NIST 800-53
NIST SP 800-53 Rev. 5
The comprehensive catalog of security and privacy controls organized into 20 families. It is the source catalog that most US government compliance programs select from via baselines.
Who it applies to
Mandatory for US federal information systems under FISMA and for many federal contractors; widely reused worldwide as the reference control catalog that underpins FedRAMP, CMMC and other programs.
AC — Access Control
AU — Audit and Accountability
CM — Configuration Management
CP — Contingency Planning
IR — Incident Response
- IR-4 Incident handling13 mapped
Implement an incident-handling capability covering preparation, detection, analysis, containment, eradication and recovery.
- IR-6 Incident reporting13 mapped
Require personnel to report suspected incidents and report incident information to designated authorities within defined timeframes.
PM — Program Management
RA — Risk Assessment
SC — System and Communications Protection
- SC-28 Protection of information at rest15 mapped
Protect the confidentiality and integrity of information at rest, typically through cryptography.
- SC-8 Transmission confidentiality and integrity15 mapped
Protect the confidentiality and integrity of transmitted information, typically through cryptography.