(18) withdrawn → AC-16 Tailoring only Security Attribute Binding
AC-04(19) Tailoring only Validation of Metadata
AC-04(20) Tailoring only Approved Solutions
AC-04(21) Tailoring only Physical or Logical Separation of Information Flows
AC-04(22) Tailoring only Access Only
AC-04(23) Tailoring only Modify Non-releasable Information
AC-04(24) Tailoring only Internal Normalized Format
AC-04(25) Tailoring only Data Sanitization
AC-04(26) Tailoring only Audit Filtering Actions
AC-04(27) Tailoring only Redundant/Independent Filtering Mechanisms
AC-04(28) Tailoring only Linear Filter Pipelines
AC-04(29) Tailoring only Filter Orchestration Engines
AC-04(30) Tailoring only Filter Mechanisms Using Multiple Processes
AC-04(31) Tailoring only Failed Content Transfer Prevention
AC-04(32) Tailoring only Process Requirements for Information Transfer
AC-05 Moderate Separation of Duties
AC-06 Moderate Least Privilege
AC-06(01) Moderate Authorize Access to Security Functions
AC-06(02) Moderate Non-privileged Access for Nonsecurity Functions
AC-06(03) High Network Access to Privileged Commands
AC-06(04) Tailoring only Separate Processing Domains
AC-06(05) Moderate Privileged Accounts
AC-06(06) Tailoring only Privileged Access by Non-organizational Users
AC-06(07) Moderate Review of User Privileges
AC-06(08) Tailoring only Privilege Levels for Code Execution
AC-06(09) Moderate Log Use of Privileged Functions
AC-06(10) Moderate Prohibit Non-privileged Users from Executing Privileged Functions
AC-07 Low Unsuccessful Logon Attempts
AC-07(01) withdrawn → AC-07 Tailoring only Automatic Account Lock
AC-07(02) Tailoring only Purge or Wipe Mobile Device
AC-07(03) Tailoring only Biometric Attempt Limiting
AC-07(04) Tailoring only Use of Alternate Authentication Factor
AC-08 Low System Use Notification
AC-09 Tailoring only Previous Logon Notification
AC-09(01) Tailoring only Unsuccessful Logons
AC-09(02) Tailoring only Successful and Unsuccessful Logons
AC-09(03) Tailoring only Notification of Account Changes
AC-09(04) Tailoring only Additional Logon Information
AC-10 High Concurrent Session Control
AC-11 Moderate Device Lock
AC-11(01) Moderate Pattern-hiding Displays
AC-12 Moderate Session Termination
AC-12(01) Tailoring only User-initiated Logouts
AC-12(02) Tailoring only Termination Message
AC-12(03) Tailoring only Timeout Warning Message
AC-13 withdrawn → AC-02, AU-06 Tailoring only Supervision and Review — Access Control
AC-14 Low Permitted Actions Without Identification or Authentication
AC-14(01) withdrawn → AC-14 Tailoring only Necessary Uses
AC-15 withdrawn → MP-03 Tailoring only Automated Marking
AC-16 Tailoring only Security and Privacy Attributes
AC-16(01) Tailoring only Dynamic Attribute Association
AC-16(02) Tailoring only Attribute Value Changes by Authorized Individuals
AC-16(03) Tailoring only Maintenance of Attribute Associations by System
AC-16(04) Tailoring only Association of Attributes by Authorized Individuals
AC-16(05) Tailoring only Attribute Displays on Objects to Be Output
AC-16(06) Tailoring only Maintenance of Attribute Association
AC-16(07) Tailoring only Consistent Attribute Interpretation
AC-16(08) Tailoring only Association Techniques and Technologies
AC-16(09) Tailoring only Attribute Reassignment — Regrading Mechanisms
AC-16(10) Tailoring only Attribute Configuration by Authorized Individuals
AC-17 Low Remote Access
AC-17(01) Moderate Monitoring and Control
AC-17(02) Moderate Protection of Confidentiality and Integrity Using Encryption
AC-17(03) Moderate Managed Access Control Points
AC-17(04) Moderate Privileged Commands and Access
AC-17(05) withdrawn → SI-04 Tailoring only Monitoring for Unauthorized Connections
AC-17(06) Tailoring only Protection of Mechanism Information
AC-17(07) withdrawn → AC-03(10) Tailoring only Additional Protection for Security Function Access
AC-17(08) withdrawn → CM-07 Tailoring only Disable Nonsecure Network Protocols
AC-17(09) Tailoring only Disconnect or Disable Access
AC-17(10) Tailoring only Authenticate Remote Commands
AC-18 Low Wireless Access
AC-18(01) Moderate Authentication and Encryption
AC-18(02) withdrawn → SI-04 Tailoring only Monitoring Unauthorized Connections
AC-18(03) Moderate Disable Wireless Networking
AC-18(04) High Restrict Configurations by Users
AC-18(05) High Antennas and Transmission Power Levels
AC-19 Low Access Control for Mobile Devices
AC-19(01) withdrawn → MP-07 Tailoring only Use of Writable and Portable Storage Devices
AC-19(02) withdrawn → MP-07 Tailoring only Use of Personally Owned Portable Storage Devices
AC-19(03) withdrawn → MP-07 Tailoring only Use of Portable Storage Devices with No Identifiable Owner
AC-19(04) Tailoring only Restrictions for Classified Information
AC-19(05) Moderate Full Device or Container-based Encryption
AC-20 Low Use of External Systems
AC-20(01) Moderate Limits on Authorized Use
AC-20(02) Moderate Portable Storage Devices — Restricted Use
AC-20(03) Tailoring only Non-organizationally Owned Systems — Restricted Use
AC-20(04) Tailoring only Network Accessible Storage Devices — Prohibited Use
AC-20(05) Tailoring only Portable Storage Devices — Prohibited Use
AC-21 Moderate Information Sharing
AC-21(01) Tailoring only Automated Decision Support
AC-21(02) Tailoring only Information Search and Retrieval
AC-22 Low Publicly Accessible Content
AC-23 Tailoring only Data Mining Protection
AC-24 Tailoring only Access Control Decisions
AC-24(01) Tailoring only Transmit Access Authorization Information
AC-24(02) Tailoring only No User or Process Identity
AC-25 Tailoring only Reference Monitor
Awareness and Training  · 17 controls

Awareness and Training (AT)

Our thematic mapping puts this group against (g)

NIST 800-53 controls in AT, Awareness and Training
Control Level Title
AT-01 Low Policy and Procedures
AT-02 Low Literacy Training and Awareness
AT-02(01) Tailoring only Practical Exercises
AT-02(02) Low Insider Threat
AT-02(03) Moderate Social Engineering and Mining
AT-02(04) Tailoring only Suspicious Communications and Anomalous System Behavior
AT-02(05) Tailoring only Advanced Persistent Threat
AT-02(06) Tailoring only Cyber Threat Environment
AT-03 Low Role-based Training
AT-03(01) Tailoring only Environmental Controls
AT-03(02) Tailoring only Physical Security Controls
AT-03(03) Tailoring only Practical Exercises
AT-03(04) withdrawn → AT-02(04) Tailoring only Suspicious Communications and Anomalous System Behavior
AT-03(05) Tailoring only Processing Personally Identifiable Information
AT-04 Low Training Records
AT-05 withdrawn → PM-15 Tailoring only Contacts with Security Groups and Associations
AT-06 Tailoring only Training Feedback
Audit and Accountability  · 69 controls

Audit and Accountability (AU)

Our thematic mapping puts this group against (b)

NIST 800-53 controls in AU, Audit and Accountability
Control Level Title
AU-01 Low Policy and Procedures
AU-02 Low Event Logging
AU-02(01) withdrawn → AU-12 Tailoring only Compilation of Audit Records from Multiple Sources
AU-02(02) withdrawn → AU-12 Tailoring only Selection of Audit Events by Component
AU-02(03) withdrawn → AU-02 Tailoring only Reviews and Updates
AU-02(04) withdrawn → AC-06(09) Tailoring only Privileged Functions
AU-03 Low Content of Audit Records
AU-03(01) Moderate Additional Audit Information
AU-03(02) withdrawn → PL-09 Tailoring only Centralized Management of Planned Audit Record Content
AU-03(03) Tailoring only Limit Personally Identifiable Information Elements
AU-04 Low Audit Log Storage Capacity
AU-04(01) Tailoring only Transfer to Alternate Storage
AU-05 Low Response to Audit Logging Process Failures
AU-05(01) High Storage Capacity Warning
AU-05(02) High Real-time Alerts
AU-05(03) Tailoring only Configurable Traffic Volume Thresholds
AU-05(04) Tailoring only Shutdown on Failure
AU-05(05) Tailoring only Alternate Audit Logging Capability
AU-06 Low Audit Record Review, Analysis, and Reporting
AU-06(01) Moderate Automated Process Integration
AU-06(02) withdrawn → SI-04 Tailoring only Automated Security Alerts
AU-06(03) Moderate Correlate Audit Record Repositories
AU-06(04) Tailoring only Central Review and Analysis
AU-06(05) High Integrated Analysis of Audit Records
AU-06(06) High Correlation with Physical Monitoring
AU-06(07) Tailoring only Permitted Actions
AU-06(08) Tailoring only Full Text Analysis of Privileged Commands
AU-06(09) Tailoring only Correlation with Information from Nontechnical Sources
AU-06(10) withdrawn → AU-06 Tailoring only Audit Level Adjustment
AU-07 Moderate Audit Record Reduction and Report Generation
AU-07(01) Moderate Automatic Processing
AU-07(02) withdrawn → AU-07(01) Tailoring only Automatic Sort and Search
AU-08 Low Time Stamps
AU-08(01) withdrawn → SC-45(01) Tailoring only Synchronization with Authoritative Time Source
AU-08(02) withdrawn → SC-45(02) Tailoring only Secondary Authoritative Time Source
AU-09 Low Protection of Audit Information
AU-09(01) Tailoring only Hardware Write-once Media
AU-09(02) High Store on Separate Physical Systems or Components
AU-09(03) High Cryptographic Protection
AU-09(04) Moderate Access by Subset of Privileged Users
AU-09(05) Tailoring only Dual Authorization
AU-09(06) Tailoring only Read-only Access
AU-09(07) Tailoring only Store on Component with Different Operating System
AU-10 High Non-repudiation
AU-10(01) Tailoring only Association of Identities
AU-10(02) Tailoring only Validate Binding of Information Producer Identity
AU-10(03) Tailoring only Chain of Custody
AU-10(04) Tailoring only Validate Binding of Information Reviewer Identity
AU-10(05) withdrawn → SI-07 Tailoring only Digital Signatures
AU-11 Low Audit Record Retention
AU-11(01) Tailoring only Long-term Retrieval Capability
AU-12 Low Audit Record Generation
AU-12(01) High System-wide and Time-correlated Audit Trail
AU-12(02) Tailoring only Standardized Formats
AU-12(03) High Changes by Authorized Individuals
AU-12(04) Tailoring only Query Parameter Audits of Personally Identifiable Information
AU-13 Tailoring only Monitoring for Information Disclosure
AU-13(01) Tailoring only Use of Automated Tools
AU-13(02) Tailoring only Review of Monitored Sites
AU-13(03) Tailoring only Unauthorized Replication of Information
AU-14 Tailoring only Session Audit
AU-14(01) Tailoring only System Start-up
AU-14(02) withdrawn → AU-14 Tailoring only Capture and Record Content
AU-14(03) Tailoring only Remote Viewing and Listening
AU-15 withdrawn → AU-05(05) Tailoring only Alternate Audit Logging Capability
AU-16 Tailoring only Cross-organizational Audit Logging
AU-16(01) Tailoring only Identity Preservation
AU-16(02) Tailoring only Sharing of Audit Information
AU-16(03) Tailoring only Disassociability
Assessment, Authorization, and Monitoring  · 32 controls

Assessment, Authorization, and Monitoring (CA)

Our thematic mapping puts this group against (f)

NIST 800-53 controls in CA, Assessment, Authorization, and Monitoring
Control Level Title
CA-01 Low Policy and Procedures
CA-02 Low Control Assessments
CA-02(01) Moderate Independent Assessors
CA-02(02) High Specialized Assessments
CA-02(03) Tailoring only Leveraging Results from External Organizations
CA-03 Low Information Exchange
CA-03(01) withdrawn → SC-07(25) Tailoring only Unclassified National Security System Connections
CA-03(02) withdrawn → SC-07(26) Tailoring only Classified National Security System Connections
CA-03(03) withdrawn → SC-07(27) Tailoring only Unclassified Non-national Security System Connections
CA-03(04) withdrawn → SC-07(28) Tailoring only Connections to Public Networks
CA-03(05) withdrawn → SC-07(05) Tailoring only Restrictions on External System Connections
CA-03(06) High Transfer Authorizations
CA-03(07) Tailoring only Transitive Information Exchanges
CA-04 withdrawn → CA-02 Tailoring only Security Certification
CA-05 Low Plan of Action and Milestones
CA-05(01) Tailoring only Automation Support for Accuracy and Currency
CA-06 Low Authorization
CA-06(01) Tailoring only Joint Authorization — Intra-organization
CA-06(02) Tailoring only Joint Authorization — Inter-organization
CA-07 Low Continuous Monitoring
CA-07(01) Moderate Independent Assessment
CA-07(02) withdrawn → CA-02 Tailoring only Types of Assessments
CA-07(03) Tailoring only Trend Analyses
CA-07(04) Low Risk Monitoring
CA-07(05) Tailoring only Consistency Analysis
CA-07(06) Tailoring only Automation Support for Monitoring
CA-08 High Penetration Testing
CA-08(01) High Independent Penetration Testing Agent or Team
CA-08(02) Tailoring only Red Team Exercises
CA-08(03) Tailoring only Facility Penetration Testing
CA-09 Low Internal System Connections
CA-09(01) Tailoring only Compliance Checks
Configuration Management  · 66 controls

Configuration Management (CM)

Our thematic mapping puts this group against (e) (g) (i)

NIST 800-53 controls in CM, Configuration Management
Control Level Title
CM-01 Low Policy and Procedures
CM-02 Low Baseline Configuration
CM-02(01) withdrawn → CM-02 Tailoring only Reviews and Updates
CM-02(02) Moderate Automation Support for Accuracy and Currency
CM-02(03) Moderate Retention of Previous Configurations
CM-02(04) withdrawn → CM-07(04) Tailoring only Unauthorized Software
CM-02(05) withdrawn → CM-07(05) Tailoring only Authorized Software
CM-02(06) Tailoring only Development and Test Environments
CM-02(07) Moderate Configure Systems and Components for High-risk Areas
CM-03 Moderate Configuration Change Control
CM-03(01) High Automated Documentation, Notification, and Prohibition of Changes
CM-03(02) Moderate Testing, Validation, and Documentation of Changes
CM-03(03) Tailoring only Automated Change Implementation
CM-03(04) Moderate Security and Privacy Representatives
CM-03(05) Tailoring only Automated Security Response
CM-03(06) High Cryptography Management
CM-03(07) Tailoring only Review System Changes
CM-03(08) Tailoring only Prevent or Restrict Configuration Changes
CM-04 Low Impact Analyses
CM-04(01) High Separate Test Environments
CM-04(02) Moderate Verification of Controls
CM-05 Low Access Restrictions for Change
CM-05(01) High Automated Access Enforcement and Audit Records
CM-05(02) withdrawn → CM-03(07) Tailoring only Review System Changes
CM-05(03) withdrawn → CM-14 Tailoring only Signed Components
CM-05(04) Tailoring only Dual Authorization
CM-05(05) Tailoring only Privilege Limitation for Production and Operation
CM-05(06) Tailoring only Limit Library Privileges
CM-05(07) withdrawn → SI-07 Tailoring only Automatic Implementation of Security Safeguards
CM-06 Low Configuration Settings
CM-06(01) High Automated Management, Application, and Verification
CM-06(02) High Respond to Unauthorized Changes
CM-06(03) withdrawn → SI-07 Tailoring only Unauthorized Change Detection
CM-06(04) withdrawn → CM-04 Tailoring only Conformance Demonstration
CM-07 Low Least Functionality
CM-07(01) Moderate Periodic Review
CM-07(02) Moderate Prevent Program Execution
CM-07(03) Tailoring only Registration Compliance
CM-07(04) Tailoring only Unauthorized Software — Deny-by-exception
CM-07(05) Moderate Authorized Software — Allow-by-exception
CM-07(06) Tailoring only Confined Environments with Limited Privileges
CM-07(07) Tailoring only Code Execution in Protected Environments
CM-07(08) Tailoring only Binary or Machine Executable Code
CM-07(09) Tailoring only Prohibiting The Use of Unauthorized Hardware
CM-08 Low System Component Inventory
CM-08(01) Moderate Updates During Installation and Removal
CM-08(02) High Automated Maintenance
CM-08(03) Moderate Automated Unauthorized Component Detection
CM-08(04) High Accountability Information
CM-08(05) withdrawn → CM-08 Tailoring only No Duplicate Accounting of Components
CM-08(06) Tailoring only Assessed Configurations and Approved Deviations
CM-08(07) Tailoring only Centralized Repository
CM-08(08) Tailoring only Automated Location Tracking
CM-08(09) Tailoring only Assignment of Components to Systems
CM-09 Moderate Configuration Management Plan
CM-09(01) Tailoring only Assignment of Responsibility
CM-10 Low Software Usage Restrictions
CM-10(01) Tailoring only Open-source Software
CM-11 Low User-installed Software
CM-11(01) withdrawn → CM-08(03) Tailoring only Alerts for Unauthorized Installations
CM-11(02) Tailoring only Software Installation with Privileged Status
CM-11(03) Tailoring only Automated Enforcement and Monitoring
CM-12 Moderate Information Location
CM-12(01) Moderate Automated Tools to Support Information Location
CM-13 Tailoring only Data Action Mapping
CM-14 Tailoring only Signed Components
Contingency Planning  · 56 controls

Contingency Planning (CP)

Our thematic mapping puts this group against (c)

NIST 800-53 controls in CP, Contingency Planning
Control Level Title
CP-01 Low Policy and Procedures
CP-02 Low Contingency Plan
CP-02(01) Moderate Coordinate with Related Plans
CP-02(02) High Capacity Planning
CP-02(03) Moderate Resume Mission and Business Functions
CP-02(04) withdrawn → CP-02(03) Tailoring only Resume All Mission and Business Functions
CP-02(05) High Continue Mission and Business Functions
CP-02(06) Tailoring only Alternate Processing and Storage Sites
CP-02(07) Tailoring only Coordinate with External Service Providers
CP-02(08) Moderate Identify Critical Assets
CP-03 Low Contingency Training
CP-03(01) High Simulated Events
CP-03(02) Tailoring only Mechanisms Used in Training Environments
CP-04 Low Contingency Plan Testing
CP-04(01) Moderate Coordinate with Related Plans
CP-04(02) High Alternate Processing Site
CP-04(03) Tailoring only Automated Testing
CP-04(04) Tailoring only Full Recovery and Reconstitution
CP-04(05) Tailoring only Self-challenge
CP-05 withdrawn → CP-02 Tailoring only Contingency Plan Update
CP-06 Moderate Alternate Storage Site
CP-06(01) Moderate Separation from Primary Site
CP-06(02) High Recovery Time and Recovery Point Objectives
CP-06(03) Moderate Accessibility
CP-07 Moderate Alternate Processing Site
CP-07(01) Moderate Separation from Primary Site
CP-07(02) Moderate Accessibility
CP-07(03) Moderate Priority of Service
CP-07(04) High Preparation for Use
CP-07(05) withdrawn → CP-07 Tailoring only Equivalent Information Security Safeguards
CP-07(06) Tailoring only Inability to Return to Primary Site
CP-08 Moderate Telecommunications Services
CP-08(01) Moderate Priority of Service Provisions
CP-08(02) Moderate Single Points of Failure
CP-08(03) High Separation of Primary and Alternate Providers
CP-08(04) High Provider Contingency Plan
CP-08(05) Tailoring only Alternate Telecommunication Service Testing
CP-09 Low System Backup
CP-09(01) Moderate Testing for Reliability and Integrity
CP-09(02) High Test Restoration Using Sampling
CP-09(03) High Separate Storage for Critical Information
CP-09(04) withdrawn → CP-09 Tailoring only Protection from Unauthorized Modification
CP-09(05) High Transfer to Alternate Storage Site
CP-09(06) Tailoring only Redundant Secondary System
CP-09(07) Tailoring only Dual Authorization for Deletion or Destruction
CP-09(08) Moderate Cryptographic Protection
CP-10 Low System Recovery and Reconstitution
CP-10(01) withdrawn → CP-04 Tailoring only Contingency Plan Testing
CP-10(02) Moderate Transaction Recovery
CP-10(03) withdrawn Tailoring only Compensating Security Controls
CP-10(04) High Restore Within Time Period
CP-10(05) withdrawn → SI-13 Tailoring only Failover Capability
CP-10(06) Tailoring only Component Protection
CP-11 Tailoring only Alternate Communications Protocols
CP-12 Tailoring only Safe Mode
CP-13 Tailoring only Alternative Security Mechanisms
Identification and Authentication  · 74 controls

Identification and Authentication (IA)

Our thematic mapping puts this group against (i) (j)

NIST 800-53 controls in IA, Identification and Authentication
Control Level Title
IA-01 Low Policy and Procedures
IA-02 Low Identification and Authentication (Organizational Users)
IA-02(01) Low Multi-factor Authentication to Privileged Accounts
IA-02(02) Low Multi-factor Authentication to Non-privileged Accounts
IA-02(03) withdrawn → IA-02(01) Tailoring only Local Access to Privileged Accounts
IA-02(04) withdrawn → IA-02(02) Tailoring only Local Access to Non-privileged Accounts
IA-02(05) High Individual Authentication with Group Authentication
IA-02(06) Tailoring only Access to Accounts —separate Device
IA-02(07) withdrawn → IA-02(06) Tailoring only Network Access to Non-privileged Accounts — Separate Device
IA-02(08) Low Access to Accounts — Replay Resistant
IA-02(09) withdrawn → IA-02(08) Tailoring only Network Access to Non-privileged Accounts — Replay Resistant
IA-02(10) Tailoring only Single Sign-on
IA-02(11) withdrawn → IA-02(06) Tailoring only Remote Access — Separate Device
IA-02(12) Low Acceptance of PIV Credentials
IA-02(13) Tailoring only Out-of-band Authentication
IA-03 Moderate Device Identification and Authentication
IA-03(01) Tailoring only Cryptographic Bidirectional Authentication
IA-03(02) withdrawn → IA-03(01) Tailoring only Cryptographic Bidirectional Network Authentication
IA-03(03) Tailoring only Dynamic Address Allocation
IA-03(04) Tailoring only Device Attestation
IA-04 Low Identifier Management
IA-04(01) Tailoring only Prohibit Account Identifiers as Public Identifiers
IA-04(02) withdrawn → IA-12(01) Tailoring only Supervisor Authorization
IA-04(03) withdrawn → IA-12(02) Tailoring only Multiple Forms of Certification
IA-04(04) Moderate Identify User Status
IA-04(05) Tailoring only Dynamic Management
IA-04(06) Tailoring only Cross-organization Management
IA-04(07) withdrawn → IA-12(04) Tailoring only In-person Registration
IA-04(08) Tailoring only Pairwise Pseudonymous Identifiers
IA-04(09) Tailoring only Attribute Maintenance and Protection
IA-05 Low Authenticator Management
IA-05(01) Low Password-based Authentication
IA-05(02) Moderate Public Key-based Authentication
IA-05(03) withdrawn → IA-12(04) Tailoring only In-person or Trusted External Party Registration
IA-05(04) withdrawn → IA-05(01) Tailoring only Automated Support for Password Strength Determination
IA-05(05) Tailoring only Change Authenticators Prior to Delivery
IA-05(06) Moderate Protection of Authenticators
IA-05(07) Tailoring only No Embedded Unencrypted Static Authenticators
IA-05(08) Tailoring only Multiple System Accounts
IA-05(09) Tailoring only Federated Credential Management
IA-05(10) Tailoring only Dynamic Credential Binding
IA-05(11) withdrawn → IA-02(01), IA-02(02) Tailoring only Hardware Token-based Authentication
IA-05(12) Tailoring only Biometric Authentication Performance
IA-05(13) Tailoring only Expiration of Cached Authenticators
IA-05(14) Tailoring only Managing Content of PKI Trust Stores
IA-05(15) Tailoring only GSA-approved Products and Services
IA-05(16) Tailoring only In-person or Trusted External Party Authenticator Issuance
IA-05(17) Tailoring only Presentation Attack Detection for Biometric Authenticators
IA-05(18) Tailoring only Password Managers
IA-06 Low Authentication Feedback
IA-07 Low Cryptographic Module Authentication
IA-08 Low Identification and Authentication (Non-organizational Users)
IA-08(01) Low Acceptance of PIV Credentials from Other Agencies
IA-08(02) Low Acceptance of External Authenticators
IA-08(03) withdrawn → IA-08(02) Tailoring only Use of FICAM-approved Products
IA-08(04) Low Use of Defined Profiles
IA-08(05) Tailoring only Acceptance of PIV-I Credentials
IA-08(06) Tailoring only Disassociability
IA-09 Tailoring only Service Identification and Authentication
IA-09(01) withdrawn → IA-09 Tailoring only Information Exchange
IA-09(02) withdrawn → IA-09 Tailoring only Transmission of Decisions
IA-10 Tailoring only Adaptive Authentication
IA-11 Low Re-authentication
IA-12 Moderate Identity Proofing
IA-12(01) Tailoring only Supervisor Authorization
IA-12(02) Moderate Identity Evidence
IA-12(03) Moderate Identity Evidence Validation and Verification
IA-12(04) High In-person Validation and Verification
IA-12(05) Moderate Address Confirmation
IA-12(06) Tailoring only Accept Externally-proofed Identities
IA-13 Tailoring only Identity Providers and Authorization Servers
IA-13(01) Tailoring only Protection of Cryptographic Keys
IA-13(02) Tailoring only Verification of Identity Assertions and Access Tokens
IA-13(03) Tailoring only Token Management
Incident Response  · 42 controls

Incident Response (IR)

Our thematic mapping puts this group against (b)

NIST 800-53 controls in IR, Incident Response
Control Level Title
IR-01 Low Policy and Procedures
IR-02 Low Incident Response Training
IR-02(01) High Simulated Events
IR-02(02) High Automated Training Environments
IR-02(03) Tailoring only Breach
IR-03 Moderate Incident Response Testing
IR-03(01) Tailoring only Automated Testing
IR-03(02) Moderate Coordination with Related Plans
IR-03(03) Tailoring only Continuous Improvement
IR-04 Low Incident Handling
IR-04(01) Moderate Automated Incident Handling Processes
IR-04(02) Tailoring only Dynamic Reconfiguration
IR-04(03) Tailoring only Continuity of Operations
IR-04(04) High Information Correlation
IR-04(05) Tailoring only Automatic Disabling of System
IR-04(06) Tailoring only Insider Threats
IR-04(07) Tailoring only Insider Threats — Intra-organization Coordination
IR-04(08) Tailoring only Correlation with External Organizations
IR-04(09) Tailoring only Dynamic Response Capability
IR-04(10) Tailoring only Supply Chain Coordination
IR-04(11) High Integrated Incident Response Team
IR-04(12) Tailoring only Malicious Code and Forensic Analysis
IR-04(13) Tailoring only Behavior Analysis
IR-04(14) Tailoring only Security Operations Center
IR-04(15) Tailoring only Public Relations and Reputation Repair
IR-05 Low Incident Monitoring
IR-05(01) High Automated Tracking, Data Collection, and Analysis
IR-06 Low Incident Reporting
IR-06(01) Moderate Automated Reporting
IR-06(02) Tailoring only Vulnerabilities Related to Incidents
IR-06(03) Moderate Supply Chain Coordination
IR-07 Low Incident Response Assistance
IR-07(01) Moderate Automation Support for Availability of Information and Support
IR-07(02) Tailoring only Coordination with External Providers
IR-08 Low Incident Response Plan
IR-08(01) Tailoring only Breaches
IR-09 Tailoring only Information Spillage Response
IR-09(01) withdrawn → IR-09 Tailoring only Responsible Personnel
IR-09(02) Tailoring only Training
IR-09(03) Tailoring only Post-spill Operations
IR-09(04) Tailoring only Exposure to Unauthorized Personnel
IR-10 withdrawn → IR-04(11) Tailoring only Integrated Information Security Analysis Team
Maintenance  · 30 controls

Maintenance (MA)

Our thematic mapping puts this group against (e)

NIST 800-53 controls in MA, Maintenance
Control Level Title
MA-01 Low Policy and Procedures
MA-02 Low Controlled Maintenance
MA-02(01) withdrawn → MA-02 Tailoring only Record Content
MA-02(02) High Automated Maintenance Activities
MA-03 Moderate Maintenance Tools
MA-03(01) Moderate Inspect Tools
MA-03(02) Moderate Inspect Media
MA-03(03) Moderate Prevent Unauthorized Removal
MA-03(04) Tailoring only Restricted Tool Use
MA-03(05) Tailoring only Execution with Privilege
MA-03(06) Tailoring only Software Updates and Patches
MA-04 Low Nonlocal Maintenance
MA-04(01) Tailoring only Logging and Review
MA-04(02) withdrawn → MA-01, MA-04 Tailoring only Document Nonlocal Maintenance
MA-04(03) High Comparable Security and Sanitization
MA-04(04) Tailoring only Authentication and Separation of Maintenance Sessions
MA-04(05) Tailoring only Approvals and Notifications
MA-04(06) Tailoring only Cryptographic Protection
MA-04(07) Tailoring only Disconnect Verification
MA-05 Low Maintenance Personnel
MA-05(01) High Individuals Without Appropriate Access
MA-05(02) Tailoring only Security Clearances for Classified Systems
MA-05(03) Tailoring only Citizenship Requirements for Classified Systems
MA-05(04) Tailoring only Foreign Nationals
MA-05(05) Tailoring only Non-system Maintenance
MA-06 Moderate Timely Maintenance
MA-06(01) Tailoring only Preventive Maintenance
MA-06(02) Tailoring only Predictive Maintenance
MA-06(03) Tailoring only Automated Support for Predictive Maintenance
MA-07 Tailoring only Field Maintenance
Media Protection  · 30 controls

Media Protection (MP)

Our thematic mapping puts this group against (i)

NIST 800-53 controls in MP, Media Protection
Control Level Title
MP-01 Low Policy and Procedures
MP-02 Low Media Access
MP-02(01) withdrawn → MP-04(02) Tailoring only Automated Restricted Access
MP-02(02) withdrawn → SC-28(01) Tailoring only Cryptographic Protection
MP-03 Moderate Media Marking
MP-04 Moderate Media Storage
MP-04(01) withdrawn → SC-28(01) Tailoring only Cryptographic Protection
MP-04(02) Tailoring only Automated Restricted Access
MP-05 Moderate Media Transport
MP-05(01) withdrawn → MP-05 Tailoring only Protection Outside of Controlled Areas
MP-05(02) withdrawn → MP-05 Tailoring only Documentation of Activities
MP-05(03) Tailoring only Custodians
MP-05(04) withdrawn → SC-28(01) Tailoring only Cryptographic Protection
MP-06 Low Media Sanitization
MP-06(01) High Review, Approve, Track, Document, and Verify
MP-06(02) High Equipment Testing
MP-06(03) High Nondestructive Techniques
MP-06(04) withdrawn → MP-06 Tailoring only Controlled Unclassified Information
MP-06(05) withdrawn → MP-06 Tailoring only Classified Information
MP-06(06) withdrawn → MP-06 Tailoring only Media Destruction
MP-06(07) Tailoring only Dual Authorization
MP-06(08) Tailoring only Remote Purging or Wiping of Information
MP-07 Low Media Use
MP-07(01) withdrawn → MP-07 Tailoring only Prohibit Use Without Owner
MP-07(02) Tailoring only Prohibit Use of Sanitization-resistant Media
MP-08 Tailoring only Media Downgrading
MP-08(01) Tailoring only Documentation of Process
MP-08(02) Tailoring only Equipment Testing
MP-08(03) Tailoring only Controlled Unclassified Information
MP-08(04) Tailoring only Classified Information
Physical and Environmental Protection  · 59 controls

Physical and Environmental Protection (PE)

Our thematic mapping puts this group against (c) (i)

NIST 800-53 controls in PE, Physical and Environmental Protection
Control Level Title
PE-01 Low Policy and Procedures
PE-02 Low Physical Access Authorizations
PE-02(01) Tailoring only Access by Position or Role
PE-02(02) Tailoring only Two Forms of Identification
PE-02(03) Tailoring only Restrict Unescorted Access
PE-03 Low Physical Access Control
PE-03(01) High System Access
PE-03(02) Tailoring only Facility and Systems
PE-03(03) Tailoring only Continuous Guards
PE-03(04) Tailoring only Lockable Casings
PE-03(05) Tailoring only Tamper Protection
PE-03(06) withdrawn → CA-08 Tailoring only Facility Penetration Testing
PE-03(07) Tailoring only Physical Barriers
PE-03(08) Tailoring only Access Control Vestibules
PE-04 Moderate Access Control for Transmission
PE-05 Moderate Access Control for Output Devices
PE-05(01) withdrawn → PE-05 Tailoring only Access to Output by Authorized Individuals
PE-05(02) Tailoring only Link to Individual Identity
PE-05(03) withdrawn → PE-22 Tailoring only Marking Output Devices
PE-06 Low Monitoring Physical Access
PE-06(01) Moderate Intrusion Alarms and Surveillance Equipment
PE-06(02) Tailoring only Automated Intrusion Recognition and Responses
PE-06(03) Tailoring only Video Surveillance
PE-06(04) High Monitoring Physical Access to Systems
PE-07 withdrawn → PE-02, PE-03 Tailoring only Visitor Control
PE-08 Low Visitor Access Records
PE-08(01) High Automated Records Maintenance and Review
PE-08(02) withdrawn → PE-02 Tailoring only Physical Access Records
PE-08(03) Tailoring only Limit Personally Identifiable Information Elements
PE-09 Moderate Power Equipment and Cabling
PE-09(01) Tailoring only Redundant Cabling
PE-09(02) Tailoring only Automatic Voltage Controls
PE-10 Moderate Emergency Shutoff
PE-10(01) withdrawn → PE-10 Tailoring only Accidental and Unauthorized Activation
PE-11 Moderate Emergency Power
PE-11(01) High Alternate Power Supply — Minimal Operational Capability
PE-11(02) Tailoring only Alternate Power Supply — Self-contained
PE-12 Low Emergency Lighting
PE-12(01) Tailoring only Essential Mission and Business Functions
PE-13 Low Fire Protection
PE-13(01) Moderate Detection Systems — Automatic Activation and Notification
PE-13(02) High Suppression Systems — Automatic Activation and Notification
PE-13(03) withdrawn → PE-13(02) Tailoring only Automatic Fire Suppression
PE-13(04) Tailoring only Inspections
PE-14 Low Environmental Controls
PE-14(01) Tailoring only Automatic Controls
PE-14(02) Tailoring only Monitoring with Alarms and Notifications
PE-15 Low Water Damage Protection
PE-15(01) High Automation Support
PE-16 Low Delivery and Removal
PE-17 Moderate Alternate Work Site
PE-18 High Location of System Components
PE-18(01) withdrawn → PE-23 Tailoring only Facility Site
PE-19 Tailoring only Information Leakage
PE-19(01) Tailoring only National Emissions Policies and Procedures
PE-20 Tailoring only Asset Monitoring and Tracking
PE-21 Tailoring only Electromagnetic Pulse Protection
PE-22 Tailoring only Component Marking
PE-23 Tailoring only Facility Location
Planning  · 17 controls

Planning (PL)

Our thematic mapping puts this group against (a)

NIST 800-53 controls in PL, Planning
Control Level Title
PL-01 Low Policy and Procedures
PL-02 Low System Security and Privacy Plans
PL-02(01) withdrawn → PL-07 Tailoring only Concept of Operations
PL-02(02) withdrawn → PL-08 Tailoring only Functional Architecture
PL-02(03) withdrawn → PL-02 Tailoring only Plan and Coordinate with Other Organizational Entities
PL-03 withdrawn → PL-02 Tailoring only System Security Plan Update
PL-04 Low Rules of Behavior
PL-04(01) Low Social Media and External Site/Application Usage Restrictions
PL-05 withdrawn → RA-08 Tailoring only Privacy Impact Assessment
PL-06 withdrawn → PL-02 Tailoring only Security-related Activity Planning
PL-07 Tailoring only Concept of Operations
PL-08 Moderate Security and Privacy Architectures
PL-08(01) Tailoring only Defense in Depth
PL-08(02) Tailoring only Supplier Diversity
PL-09 Tailoring only Central Management
PL-10 Low Baseline Selection
PL-11 Low Baseline Tailoring
Program Management  · 37 controls

Program Management (PM)

Our thematic mapping puts this group against (a) (f)

NIST 800-53 controls in PM, Program Management
Control Level Title
PM-01 Tailoring only Information Security Program Plan
PM-02 Tailoring only Information Security Program Leadership Role
PM-03 Tailoring only Information Security and Privacy Resources
PM-04 Tailoring only Plan of Action and Milestones Process
PM-05 Tailoring only System Inventory
PM-05(01) Tailoring only Inventory of Personally Identifiable Information
PM-06 Tailoring only Measures of Performance
PM-07 Tailoring only Enterprise Architecture
PM-07(01) Tailoring only Offloading
PM-08 Tailoring only Critical Infrastructure Plan
PM-09 Tailoring only Risk Management Strategy
PM-10 Tailoring only Authorization Process
PM-11 Tailoring only Mission and Business Process Definition
PM-12 Tailoring only Insider Threat Program
PM-13 Tailoring only Security and Privacy Workforce
PM-14 Tailoring only Testing, Training, and Monitoring
PM-15 Tailoring only Security and Privacy Groups and Associations
PM-16 Tailoring only Threat Awareness Program
PM-16(01) Tailoring only Automated Means for Sharing Threat Intelligence
PM-17 Tailoring only Protecting Controlled Unclassified Information on External Systems
PM-18 Tailoring only Privacy Program Plan
PM-19 Tailoring only Privacy Program Leadership Role
PM-20 Tailoring only Dissemination of Privacy Program Information
PM-20(01) Tailoring only Privacy Policies on Websites, Applications, and Digital Services
PM-21 Tailoring only Accounting of Disclosures
PM-22 Tailoring only Personally Identifiable Information Quality Management
PM-23 Tailoring only Data Governance Body
PM-24 Tailoring only Data Integrity Board
PM-25 Tailoring only Minimization of Personally Identifiable Information Used in Testing, Training, and Research
PM-26 Tailoring only Complaint Management
PM-27 Tailoring only Privacy Reporting
PM-28 Tailoring only Risk Framing
PM-29 Tailoring only Risk Management Program Leadership Roles
PM-30 Tailoring only Supply Chain Risk Management Strategy
PM-30(01) Tailoring only Suppliers of Critical or Mission-essential Items
PM-31 Tailoring only Continuous Monitoring Strategy
PM-32 Tailoring only Purposing
Personnel Security  · 18 controls

Personnel Security (PS)

Our thematic mapping puts this group against (i)

NIST 800-53 controls in PS, Personnel Security
Control Level Title
PS-01 Low Policy and Procedures
PS-02 Low Position Risk Designation
PS-03 Low Personnel Screening
PS-03(01) Tailoring only Classified Information
PS-03(02) Tailoring only Formal Indoctrination
PS-03(03) Tailoring only Information Requiring Special Protective Measures
PS-03(04) Tailoring only Citizenship Requirements
PS-04 Low Personnel Termination
PS-04(01) Tailoring only Post-employment Requirements
PS-04(02) High Automated Actions
PS-05 Low Personnel Transfer
PS-06 Low Access Agreements
PS-06(01) withdrawn → PS-03 Tailoring only Information Requiring Special Protection
PS-06(02) Tailoring only Classified Information Requiring Special Protection
PS-06(03) Tailoring only Post-employment Requirements
PS-07 Low External Personnel Security
PS-08 Low Personnel Sanctions
PS-09 Low Position Descriptions
Personally Identifiable Information Processing and Transparency  · 21 controls

Personally Identifiable Information Processing and Transparency (PT)

NIST 800-53 controls in PT, Personally Identifiable Information Processing and Transparency
Control Level Title
PT-01 Tailoring only Policy and Procedures
PT-02 Tailoring only Authority to Process Personally Identifiable Information
PT-02(01) Tailoring only Data Tagging
PT-02(02) Tailoring only Automation
PT-03 Tailoring only Personally Identifiable Information Processing Purposes
PT-03(01) Tailoring only Data Tagging
PT-03(02) Tailoring only Automation
PT-04 Tailoring only Consent
PT-04(01) Tailoring only Tailored Consent
PT-04(02) Tailoring only Just-in-time Consent
PT-04(03) Tailoring only Revocation
PT-05 Tailoring only Privacy Notice
PT-05(01) Tailoring only Just-in-time Notice
PT-05(02) Tailoring only Privacy Act Statements
PT-06 Tailoring only System of Records Notice
PT-06(01) Tailoring only Routine Uses
PT-06(02) Tailoring only Exemption Rules
PT-07 Tailoring only Specific Categories of Personally Identifiable Information
PT-07(01) Tailoring only Social Security Numbers
PT-07(02) Tailoring only First Amendment Information
PT-08 Tailoring only Computer Matching Requirements
Risk Assessment  · 26 controls

Risk Assessment (RA)

Our thematic mapping puts this group against (a) (e)

NIST 800-53 controls in RA, Risk Assessment
Control Level Title
RA-01 Low Policy and Procedures
RA-02 Low Security Categorization
RA-02(01) Tailoring only Impact-level Prioritization
RA-03 Low Risk Assessment
RA-03(01) Low Supply Chain Risk Assessment
RA-03(02) Tailoring only Use of All-source Intelligence
RA-03(03) Tailoring only Dynamic Threat Awareness
RA-03(04) Tailoring only Predictive Cyber Analytics
RA-04 withdrawn → RA-03 Tailoring only Risk Assessment Update
RA-05 Low Vulnerability Monitoring and Scanning
RA-05(01) withdrawn → RA-05 Tailoring only Update Tool Capability
RA-05(02) Low Update Vulnerabilities to Be Scanned
RA-05(03) Tailoring only Breadth and Depth of Coverage
RA-05(04) High Discoverable Information
RA-05(05) Moderate Privileged Access
RA-05(06) Tailoring only Automated Trend Analyses
RA-05(07) withdrawn → CM-08 Tailoring only Automated Detection and Notification of Unauthorized Components
RA-05(08) Tailoring only Review Historic Audit Logs
RA-05(09) withdrawn → CA-08 Tailoring only Penetration Testing and Analyses
RA-05(10) Tailoring only Correlate Scanning Information
RA-05(11) Low Public Disclosure Program
RA-06 Tailoring only Technical Surveillance Countermeasures Survey
RA-07 Low Risk Response
RA-08 Tailoring only Privacy Impact Assessments
RA-09 Moderate Criticality Analysis
RA-10 Tailoring only Threat Hunting
System and Services Acquisition  · 147 controls

System and Services Acquisition (SA)

Our thematic mapping puts this group against (d) (e)

NIST 800-53 controls in SA, System and Services Acquisition
Control Level Title
SA-01 Low Policy and Procedures
SA-02 Low Allocation of Resources
SA-03 Low System Development Life Cycle
SA-03(01) Tailoring only Manage Preproduction Environment
SA-03(02) Tailoring only Use of Live or Operational Data
SA-03(03) Tailoring only Technology Refresh
SA-04 Low Acquisition Process
SA-04(01) Moderate Functional Properties of Controls
SA-04(02) Moderate Design and Implementation Information for Controls
SA-04(03) Tailoring only Development Methods, Techniques, and Practices
SA-04(04) withdrawn → CM-08(09) Tailoring only Assignment of Components to Systems
SA-04(05) High System, Component, and Service Configurations
SA-04(06) Tailoring only Use of Information Assurance Products
SA-04(07) Tailoring only NIAP-approved Protection Profiles
SA-04(08) Tailoring only Continuous Monitoring Plan for Controls
SA-04(09) Moderate Functions, Ports, Protocols, and Services in Use
SA-04(10) Low Use of Approved PIV Products
SA-04(11) Tailoring only System of Records
SA-04(12) Tailoring only Data Ownership
SA-05 Low System Documentation
SA-05(01) withdrawn → SA-04(01) Tailoring only Functional Properties of Security Controls
SA-05(02) withdrawn → SA-04(02) Tailoring only Security-relevant External System Interfaces
SA-05(03) withdrawn → SA-04(02) Tailoring only High-level Design
SA-05(04) withdrawn → SA-04(02) Tailoring only Low-level Design
SA-05(05) withdrawn → SA-04(02) Tailoring only Source Code
SA-06 withdrawn → CM-10, SI-07 Tailoring only Software Usage Restrictions
SA-07 withdrawn → CM-11, SI-07 Tailoring only User-installed Software
SA-08 Low Security and Privacy Engineering Principles
SA-08(01) Tailoring only Clear Abstractions
SA-08(02) Tailoring only Least Common Mechanism
SA-08(03) Tailoring only Modularity and Layering
SA-08(04) Tailoring only Partially Ordered Dependencies
SA-08(05) Tailoring only Efficiently Mediated Access
SA-08(06) Tailoring only Minimized Sharing
SA-08(07) Tailoring only Reduced Complexity
SA-08(08) Tailoring only Secure Evolvability
SA-08(09) Tailoring only Trusted Components
SA-08(10) Tailoring only Hierarchical Trust
SA-08(11) Tailoring only Inverse Modification Threshold
SA-08(12) Tailoring only Hierarchical Protection
SA-08(13) Tailoring only Minimized Security Elements
SA-08(14) Tailoring only Least Privilege
SA-08(15) Tailoring only Predicate Permission
SA-08(16) Tailoring only Self-reliant Trustworthiness
SA-08(17) Tailoring only Secure Distributed Composition
SA-08(18) Tailoring only Trusted Communications Channels
SA-08(19) Tailoring only Continuous Protection
SA-08(20) Tailoring only Secure Metadata Management
SA-08(21) Tailoring only Self-analysis
SA-08(22) Tailoring only Accountability and Traceability
SA-08(23) Tailoring only Secure Defaults
SA-08(24) Tailoring only Secure Failure and Recovery
SA-08(25) Tailoring only Economic Security
SA-08(26) Tailoring only Performance Security
SA-08(27) Tailoring only Human Factored Security
SA-08(28) Tailoring only Acceptable Security
SA-08(29) Tailoring only Repeatable and Documented Procedures
SA-08(30) Tailoring only Procedural Rigor
SA-08(31) Tailoring only Secure System Modification
SA-08(32) Tailoring only Sufficient Documentation
SA-08(33) Tailoring only Minimization
SA-09 Low External System Services
SA-09(01) Tailoring only Risk Assessments and Organizational Approvals
SA-09(02) Moderate Identification of Functions, Ports, Protocols, and Services
SA-09(03) Tailoring only Establish and Maintain Trust Relationship with Providers
SA-09(04) Tailoring only Consistent Interests of Consumers and Providers
SA-09(05) Tailoring only Processing, Storage, and Service Location
SA-09(06) Tailoring only Organization-controlled Cryptographic Keys
SA-09(07) Tailoring only Organization-controlled Integrity Checking
SA-09(08) Tailoring only Processing and Storage Location — U.S. Jurisdiction
SA-10 Moderate Developer Configuration Management
SA-10(01) Tailoring only Software and Firmware Integrity Verification
SA-10(02) Tailoring only Alternative Configuration Management Processes
SA-10(03) Tailoring only Hardware Integrity Verification
SA-10(04) Tailoring only Trusted Generation
SA-10(05) Tailoring only Mapping Integrity for Version Control
SA-10(06) Tailoring only Trusted Distribution
SA-10(07) Tailoring only Security and Privacy Representatives
SA-11 Moderate Developer Testing and Evaluation
SA-11(01) Tailoring only Static Code Analysis
SA-11(02) Tailoring only Threat Modeling and Vulnerability Analyses
SA-11(03) Tailoring only Independent Verification of Assessment Plans and Evidence
SA-11(04) Tailoring only Manual Code Reviews
SA-11(05) Tailoring only Penetration Testing
SA-11(06) Tailoring only Attack Surface Reviews
SA-11(07) Tailoring only Verify Scope of Testing and Evaluation
SA-11(08) Tailoring only Dynamic Code Analysis
SA-11(09) Tailoring only Interactive Application Security Testing
SA-12 withdrawn → SR Tailoring only Supply Chain Protection
SA-12(01) withdrawn → SR-05 Tailoring only Acquisition Strategies / Tools / Methods
SA-12(02) withdrawn → SR-06 Tailoring only Supplier Reviews
SA-12(03) withdrawn → SR-03 Tailoring only Trusted Shipping and Warehousing
SA-12(04) withdrawn → SR-03(01) Tailoring only Diversity of Suppliers
SA-12(05) withdrawn → SR-03(02) Tailoring only Limitation of Harm
SA-12(06) withdrawn → SR-05(01) Tailoring only Minimizing Procurement Time
SA-12(07) withdrawn → SR-05(02) Tailoring only Assessments Prior to Selection / Acceptance / Update
SA-12(08) withdrawn → RA-03(02) Tailoring only Use of All-source Intelligence
SA-12(09) withdrawn → SR-07 Tailoring only Operations Security
SA-12(10) withdrawn → SR-04(03) Tailoring only Validate as Genuine and Not Altered
SA-12(11) withdrawn → SR-06(01) Tailoring only Penetration Testing / Analysis of Elements, Processes, and Actors
SA-12(12) withdrawn → SR-08 Tailoring only Inter-organizational Agreements
SA-12(13) withdrawn → MA-06, RA-09 Tailoring only Critical Information System Components
SA-12(14) withdrawn → SR-04(01), SR-04(02) Tailoring only Identity and Traceability
SA-12(15) withdrawn → SR-03 Tailoring only Processes to Address Weaknesses or Deficiencies
SA-13 withdrawn → SA-08 Tailoring only Trustworthiness
SA-14 withdrawn → RA-09 Tailoring only Criticality Analysis
SA-14(01) withdrawn → SA-20 Tailoring only Critical Components with No Viable Alternative Sourcing
SA-15 Moderate Development Process, Standards, and Tools
SA-15(01) Tailoring only Quality Metrics
SA-15(02) Tailoring only Security and Privacy Tracking Tools
SA-15(03) Moderate Criticality Analysis
SA-15(04) withdrawn → SA-11(02) Tailoring only Threat Modeling and Vulnerability Analysis
SA-15(05) Tailoring only Attack Surface Reduction
SA-15(06) Tailoring only Continuous Improvement
SA-15(07) Tailoring only Automated Vulnerability Analysis
SA-15(08) Tailoring only Reuse of Threat and Vulnerability Information
SA-15(09) withdrawn → SA-03(02) Tailoring only Use of Live Data
SA-15(10) Tailoring only Incident Response Plan
SA-15(11) Tailoring only Archive System or Component
SA-15(12) Tailoring only Minimize Personally Identifiable Information
SA-15(13) Tailoring only Logging Syntax
SA-16 High Developer-provided Training
SA-17 High Developer Security and Privacy Architecture and Design
SA-17(01) Tailoring only Formal Policy Model
SA-17(02) Tailoring only Security-relevant Components
SA-17(03) Tailoring only Formal Correspondence
SA-17(04) Tailoring only Informal Correspondence
SA-17(05) Tailoring only Conceptually Simple Design
SA-17(06) Tailoring only Structure for Testing
SA-17(07) Tailoring only Structure for Least Privilege
SA-17(08) Tailoring only Orchestration
SA-17(09) Tailoring only Design Diversity
SA-18 withdrawn → SR-09 Tailoring only Tamper Resistance and Detection
SA-18(01) withdrawn → SR-09(01) Tailoring only Multiple Phases of System Development Life Cycle
SA-18(02) withdrawn → SR-10 Tailoring only Inspection of Systems or Components
SA-19 withdrawn → SR-11 Tailoring only Component Authenticity
SA-19(01) withdrawn → SR-11(01) Tailoring only Anti-counterfeit Training
SA-19(02) withdrawn → SR-11(02) Tailoring only Configuration Control for Component Service and Repair
SA-19(03) withdrawn → SR-12 Tailoring only Component Disposal
SA-19(04) withdrawn → SR-11(03) Tailoring only Anti-counterfeit Scanning
SA-20 Tailoring only Customized Development of Critical Components
SA-21 High Developer Screening
SA-21(01) withdrawn → SA-21 Tailoring only Validation of Screening
SA-22 Low Unsupported System Components
SA-22(01) withdrawn → SA-22 Tailoring only Alternative Sources for Continued Support
SA-23 Tailoring only Specialization
SA-24 Tailoring only Design For Cyber Resiliency
System and Communications Protection  · 162 controls

System and Communications Protection (SC)

Our thematic mapping puts this group against (h) (j)

NIST 800-53 controls in SC, System and Communications Protection
Control Level Title
SC-01 Low Policy and Procedures
SC-02 Moderate Separation of System and User Functionality
SC-02(01) Tailoring only Interfaces for Non-privileged Users
SC-02(02) Tailoring only Disassociability
SC-03 High Security Function Isolation
SC-03(01) Tailoring only Hardware Separation
SC-03(02) Tailoring only Access and Flow Control Functions
SC-03(03) Tailoring only Minimize Nonsecurity Functionality
SC-03(04) Tailoring only Module Coupling and Cohesiveness
SC-03(05) Tailoring only Layered Structures
SC-04 Moderate Information in Shared System Resources
SC-04(01) withdrawn → SC-04 Tailoring only Security Levels
SC-04(02) Tailoring only Multilevel or Periods Processing
SC-05 Low Denial-of-service Protection
SC-05(01) Tailoring only Restrict Ability to Attack Other Systems
SC-05(02) Tailoring only Capacity, Bandwidth, and Redundancy
SC-05(03) Tailoring only Detection and Monitoring
SC-06 Tailoring only Resource Availability
SC-07 Low Boundary Protection
SC-07(01) withdrawn → SC-07 Tailoring only Physically Separated Subnetworks
SC-07(02) withdrawn → SC-07 Tailoring only Public Access
SC-07(03) Moderate Access Points
SC-07(04) Moderate External Telecommunications Services
SC-07(05) Moderate Deny by Default — Allow by Exception
SC-07(06) withdrawn → SC-07(18) Tailoring only Response to Recognized Failures
SC-07(07) Moderate Split Tunneling for Remote Devices
SC-07(08) Moderate Route Traffic to Authenticated Proxy Servers
SC-07(09) Tailoring only Restrict Threatening Outgoing Communications Traffic
SC-07(10) Tailoring only Prevent Exfiltration
SC-07(11) Tailoring only Restrict Incoming Communications Traffic
SC-07(12) Tailoring only Host-based Protection
SC-07(13) Tailoring only Isolation of Security Tools, Mechanisms, and Support Components
SC-07(14) Tailoring only Protect Against Unauthorized Physical Connections
SC-07(15) Tailoring only Networked Privileged Accesses
SC-07(16) Tailoring only Prevent Discovery of System Components
SC-07(17) Tailoring only Automated Enforcement of Protocol Formats
SC-07(18) High Fail Secure
SC-07(19) Tailoring only Block Communication from Non-organizationally Configured Hosts
SC-07(20) Tailoring only Dynamic Isolation and Segregation
SC-07(21) High Isolation of System Components
SC-07(22) Tailoring only Separate Subnets for Connecting to Different Security Domains
SC-07(23) Tailoring only Disable Sender Feedback on Protocol Validation Failure
SC-07(24) Tailoring only Personally Identifiable Information
SC-07(25) Tailoring only Unclassified National Security System Connections
SC-07(26) Tailoring only Classified National Security System Connections
SC-07(27) Tailoring only Unclassified Non-national Security System Connections
SC-07(28) Tailoring only Connections to Public Networks
SC-07(29) Tailoring only Separate Subnets to Isolate Functions
SC-08 Moderate Transmission Confidentiality and Integrity
SC-08(01) Moderate Cryptographic Protection
SC-08(02) Tailoring only Pre- and Post-transmission Handling
SC-08(03) Tailoring only Cryptographic Protection for Message Externals
SC-08(04) Tailoring only Conceal or Randomize Communications
SC-08(05) Tailoring only Protected Distribution System
SC-09 withdrawn → SC-08 Tailoring only Transmission Confidentiality
SC-10 Moderate Network Disconnect
SC-11 Tailoring only Trusted Path
SC-11(01) Tailoring only Irrefutable Communications Path
SC-12 Low Cryptographic Key Establishment and Management
SC-12(01) High Availability
SC-12(02) Tailoring only Symmetric Keys
SC-12(03) Tailoring only Asymmetric Keys
SC-12(04) withdrawn → SC-12(03) Tailoring only PKI Certificates
SC-12(05) withdrawn → SC-12(03) Tailoring only PKI Certificates / Hardware Tokens
SC-12(06) Tailoring only Physical Control of Keys
SC-13 Low Cryptographic Protection
SC-13(01) withdrawn → SC-13 Tailoring only FIPS-validated Cryptography
SC-13(02) withdrawn → SC-13 Tailoring only NSA-approved Cryptography
SC-13(03) withdrawn → SC-13 Tailoring only Individuals Without Formal Access Approvals
SC-13(04) withdrawn → SC-13 Tailoring only Digital Signatures
SC-14 withdrawn → AC-02, AC-03, AC-05, AC-06, SI-03, SI-04, SI-05, SI-07, SI-10 Tailoring only Public Access Protections
SC-15 Low Collaborative Computing Devices and Applications
SC-15(01) Tailoring only Physical or Logical Disconnect
SC-15(02) withdrawn → SC-07 Tailoring only Blocking Inbound and Outbound Communications Traffic
SC-15(03) Tailoring only Disabling and Removal in Secure Work Areas
SC-15(04) Tailoring only Explicitly Indicate Current Participants
SC-16 Tailoring only Transmission of Security and Privacy Attributes
SC-16(01) Tailoring only Integrity Verification
SC-16(02) Tailoring only Anti-spoofing Mechanisms
SC-16(03) Tailoring only Cryptographic Binding
SC-17 Moderate Public Key Infrastructure Certificates
SC-18 Moderate Mobile Code
SC-18(01) Tailoring only Identify Unacceptable Code and Take Corrective Actions
SC-18(02) Tailoring only Acquisition, Development, and Use
SC-18(03) Tailoring only Prevent Downloading and Execution
SC-18(04) Tailoring only Prevent Automatic Execution
SC-18(05) Tailoring only Allow Execution Only in Confined Environments
SC-19 withdrawn Tailoring only Voice Over Internet Protocol
SC-20 Low Secure Name/Address Resolution Service (Authoritative Source)
SC-20(01) withdrawn → SC-20 Tailoring only Child Subspaces
SC-20(02) Tailoring only Data Origin and Integrity
SC-21 Low Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-21(01) withdrawn → SC-21 Tailoring only Data Origin and Integrity
SC-22 Low Architecture and Provisioning for Name/Address Resolution Service
SC-23 Moderate Session Authenticity
SC-23(01) Tailoring only Invalidate Session Identifiers at Logout
SC-23(02) withdrawn → AC-12(01) Tailoring only User-initiated Logouts and Message Displays
SC-23(03) Tailoring only Unique System-generated Session Identifiers
SC-23(04) withdrawn → SC-23(03) Tailoring only Unique Session Identifiers with Randomization
SC-23(05) Tailoring only Allowed Certificate Authorities
SC-24 High Fail in Known State
SC-25 Tailoring only Thin Nodes
SC-26 Tailoring only Decoys
SC-26(01) withdrawn → SC-35 Tailoring only Detection of Malicious Code
SC-27 Tailoring only Platform-independent Applications
SC-28 Moderate Protection of Information at Rest
SC-28(01) Moderate Cryptographic Protection
SC-28(02) Tailoring only Offline Storage
SC-28(03) Tailoring only Cryptographic Keys
SC-29 Tailoring only Heterogeneity
SC-29(01) Tailoring only Virtualization Techniques
SC-30 Tailoring only Concealment and Misdirection
SC-30(01) withdrawn → SC-29(01) Tailoring only Virtualization Techniques
SC-30(02) Tailoring only Randomness
SC-30(03) Tailoring only Change Processing and Storage Locations
SC-30(04) Tailoring only Misleading Information
SC-30(05) Tailoring only Concealment of System Components
SC-31 Tailoring only Covert Channel Analysis
SC-31(01) Tailoring only Test Covert Channels for Exploitability
SC-31(02) Tailoring only Maximum Bandwidth
SC-31(03) Tailoring only Measure Bandwidth in Operational Environments
SC-32 Tailoring only System Partitioning
SC-32(01) Tailoring only Separate Physical Domains for Privileged Functions
SC-33 withdrawn → SC-08 Tailoring only Transmission Preparation Integrity
SC-34 Tailoring only Non-modifiable Executable Programs
SC-34(01) Tailoring only No Writable Storage
SC-34(02) Tailoring only Integrity Protection on Read-only Media
SC-34(03) withdrawn → SC-51 Tailoring only Hardware-based Protection
SC-35 Tailoring only External Malicious Code Identification
SC-36 Tailoring only Distributed Processing and Storage
SC-36(01) Tailoring only Polling Techniques
SC-36(02) Tailoring only Synchronization
SC-37 Tailoring only Out-of-band Channels
SC-37(01) Tailoring only Ensure Delivery and Transmission
SC-38 Tailoring only Operations Security
SC-39 Low Process Isolation
SC-39(01) Tailoring only Hardware Separation
SC-39(02) Tailoring only Separate Execution Domain Per Thread
SC-40 Tailoring only Wireless Link Protection
SC-40(01) Tailoring only Electromagnetic Interference
SC-40(02) Tailoring only Reduce Detection Potential
SC-40(03) Tailoring only Imitative or Manipulative Communications Deception
SC-40(04) Tailoring only Signal Parameter Identification
SC-41 Tailoring only Port and I/O Device Access
SC-42 Tailoring only Sensor Capability and Data
SC-42(01) Tailoring only Reporting to Authorized Individuals or Roles
SC-42(02) Tailoring only Authorized Use
SC-42(03) withdrawn → SC-42 Tailoring only Prohibit Use of Devices
SC-42(04) Tailoring only Notice of Collection
SC-42(05) Tailoring only Collection Minimization
SC-43 Tailoring only Usage Restrictions
SC-44 Tailoring only Detonation Chambers
SC-45 Tailoring only System Time Synchronization
SC-45(01) Tailoring only Synchronization with Authoritative Time Source
SC-45(02) Tailoring only Secondary Authoritative Time Source
SC-46 Tailoring only Cross Domain Policy Enforcement
SC-47 Tailoring only Alternate Communications Paths
SC-48 Tailoring only Sensor Relocation
SC-48(01) Tailoring only Dynamic Relocation of Sensors or Monitoring Capabilities
SC-49 Tailoring only Hardware-enforced Separation and Policy Enforcement
SC-50 Tailoring only Software-enforced Separation and Policy Enforcement
SC-51 Tailoring only Hardware-based Protection
System and Information Integrity  · 119 controls

System and Information Integrity (SI)

Our thematic mapping puts this group against (b) (e) (g)

NIST 800-53 controls in SI, System and Information Integrity
Control Level Title
SI-01 Low Policy and Procedures
SI-02 Low Flaw Remediation
SI-02(01) withdrawn → PL-09 Tailoring only Central Management
SI-02(02) Moderate Automated Flaw Remediation Status
SI-02(03) Tailoring only Time to Remediate Flaws and Benchmarks for Corrective Actions
SI-02(04) Tailoring only Automated Patch Management Tools
SI-02(05) Tailoring only Automatic Software and Firmware Updates
SI-02(06) Tailoring only Removal of Previous Versions of Software and Firmware
SI-02(07) Tailoring only Root Cause Analysis
SI-03 Low Malicious Code Protection
SI-03(01) withdrawn → PL-09 Tailoring only Central Management
SI-03(02) withdrawn → SI-03 Tailoring only Automatic Updates
SI-03(03) withdrawn → AC-06(10) Tailoring only Non-privileged Users
SI-03(04) Tailoring only Updates Only by Privileged Users
SI-03(05) withdrawn → MP-07 Tailoring only Portable Storage Devices
SI-03(06) Tailoring only Testing and Verification
SI-03(07) withdrawn → SI-03 Tailoring only Nonsignature-based Detection
SI-03(08) Tailoring only Detect Unauthorized Commands
SI-03(09) withdrawn → AC-17(10) Tailoring only Authenticate Remote Commands
SI-03(10) Tailoring only Malicious Code Analysis
SI-04 Low System Monitoring
SI-04(01) Tailoring only System-wide Intrusion Detection System
SI-04(02) Moderate Automated Tools and Mechanisms for Real-time Analysis
SI-04(03) Tailoring only Automated Tool and Mechanism Integration
SI-04(04) Moderate Inbound and Outbound Communications Traffic
SI-04(05) Moderate System-generated Alerts
SI-04(06) withdrawn → AC-06(10) Tailoring only Restrict Non-privileged Users
SI-04(07) Tailoring only Automated Response to Suspicious Events
SI-04(08) withdrawn → SI-04 Tailoring only Protection of Monitoring Information
SI-04(09) Tailoring only Testing of Monitoring Tools and Mechanisms
SI-04(10) High Visibility of Encrypted Communications
SI-04(11) Tailoring only Analyze Communications Traffic Anomalies
SI-04(12) High Automated Organization-generated Alerts
SI-04(13) Tailoring only Analyze Traffic and Event Patterns
SI-04(14) High Wireless Intrusion Detection
SI-04(15) Tailoring only Wireless to Wireline Communications
SI-04(16) Tailoring only Correlate Monitoring Information
SI-04(17) Tailoring only Integrated Situational Awareness
SI-04(18) Tailoring only Analyze Traffic and Covert Exfiltration
SI-04(19) Tailoring only Risk for Individuals
SI-04(20) High Privileged Users
SI-04(21) Tailoring only Probationary Periods
SI-04(22) High Unauthorized Network Services
SI-04(23) Tailoring only Host-based Devices
SI-04(24) Tailoring only Indicators of Compromise
SI-04(25) Tailoring only Optimize Network Traffic Analysis
SI-05 Low Security Alerts, Advisories, and Directives
SI-05(01) High Automated Alerts and Advisories
SI-06 High Security and Privacy Function Verification
SI-06(01) withdrawn → SI-06 Tailoring only Notification of Failed Security Tests
SI-06(02) Tailoring only Automation Support for Distributed Testing
SI-06(03) Tailoring only Report Verification Results
SI-07 Moderate Software, Firmware, and Information Integrity
SI-07(01) Moderate Integrity Checks
SI-07(02) High Automated Notifications of Integrity Violations
SI-07(03) Tailoring only Centrally Managed Integrity Tools
SI-07(04) withdrawn → SR-09 Tailoring only Tamper-evident Packaging
SI-07(05) High Automated Response to Integrity Violations
SI-07(06) Tailoring only Cryptographic Protection
SI-07(07) Moderate Integration of Detection and Response
SI-07(08) Tailoring only Auditing Capability for Significant Events
SI-07(09) Tailoring only Verify Boot Process
SI-07(10) Tailoring only Protection of Boot Firmware
SI-07(11) withdrawn → CM-07(06) Tailoring only Confined Environments with Limited Privileges
SI-07(12) Tailoring only Integrity Verification
SI-07(13) withdrawn → CM-07(07) Tailoring only Code Execution in Protected Environments
SI-07(14) withdrawn → CM-07(08) Tailoring only Binary or Machine Executable Code
SI-07(15) High Code Authentication
SI-07(16) Tailoring only Time Limit on Process Execution Without Supervision
SI-07(17) Tailoring only Runtime Application Self-protection
SI-08 Moderate Spam Protection
SI-08(01) withdrawn → PL-09 Tailoring only Central Management
SI-08(02) Moderate Automatic Updates
SI-08(03) Tailoring only Continuous Learning Capability
SI-09 withdrawn → AC-02, AC-03, AC-05, AC-06 Tailoring only Information Input Restrictions
SI-10 Moderate Information Input Validation
SI-10(01) Tailoring only Manual Override Capability
SI-10(02) Tailoring only Review and Resolve Errors
SI-10(03) Tailoring only Predictable Behavior
SI-10(04) Tailoring only Timing Interactions
SI-10(05) Tailoring only Restrict Inputs to Trusted Sources and Approved Formats
SI-10(06) Tailoring only Injection Prevention
SI-11 Moderate Error Handling
SI-12 Low Information Management and Retention
SI-12(01) Tailoring only Limit Personally Identifiable Information Elements
SI-12(02) Tailoring only Minimize Personally Identifiable Information in Testing, Training, and Research
SI-12(03) Tailoring only Information Disposal
SI-13 Tailoring only Predictable Failure Prevention
SI-13(01) Tailoring only Transferring Component Responsibilities
SI-13(02) withdrawn → SI-07(16) Tailoring only Time Limit on Process Execution Without Supervision
SI-13(03) Tailoring only Manual Transfer Between Components
SI-13(04) Tailoring only Standby Component Installation and Notification
SI-13(05) Tailoring only Failover Capability
SI-14 Tailoring only Non-persistence
SI-14(01) Tailoring only Refresh from Trusted Sources
SI-14(02) Tailoring only Non-persistent Information
SI-14(03) Tailoring only Non-persistent Connectivity
SI-15 Tailoring only Information Output Filtering
SI-16 Moderate Memory Protection
SI-17 Tailoring only Fail-safe Procedures
SI-18 Tailoring only Personally Identifiable Information Quality Operations
SI-18(01) Tailoring only Automation Support
SI-18(02) Tailoring only Data Tags
SI-18(03) Tailoring only Collection
SI-18(04) Tailoring only Individual Requests
SI-18(05) Tailoring only Notice of Correction or Deletion
SI-19 Tailoring only De-identification
SI-19(01) Tailoring only Collection
SI-19(02) Tailoring only Archiving
SI-19(03) Tailoring only Release
SI-19(04) Tailoring only Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers
SI-19(05) Tailoring only Statistical Disclosure Control
SI-19(06) Tailoring only Differential Privacy
SI-19(07) Tailoring only Validated Algorithms and Software
SI-19(08) Tailoring only Motivated Intruder
SI-20 Tailoring only Tainting
SI-21 Tailoring only Information Refresh
SI-22 Tailoring only Information Diversity
SI-23 Tailoring only Information Fragmentation
Supply Chain Risk Management  · 27 controls

Supply Chain Risk Management (SR)

Our thematic mapping puts this group against (d)

NIST 800-53 controls in SR, Supply Chain Risk Management
Control Level Title
SR-01 Low Policy and Procedures
SR-02 Low Supply Chain Risk Management Plan
SR-02(01) Low Establish SCRM Team
SR-03 Low Supply Chain Controls and Processes
SR-03(01) Tailoring only Diverse Supply Base
SR-03(02) Tailoring only Limitation of Harm
SR-03(03) Tailoring only Sub-tier Flow Down
SR-04 Tailoring only Provenance
SR-04(01) Tailoring only Identity
SR-04(02) Tailoring only Track and Trace
SR-04(03) Tailoring only Validate as Genuine and Not Altered
SR-04(04) Tailoring only Supply Chain Integrity — Pedigree
SR-05 Low Acquisition Strategies, Tools, and Methods
SR-05(01) Tailoring only Adequate Supply
SR-05(02) Tailoring only Assessments Prior to Selection, Acceptance, Modification, or Update
SR-06 Moderate Supplier Assessments and Reviews
SR-06(01) Tailoring only Testing and Analysis
SR-07 Tailoring only Supply Chain Operations Security
SR-08 Low Notification Agreements
SR-09 High Tamper Resistance and Detection
SR-09(01) High Multiple Stages of System Development Life Cycle
SR-10 Low Inspection of Systems or Components
SR-11 Low Component Authenticity
SR-11(01) Low Anti-counterfeit Training
SR-11(02) Low Configuration Control for Component Service and Repair
SR-11(03) Tailoring only Anti-counterfeit Scanning
SR-12 Low Component Disposal

Where each reference takes you

Every identifier on this page is a link. Inside the site: a control identifier links to itself, so you can cite a single row in an audit note; a group heading links to itself; and every article 21(2) letter opens that measure in full — its wording, what it means and what an auditor asks for.

Catalogue reviewed , against NIST SP 800-53 Rev. 5 requirements of 5.2.0. NIST 800-53 and the documents it comes from belong to National Institute of Standards and Technology (NIST).

Sources

We are not affiliated with National Institute of Standards and Technology (NIST). NIST 800-53 and related marks belong to their owners.

Cart 0