Security and privacy controls, mapped and made actionable.
NIST Special Publication 800-53 is the authoritative catalog of security and privacy controls for federal information systems and any organization that processes, stores, or transmits federal data. It tells organizations what to implement — specific, auditable controls — rather than describing high-level outcomes.
Controls are grouped into 20 families spanning access control, audit, incident response, supply chain risk, and more. Each control is assigned to one or more baselines (Low, Moderate, High, Privacy). Organizations select the baseline that matches their system's impact level — not every control applies to every system.
A set of standards, guidelines, and best practices for security and privacy
Helps prevent, detect, and respond to cyber threats across the full control lifecycle
Organized into 20 control families, from Access Control (AC) through Supply Chain Risk Management (SR)
Baseline-scoped — implementation depth depends on a system's impact level
Distinct from NIST CSF (outcomes framework) and NIST SP 800-171 (CUI protection subset)
NIST SP 800-53 governs far more than internal IT. Many of its controls dictate how organizations select, assess, and monitor the vendors and external services in their supply chain.
Required under FISMA and foundational to FedRAMP authorization packages.
CMMC and DFARS flows reference 800-53 control language; supply chain programs inherit SA and SR family requirements.
Organizations handling CUI, FCI, or federal contract data align vendor and internal posture to 800-53 baselines.
Vendor assessments, security questionnaires, and continuous monitoring map directly to SA, SR, PS, and RA controls.
Many 800-53 controls govern how organizations select, assess, and monitor vendors and external services — not just internal IT. UpGuard helps teams operationalize those requirements through automated questionnaires, continuous external monitoring, and risk-mapped reporting.
NIST SP 800-53 Rev 5 defines four baseline profiles. Each baseline is a curated subset of controls appropriate for a given impact level.
Minimal impact systems
For systems where loss of confidentiality, integrity, or availability would have a limited adverse effect.
Most federal & enterprise systems
The default for many federal systems and the baseline most organizations reference for vendor assessments.
Critical infrastructure
For systems where a breach could cause severe or catastrophic harm to operations, assets, or individuals.
Privacy overlay controls
Additional controls to manage privacy risk beyond the security baseline — often combined with Low, Moderate, or High.
NIST SP 800-53 organizes controls into 20 families. Select a family to browse its controls, implementation guidance, and cross-framework mappings.
Govern who can access systems and data, and under what conditions.
Ensure personnel understand security risks and their responsibilities.
Record, review, and protect audit logs of system activity.
Assess control effectiveness and maintain ongoing system authorization.
Establish and maintain secure baseline configurations for systems.
Prepare for and recover from disruptions to system operations.
Verify user and device identity before granting system access.
Detect, respond to, and recover from security incidents.
Perform system maintenance securely and with appropriate oversight.
Protect and sanitize system media containing sensitive data.
Restrict physical access to systems, facilities, and equipment.
Develop and maintain security and privacy plans for systems.
Govern the organization-wide security and privacy program.
Screen personnel and manage access through the employment lifecycle.
Manage how personally identifiable information is processed and disclosed.
Identify, assess, and respond to organizational and system risk.
Manage security in system development and external service acquisition.
Protect communications and boundaries between systems and networks.
Detect flaws, malware, and unauthorized changes to systems.
Looking for a specific control? Start with these frequently referenced requirements.
Orphaned accounts, over-provisioned vendor access, and lifecycle gaps.
Password policy, MFA, and credential hygiene failures.
Offboarding failures and insider access after termination.
Vendor and cloud service security requirements.
Supply chain risk program foundations.
Continuous vulnerability management and scanning.
Not sure which NIST resource you need? Here's how 800-53 differs from the frameworks it's most often confused with.
| Framework | What it is | UpGuard page |
|---|---|---|
| NIST CSF | Outcomes-based cybersecurity framework — Identify, Protect, Detect, Respond, Recover. | View hub → |
| NIST SP 800-53 (this page) | Control catalog — specific, auditable security and privacy controls. | You're here |
| NIST SP 800-171 | CUI protection requirements for non-federal organizations — an 800-53 subset. | Read guide → |
| ISO 27001:2022 | International ISMS standard with Annex A controls. | View hub → |
Every NIST SP 800-53 control page in this hub includes mapped equivalents in ISO 27001:2022 and NIST SP 800-171 — so teams can trace requirements across frameworks without maintaining separate spreadsheets.
Better assess vendor security, adherence to cybersecurity standards, and data protection capabilities.
Ensure vendors meet your NIST-aligned cybersecurity standards
Automate vendor risk assessments to detect threats across your supply chain
Map SA, SR, PS, and RA controls to onboarding, monitoring, and offboarding
Use risk-mapped questionnaires to evaluate third parties against 800-53
Free resources to help you implement and assess NIST SP 800-53 controls — use alongside the control library above.
A practical, control-by-control checklist for planning and tracking your 800-53 implementation.
A ready-to-use template to document, score, and prioritize risk against 800-53 controls.
Download the full checklist as a working resource for your security and audit teams.
Free resources to help you implement and assess NIST SP 800-53 controls — use alongside the control library above.