NIST 800-53

framework · cybersecurity · regulatory-standard

Catalog of security and privacy controls for federal information systems and organizations.

NIST Special Publication 800-53 is the comprehensive catalog of security and privacy controls developed by the National Institute of Standards and Technology for federal information systems, originally mandated by the Federal Information Security Management Act (FISMA, 2002, updated FISMA 2014). The catalog (Revision 5, published September 2020 with subsequent updates) organizes 1,189 controls across 20 control families including Access Control, Audit and Accountability, Configuration Management, Contingency Planning, Identification and Authentication, Incident Response, Risk Assessment, System and Communications Protection, and System and Information Integrity. Controls are tailored to system risk levels (Low, Moderate, High) per FIPS 199 categorization, with control baselines specifying which controls apply at each level (NIST 800-53B). Revision 5 substantially restructured the catalog with control statements written more clearly, with explicit privacy controls integrated alongside security (rather than as a separate publication), and with substantial new content on supply chain risk, cyber resilience, and modernization. NIST 800-53 is the foundational control catalog for US federal systems, has substantial influence beyond federal contexts (state and local government, healthcare via HITRUST, defense industrial base via CMMC), and is widely used internationally as a reference even where not explicitly required. The catalog is used in conjunction with NIST 800-37 (Risk Management Framework, separately enriched) which specifies the process for selecting, implementing, assessing, authorizing, and monitoring controls.

Originators

National Institute of Standards and Technology (NIST); Computer Security Division; substantial federal-agency input through Joint Task Force high

Year / Decade

2002 (FISMA mandate); 2005 (initial publication); 2020 (Revision 5, current); ongoing updates high

Primary sources

NIST (2020). Special Publication 800-53 Revision 5: Security and Privacy Controls for Information Systems and Organizations, NIST (2020). Special Publication 800-53B: Control Baselines for Information Systems and Organizations, FISMA (2002, 2014). Federal Information Security Management Act / Federal Information Security Modernization Act high

Core components

Primary use case

Foundational control catalog for US federal information systems under FISMA; basis for control selection in federal authorization to operate (ATO) decisions; reference framework in defense industrial base (CMMC), healthcare (HITRUST CSF), and state/local government cybersecurity; foundation for substantial cybersecurity consulting and certification practice; pedagogical reference in cybersecurity education; integration with FedRAMP for cloud service authorization.

Common criticisms

Lineage

Siblings
NIST Risk Management Framework, ISO/IEC 27002, CIS Controls