U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.


Secure websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to our website. Please do not share sensitive information with us.

SP 800-53A Rev. 5

Assessing Security and Privacy Controls in Information Systems and Organizations

Date Published: January 2022

Supersedes: SP 800-53A Rev. 4 (12/18/2014)

Planning Note (3/30/2022):

As stakeholders use NIST SP 800-53A and its derivative data formats, updates are identified to improve the quality of the publication.  Updates can include corrections, clarifications, or other minor changes in the publication that are either editorial or substantive in nature. Any potential updates for SP 800-53A and its derivative data formats that are not yet published in an errata update or revision—including additional issues and potential corrections—will be posted as they are identified.  Please report any potential updates to sec-cert@nist.gov.


Joint Task Force



assessment; assessment plan; assurance; control assessment; FISMA; Privacy Act; privacy controls; Open Security Controls Assessment Language; OSCAL; privacy requirements; Risk Management Framework; security controls; security requirements
Control Families

None selected