NIST 800-53
Catalog of security and privacy controls for federal information systems and organizations.
NIST Special Publication 800-53 is the comprehensive catalog of security and privacy controls developed by the National Institute of Standards and Technology for federal information systems, originally mandated by the Federal Information Security Management Act (FISMA, 2002, updated FISMA 2014). The catalog (Revision 5, published September 2020 with subsequent updates) organizes 1,189 controls across 20 control families including Access Control, Audit and Accountability, Configuration Management, Contingency Planning, Identification and Authentication, Incident Response, Risk Assessment, System and Communications Protection, and System and Information Integrity. Controls are tailored to system risk levels (Low, Moderate, High) per FIPS 199 categorization, with control baselines specifying which controls apply at each level (NIST 800-53B). Revision 5 substantially restructured the catalog with control statements written more clearly, with explicit privacy controls integrated alongside security (rather than as a separate publication), and with substantial new content on supply chain risk, cyber resilience, and modernization. NIST 800-53 is the foundational control catalog for US federal systems, has substantial influence beyond federal contexts (state and local government, healthcare via HITRUST, defense industrial base via CMMC), and is widely used internationally as a reference even where not explicitly required. The catalog is used in conjunction with NIST 800-37 (Risk Management Framework, separately enriched) which specifies the process for selecting, implementing, assessing, authorizing, and monitoring controls.
Core components
- Catalog of 1,189 controls (Rev 5)
- 20 control families (Access Control, Audit, Configuration Management, Contingency Planning, IA, Incident Response, Risk Assessment, etc.)
- Three baselines: Low, Moderate, High (NIST 800-53B)
- Control structure: control text, discussion, related controls, references
- Privacy controls integrated in Rev 5
- Supply chain risk management additions
- Tailoring guidance for system-specific selection
- Use with NIST 800-37 RMF
- FISMA mandate for federal systems
- Influence beyond federal contexts (HITRUST, CMMC, state/local government)
Primary use case
Foundational control catalog for US federal information systems under FISMA; basis for control selection in federal authorization to operate (ATO) decisions; reference framework in defense industrial base (CMMC), healthcare (HITRUST CSF), and state/local government cybersecurity; foundation for substantial cybersecurity consulting and certification practice; pedagogical reference in cybersecurity education; integration with FedRAMP for cloud service authorization.
Common criticisms
- Volume of controls (1,189 in Rev 5) makes implementation enormously demanding even with tailoring guidance — many federal systems struggle with comprehensive 800-53 compliance
- cost of implementation and assessment is substantial, with much federal cyber budget consumed by 800-53 process work
- tendency toward checklist compliance rather than substantive security improvement (the same critique applies to most regulatory-standard frameworks)
- some controls are written at high abstraction level requiring substantial interpretive work for specific environments
- integration with cloud, DevOps, and modern architecture patterns has improved through Rev 5 but remains incomplete
- distinguishing between controls that meaningfully reduce risk and controls that exist for compliance reasons is genuinely difficult
- commercial GRC platforms have produced compliance-tracking automation that may obscure substantive security questions
- cross-walking with other frameworks (ISO 27002, CIS Controls, etc.) requires substantial effort that organizations often duplicate
- the framework's federal origin has shaped specific control choices that don't always travel well to non-federal contexts.
Lineage
- Siblings
- NIST Risk Management Framework, ISO/IEC 27002, CIS Controls