International · United States National Institute of Standards and Technology

NIST Special Publication 800-53, Security and Privacy Controls

A comprehensive catalogue of security and privacy controls, widely used as a control reference well beyond its original United States federal context.

Who it applies to

United States federal systems and their suppliers by obligation, and a much wider set of organisations by choice, because the catalogue is thorough and freely published.

What it requires

  • Control selection driven by system categorisation and a defined baseline
  • Tailoring of the baseline, with the reasoning recorded
  • Assessment of control effectiveness rather than implementation alone
  • Continuous monitoring rather than periodic snapshot assessment

What preparing for it involves

Its depth is both its strength and its difficulty. The catalogue is frequently used as a reference against which other frameworks are mapped, which is why it appears in cross-framework work far more often than as a compliance target in its own right.

How it concludes

Authorisation within a United States federal context, or an internal control position where it is adopted voluntarily.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.