Note that NIST Special Publication (SP) 800-53, 800-53A, and SP 800-53B contain additional background, scoping, and implementation guidance in addition to the controls, assessment procedures, and baselines. This NIST SP 800-53 database represents the derivative format of controls defined in NIST SP 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations. Derivative data formats of the forthcoming SP 800-53A, Revision 5 controls will be available when the publication is finalized (anticipated by early 2022).
If there are any discrepancies noted in the content between these NIST SP 800-53 derivative data formats and the latest published NIST SP 800-53, Revision 5 (normative) and NIST SP 800-53B (normative), please contact sec-cert@nist.gov and refer to the official published documents.
See Additional Resource Downloads for graphics and the RMF Step FAQs.
SP 800-53, Revision 5 Controls
Authoritative Source: NIST SP 800-53, Revision 5 |
SP 800-53B Control Baselines
|
SP 800-53, Revision 4 Controls
Authoritative Source: NIST SP 800-53, Revision 4 |
SP 800-53A, Revision 4 Assessment Procedures
|
SP 800-53, Revision 3 Controls Authoritative Source: NIST SP 800-53, Revision 3 |
SP 800-53A, Revision 1* Assessment Procedures
|
Security and Privacy: general security & privacy, privacy, risk management, security measurement, security programs & operations
Laws and Regulations: E-Government Act, Federal Information Security Modernization Act