Date Published: August 2009 (Updated 5/1/2010)
Withdrawn: April 30, 2014
Superseded By: SP 800-53 Rev. 4 (April 2013)
Supersedes: SP 800-53 Rev. 3 (August 2009 (Updated 9/14/2009))
Author(s)
Joint Task Force Transformation Initiative
The objective of NIST SP 800-53 is to provide a set of security controls that can satisfy the breadth and depth of security requirements levied on information systems and organizations and that is consistent with and complementary to other established information security standards. Revision 3 is the first major update since December 2005 and includes significant improvements to the security control catalog.
The objective of NIST SP 800-53 is to provide a set of security controls that can satisfy the breadth and depth of security requirements levied on information systems and organizations and that is consistent with and complementary to other established information security standards. Revision 3 is...
See full abstract
The objective of NIST SP 800-53 is to provide a set of security controls that can satisfy the breadth and depth of security requirements levied on information systems and organizations and that is consistent with and complementary to other established information security standards. Revision 3 is the first major update since December 2005 and includes significant improvements to the security control catalog.
Hide full abstract
Keywords
common controls; FISMA; managing risk; risk management framework; security control assurance; security control baselines; security controls; security requirements
Control Families
Access Control;
Audit and Accountability;
Awareness and Training;
Security Assessment and Authorization;
Configuration Management;
Contingency Planning;
Identification and Authentication;
Incident Response;
Maintenance;
Media Protection;
Personnel Security;
Physical and Environmental Protection;
Planning;
Risk Assessment;
System and Communications Protection;
System and Information Integrity;
System and Services Acquisition;