Since NIST 800-53 was first introduced, the number of controls has greatly expanded; the initial version of 800-53 contained approximately 300 controls and NIST 800-53 rev 4 contains 965 controls.
Despite the complexity, each NIST 800-53 revision makes the controls set increasingly valuable. As things like mobile, IoT, and cloud evolve, NIST continuously enhances 800-53 to make migration an ongoing requirement.
Security Objectives / Impact / Required Security Controls
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Confidentiality |
Integrity |
Availability |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Low |
Login Audit |
Antivirus |
Onsite Backup |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Moderate |
Login Audit |
Antivirus |
High Availability |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
High |
Login Audit |
Antivirus |
High Availability |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
The following list is showing those most common controls align with the impact level in 800-53.
Impact / Required Security Controls (Based on 800-53))
|
NIST SP 800-53 Full Control List
https://www.stigviewer.com/controls/800-53
NIST priorities are from P0 to P5, with P1 being the highest priority. Generally 1-5 dictates the order in which the controls should be implemented.
There is a P0 – which is the lowest priority.
Num. |
Title |
Impact |
Priority |
Subject Area |
AC-1 |
LOW |
P1 |
Access Control |
|
AC-2 |
LOW |
P1 |
Access Control |
|
AC-3 |
LOW |
P1 |
Access Control |
|
AC-7 |
LOW |
P2 |
Access Control |
|
AC-8 |
LOW |
P1 |
Access Control |
|
AC-14 |
LOW |
P3 |
Access Control |
|
AC-17 |
LOW |
P1 |
Access Control |
|
AC-18 |
LOW |
P1 |
Access Control |
|
AC-19 |
LOW |
P1 |
Access Control |
|
AC-20 |
LOW |
P1 |
Access Control |
|
AC-22 |
LOW |
P3 |
Access Control |
|
AT-1 |
LOW |
P1 |
Awareness And |
|
AT-2 |
LOW |
P1 |
Awareness And |
|
AT-3 |
LOW |
P1 |
Awareness And |
|
AT-4 |
LOW |
P3 |
Awareness And |
|
AU-1 |
LOW |
P1 |
Audit And |
|
AU-2 |
LOW |
P1 |
Audit And |
|
AU-3 |
LOW |
P1 |
Audit And |
|
AU-4 |
LOW |
P1 |
Audit And |
|
AU-5 |
LOW |
P1 |
Audit And |
|
AU-6 |
LOW |
P1 |
Audit And |
|
AU-8 |
LOW |
P1 |
Audit And |
|
AU-9 |
LOW |
P1 |
Audit And |
|
AU-11 |
LOW |
P3 |
Audit And |
|
AU-12 |
LOW |
P1 |
Audit And |
|
CA-1 |
LOW |
P1 |
Security |
|
CA-2 |
LOW |
P2 |
Security |
|
CA-3 |
LOW |
P1 |
Security |
|
CA-5 |
LOW |
P3 |
Security |
|
CA-6 |
LOW |
P2 |
Security |
|
CA-7 |
LOW |
P2 |
Security |
|
CA-9 |
LOW |
P2 |
Security |
|
CM-1 |
LOW |
P1 |
Configuration |
|
CM-2 |
LOW |
P1 |
Configuration |
|
CM-4 |
LOW |
P2 |
Configuration |
|
CM-6 |
LOW |
P1 |
Configuration |
|
CM-7 |
LOW |
P1 |
Configuration |
|
CM-8 |
LOW |
P1 |
Configuration |
|
CM-10 |
LOW |
P2 |
Configuration |
|
CM-11 |
LOW |
P1 |
Configuration |
|
CP-1 |
LOW |
P1 |
Contingency |
|
CP-2 |
LOW |
P1 |
Contingency |
|
CP-3 |
LOW |
P2 |
Contingency |
|
CP-4 |
LOW |
P2 |
Contingency |
|
CP-9 |
LOW |
P1 |
Contingency |
|
CP-10 |
LOW |
P1 |
Contingency |
|
IA-1 |
LOW |
P1 |
Identification |
|
IA-2 |
LOW |
P1 |
Identification |
|
IA-4 |
LOW |
P1 |
Identification |
|
IA-5 |
LOW |
P1 |
Identification |
|
IA-6 |
LOW |
P2 |
Identification |
|
IA-7 |
LOW |
P1 |
Identification |
|
IA-8 |
IDENTIFICATION |
LOW |
P1 |
Identification |
IR-1 |
LOW |
P1 |
Incident Response |
|
IR-2 |
LOW |
P2 |
Incident Response |
|
IR-4 |
LOW |
P1 |
Incident Response |
|
IR-5 |
LOW |
P1 |
Incident Response |
|
IR-6 |
LOW |
P1 |
Incident Response |
|
IR-7 |
LOW |
P2 |
Incident Response |
|
IR-8 |
LOW |
P1 |
Incident Response |
|
MA-1 |
LOW |
P1 |
Maintenance |
|
MA-2 |
LOW |
P2 |
Maintenance |
|
MA-4 |
LOW |
P2 |
Maintenance |
|
MA-5 |
LOW |
P2 |
Maintenance |
|
MP-1 |
LOW |
P1 |
Media Protection |
|
MP-2 |
LOW |
P1 |
Media Protection |
|
MP-6 |
LOW |
P1 |
Media Protection |
|
MP-7 |
LOW |
P1 |
Media Protection |
|
PE-1 |
LOW |
P1 |
Physical And |
|
PE-2 |
LOW |
P1 |
Physical And |
|
PE-3 |
LOW |
P1 |
Physical And |
|
PE-6 |
LOW |
P1 |
Physical And |
|
PE-8 |
LOW |
P3 |
Physical And |
|
PE-12 |
LOW |
P1 |
Physical And |
|
PE-13 |
LOW |
P1 |
Physical And |
|
PE-14 |
LOW |
P1 |
Physical And |
|
PE-15 |
LOW |
P1 |
Physical And |
|
PE-16 |
LOW |
P2 |
Physical And |
|
PL-1 |
LOW |
P1 |
Planning |
|
PL-2 |
LOW |
P1 |
Planning |
|
PL-4 |
LOW |
P2 |
Planning |
|
PS-1 |
LOW |
P1 |
Personnel |
|
PS-2 |
LOW |
P1 |
Personnel |
|
PS-3 |
LOW |
P1 |
Personnel |
|
PS-4 |
LOW |
P1 |
Personnel |
|
PS-5 |
LOW |
P2 |
Personnel |
|
PS-6 |
LOW |
P3 |
Personnel |
|
PS-7 |
LOW |
P1 |
Personnel |
|
PS-8 |
LOW |
P3 |
Personnel |
|
RA-1 |
LOW |
P1 |
Risk Assessment |
|
RA-2 |
LOW |
P1 |
Risk Assessment |
|
RA-3 |
LOW |
P1 |
Risk Assessment |
|
RA-5 |
LOW |
P1 |
Risk Assessment |
|
SA-1 |
LOW |
P1 |
System And |
|
SA-2 |
LOW |
P1 |
System And |
|
SA-3 |
LOW |
P1 |
System And |
|
SA-4 |
LOW |
P1 |
System And |
|
SA-5 |
LOW |
P2 |
System And |
|
SA-9 |
LOW |
P1 |
System And |
|
SC-1 |
LOW |
P1 |
System And |
|
SC-5 |
LOW |
P1 |
System And |
|
SC-7 |
LOW |
P1 |
System And Communications |
|
SC-12 |
LOW |
P1 |
System And |
|
SC-13 |
LOW |
P1 |
System And |
|
SC-15 |
LOW |
P1 |
System And |
|
SC-20 |
SECURE |
LOW |
P1 |
System And |
SC-21 |
SECURE |
LOW |
P1 |
System And |
SC-22 |
ARCHITECTURE |
LOW |
P1 |
System And |
SC-39 |
LOW |
P1 |
System And |
|
SI-1 |
LOW |
P1 |
System And |
|
SI-2 |
LOW |
P1 |
System And |
|
SI-3 |
LOW |
P1 |
System And |
|
SI-4 |
LOW |
P1 |
System And |
|
SI-5 |
LOW |
P1 |
System And |
|
SI-12 |
LOW |
P2 |
System And |
Num. |
Title |
Impact |
Priority |
Subject Area |
AC-4 |
MODERATE |
P1 |
Access Control |
|
AC-5 |
MODERATE |
P1 |
Access Control |
|
AC-6 |
MODERATE |
P1 |
Access Control |
|
AC-11 |
MODERATE |
P3 |
Access Control |
|
AC-12 |
MODERATE |
P2 |
Access Control |
|
AC-21 |
MODERATE |
P2 |
Access Control |
|
AU-7 |
MODERATE |
P2 |
Audit And |
|
CM-3 |
MODERATE |
P1 |
Configuration |
|
CM-5 |
MODERATE |
P1 |
Configuration |
|
CM-9 |
MODERATE |
P1 |
Configuration |
|
CP-6 |
MODERATE |
P1 |
Contingency |
|
CP-7 |
MODERATE |
P1 |
Contingency |
|
CP-8 |
MODERATE |
P1 |
Contingency |
|
IA-3 |
MODERATE |
P1 |
Identification |
|
IR-3 |
MODERATE |
P2 |
Incident Response |
|
MA-3 |
MODERATE |
P3 |
Maintenance |
|
MA-6 |
MODERATE |
P2 |
Maintenance |
|
MP-3 |
MODERATE |
P2 |
Media Protection |
|
MP-4 |
MODERATE |
P1 |
Media Protection |
|
MP-5 |
MODERATE |
P1 |
Media Protection |
|
PE-4 |
MODERATE |
P1 |
Physical And |
|
PE-5 |
MODERATE |
P2 |
Physical And |
|
PE-9 |
MODERATE |
P1 |
Physical And |
|
PE-10 |
MODERATE |
P1 |
Physical And |
|
PE-11 |
MODERATE |
P1 |
Physical And |
|
PE-17 |
MODERATE |
P2 |
Physical And |
|
PL-8 |
MODERATE |
P1 |
Planning |
|
SA-8 |
MODERATE |
P1 |
System And |
|
SA-10 |
MODERATE |
P1 |
System And |
|
SA-11 |
MODERATE |
P1 |
System And |
|
SC-2 |
MODERATE |
P1 |
System And |
|
SC-4 |
MODERATE |
P1 |
System And |
|
SC-8 |
MODERATE |
P1 |
System And |
|
SC-10 |
MODERATE |
P2 |
System And |
|
SC-17 |
MODERATE |
P1 |
System And |
|
SC-18 |
MODERATE |
P2 |
System And |
|
SC-19 |
MODERATE |
P1 |
System And Communications |
|
SC-23 |
MODERATE |
P1 |
System And |
|
SC-28 |
MODERATE |
P1 |
System And |
|
SI-7 |
MODERATE |
P1 |
System And |
|
SI-8 |
MODERATE |
P2 |
System And |
|
SI-10 |
MODERATE |
P1 |
System And |
|
SI-11 |
MODERATE |
P2 |
System And |
|
SI-16 |
MODERATE |
P1 |
System And |
Num. |
Title |
Impact |
Priority |
Subject Area |
AC-10 |
HIGH |
P3 |
Access Control |
|
AU-10 |
HIGH |
P2 |
Audit And |
|
CA-8 |
HIGH |
P2 |
Security |
|
PE-18 |
HIGH |
P3 |
Physical And |
|
SA-12 |
HIGH |
P1 |
System And |
|
SA-15 |
HIGH |
P2 |
System And |
|
SA-16 |
HIGH |
P2 |
System And |
|
SA-17 |
HIGH |
P1 |
System And |
|
SC-3 |
HIGH |
P1 |
System And |
|
SC-24 |
HIGH |
P1 |
System And |
|
SI-6 |
HIGH |
P1 |
System And |
Num. |
Title |
Impact |
Priority |
Subject Area |
AC-9 |
P0 |
Access Control |
||
AC-13 |
Access Control |
|||
AC-15 |
Access Control |
|||
AC-16 |
P0 |
Access Control |
||
AC-23 |
P0 |
Access Control |
||
AC-24 |
P0 |
Access Control |
||
AC-25 |
P0 |
Access Control |
||
AT-5 |
Awareness And |
|||
AU-13 |
P0 |
Audit And |
||
AU-14 |
P0 |
Audit And |
||
AU-15 |
P0 |
Audit And |
||
AU-16 |
P0 |
Audit And |
||
CA-4 |
Security |
|||
CP-5 |
Contingency |
|||
CP-11 |
P0 |
Contingency |
||
CP-12 |
P0 |
Contingency |
||
CP-13 |
P0 |
Contingency |
||
IA-9 |
P0 |
Identification |
||
IA-10 |
P0 |
Identification |
||
IA-11 |
P0 |
Identification |
||
IR-9 |
P0 |
Incident Response |
||
IR-10 |
P0 |
Incident Response |
||
MP-8 |
P0 |
Media Protection |
||
PE-7 |
Physical And |
|||
PE-19 |
P0 |
Physical And |
||
PE-20 |
P0 |
Physical And |
||
PL-3 |
Planning |
|||
PL-5 |
Planning |
|||
PL-6 |
Planning |
|||
PL-7 |
P0 |
Planning |
||
PL-9 |
P0 |
Planning |
||
RA-4 |
Risk Assessment |
|||
RA-6 |
P0 |
Risk Assessment |
||
SA-6 |
System And |
|||
SA-7 |
System And |
|||
SA-13 |
P0 |
System And |
||
SA-14 |
P0 |
System And |
||
SA-18 |
P0 |
System And |
||
SA-19 |
P0 |
System And |
||
SA-20 |
P0 |
System And |
||
SA-21 |
P0 |
System And |
||
SA-22 |
P0 |
System And |
||
SC-6 |
P0 |
System And |
||
SC-9 |
System And |
|||
SC-11 |
P0 |
System And |
||
SC-14 |
System And |
|||
SC-16 |
P0 |
System And |
||
SC-25 |
P0 |
System And |
||
SC-26 |
P0 |
System And |
||
SC-27 |
P0 |
System And |
||
SC-29 |
P0 |
System And |
||
SC-30 |
P0 |
System And |
||
SC-31 |
P0 |
System And |
||
SC-32 |
P0 |
System And |
||
SC-33 |
System And |
|||
SC-34 |
P0 |
System And |
||
SC-35 |
P0 |
System And |
||
SC-36 |
P0 |
System And |
||
SC-37 |
P0 |
System And |
||
SC-38 |
P0 |
System And |
||
SC-40 |
P0 |
System And |
||
SC-41 |
P0 |
System And |
||
SC-42 |
P0 |
System And |
||
SC-43 |
P0 |
System And |
||
SC-44 |
P0 |
System And |
||
SI-9 |
System And |
|||
SI-13 |
P0 |
System And |
||
SI-14 |
P0 |
System And |
||
SI-15 |
P0 |
System And |
||
SI-17 |
P0 |
System And |
||
PM-1 |
Program |
|||
PM-2 |
Program |
|||
PM-3 |
Program |
|||
PM-4 |
Program |
|||
PM-5 |
Program |
|||
PM-6 |
Program |
|||
PM-7 |
Program |
|||
PM-8 |
Program |
|||
PM-9 |
Program |
|||
PM-10 |
Program |
|||
PM-11 |
Program |
|||
PM-12 |
Program |
|||
PM-13 |
Program |
|||
PM-14 |
Program |
|||
PM-15 |
Program |
|||
PM-16 |
Program |