Skip to content

Essential EightNIST 800-53 crosswalk

A control-by-control mapping between ACSC Essential Eight and NIST SP 800-53 Rev. 5. 8 mappings.

Essential EightNIST 800-53RelationshipNotes
E8-1
Patch applications
RA-5
Vulnerability monitoring and scanning
EquivalentCurated
Vulnerability management
E8-2
Patch operating systems
RA-5
Vulnerability monitoring and scanning
EquivalentCurated
Vulnerability management
E8-3
Multi-factor authentication
AC-2
Account management
PartialCurated
Access control & identity
E8-4
Restrict administrative privileges
AC-2
Account management
PartialCurated
Access control & identity
E8-5
Application control
CM-6
Configuration settings
PartialCurated
Secure configuration & hardening
E8-6
Restrict Microsoft Office macros
CM-6
Configuration settings
PartialCurated
Secure configuration & hardening
E8-7
User application hardening
CM-6
Configuration settings
PartialCurated
Secure configuration & hardening
E8-8
Regular backups
CP-9
System backup
EquivalentCurated
Backup & recovery

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.