Skip to content
Mandatory · lawNISTUSvRev. 5

NIST 800-53

NIST SP 800-53 Rev. 5

The comprehensive catalog of security and privacy controls organized into 20 families. It is the source catalog that most US government compliance programs select from via baselines.

Official source ↗

Who it applies to

US federalFederal contractorsInternational (reference)

Mandatory for US federal information systems under FISMA and for many federal contractors; widely reused worldwide as the reference control catalog that underpins FedRAMP, CMMC and other programs.

AC — Access Control

AU — Audit and Accountability

CM — Configuration Management

CP — Contingency Planning

IR — Incident Response

PM — Program Management

RA — Risk Assessment

SC — System and Communications Protection