Asurvo
Security framework

Run NIST 800-53 with
confidence.

NIST Special Publication 800-53 provides a comprehensive catalog of security and privacy controls for information systems and organizations to protect operations, assets, individuals, and the nation from a diverse set of threats.

Who it's for

US federal agencies and contractors operating federal information systems.

Scope

20 control families

Category
Security

How Asurvo helps

What you get for NIST 800-53.

Full control catalog across 20 families
Baseline selection (Low, Moderate, High)
Control enhancements modelled
Cross-mapped to NIST CSF and 800-171

Practitioner guide

How NIST SP 800-53 Rev 5 actually works

NIST Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations, is published by the National Institute of Standards and Technology. Revision 5 was released in September 2020 and is the catalog that US federal agencies, FedRAMP cloud providers, and many contractors build their security programs on. It is large, deliberately so. The skill is not implementing every control; it is selecting, tailoring, and evidencing the right ones for a specific system.

Unlike an outcome framework such as the NIST CSF, 800-53 is written at the level of individual control statements. Each control has a statement of what must be done, a discussion section explaining intent, a list of related controls, references, and in many cases numbered enhancements that strengthen the base control. Many statements contain organization-defined parameters, placeholders such as a review frequency or a lockout threshold, that you must fill in and then operate consistently.

Who is required to use it

  • Federal agencies. The Federal Information Security Modernization Act (FISMA) requires agencies to protect their information systems, and OMB and NIST guidance make 800-53 the control catalog for doing so under the Risk Management Framework (SP 800-37).
  • Cloud service providers selling to agencies. FedRAMP authorizations are built on 800-53 Rev 5 baselines with FedRAMP-specific parameters and additional requirements.
  • Contractors operating systems on behalf of an agency. If you run a federal information system, your contract will typically flow down 800-53 controls rather than the lighter NIST SP 800-171 requirements, which apply to nonfederal systems handling CUI.
  • Voluntary adopters. State governments, critical infrastructure operators, and security-mature private companies use it as a reference catalog because of its depth and its published mappings.

The 20 control families

Rev 5 organizes controls into 20 families, each with a two-letter identifier. Two families were new in Rev 5: PII Processing and Transparency (PT) and Supply Chain Risk Management (SR). Rev 5 also integrated privacy controls into the main catalog instead of keeping them in a separate appendix, and rewrote control statements to be outcome-based so they apply to organizations as well as systems.

NIST SP 800-53 Rev 5 control families

NIST SP 800-53 Rev 5 control families
ACAccess ControlPEPhysical and Environmental Protection
ATAwareness and TrainingPLPlanning
AUAudit and AccountabilityPMProgram Management
CAAssessment, Authorization, and MonitoringPSPersonnel Security
CMConfiguration ManagementPTPII Processing and Transparency
CPContingency PlanningRARisk Assessment
IAIdentification and AuthenticationSASystem and Services Acquisition
IRIncident ResponseSCSystem and Communications Protection
MAMaintenanceSISystem and Information Integrity
MPMedia ProtectionSRSupply Chain Risk Management

Baselines, enhancements, and tailoring

In Rev 5, NIST moved the baselines out of the catalog and into a companion document, SP 800-53B. You start by categorizing the system under FIPS 199 as low, moderate, or high impact for confidentiality, integrity, and availability. The highest of the three generally determines which security baseline applies. SP 800-53B also defines a separate privacy baseline for systems that process personally identifiable information.

Baselines are a starting point, not the finished control set. Higher baselines add controls and, just as often, add enhancements to controls already present. AC-2 (Account Management) appears in every baseline, but the moderate and high baselines add enhancements such as automated account management and disabling inactive accounts. The Program Management family is not allocated to a system baseline because it is implemented once at the organization level.

  1. Categorize the system and document the rationale for each impact level.
  2. Select the matching baseline from SP 800-53B.
  3. Tailor by scoping out controls that do not apply, identifying common and inherited controls, assigning parameter values, and adding controls or enhancements where your risk assessment calls for them.
  4. Document every tailoring decision in the System Security Plan so an assessor can follow your reasoning.

An implementation roadmap that follows the RMF

The Risk Management Framework in SP 800-37 gives the order of work: prepare, categorize, select, implement, assess, authorize, and monitor. In practice, teams that stall usually tried to implement controls before finishing categorization and boundary definition, then had to redo documentation when the scope moved.

  1. Define the authorization boundary. List components, data flows, interconnections, and external services. Everything inside the boundary inherits the control set.
  2. Categorize and select. Record the FIPS 199 decision, pick the baseline, and complete tailoring with named control owners.
  3. Write implementation statements. For each control, describe who does what, with which tool, how often. Vague statements such as "the organization complies" are the most common reason for assessor findings.
  4. Implement and collect evidence. Configure systems, publish policies and procedures for each family, and connect evidence sources so screenshots are not your primary proof.
  5. Assess. Use the SP 800-53A assessment procedures (examine, interview, test) internally before an independent assessor does.
  6. Authorize. The authorizing official reviews the package and accepts residual risk, typically with a POA&M for open weaknesses.
  7. Monitor continuously. Maintain a continuous monitoring strategy covering vulnerability scanning, configuration drift, account reviews, and annual control assessments.

Artefacts assessors expect to see

Artefact, What it shows, Controls it supports comparison
System Security Plan (SSP)Boundary, categorization, and an implementation statement for every selected controlPL-2 and the whole catalog
Security categorization recordFIPS 199 impact levels and rationaleRA-2
Policies and procedures per familyThe "-1" control in each family, reviewed and approved on your defined cycleAC-1, AU-1, CM-1 and peers
Risk assessment reportThreats, vulnerabilities, likelihood, and impact for the systemRA-3
Configuration baselines and change recordsApproved configurations and controlled changesCM-2, CM-3, CM-6
Account reviews and access logsProvisioning, periodic review, and removal of accessAC-2, AU-2, AU-6
Contingency and incident response plans with test resultsPlans exist and have been exercisedCP-2, CP-4, IR-8, IR-3
Plan of Action and Milestones (POA&M)Open weaknesses with owners and datesCA-5
Continuous monitoring strategy and reportsOngoing assessment after authorizationCA-7

Where 800-53 programs go wrong

  • Leaving parameters blank. An assessor cannot test "reviews accounts at an organization-defined frequency." Every parameter needs a value, and your evidence must match it.
  • Treating enhancements as optional reading. At moderate and high, much of the testable substance lives in the enhancements.
  • Copying provider documentation. Inherited controls still need a clear statement of what the provider covers and what remains yours.
  • Letting the SSP go stale. The SSP describes a system that changes weekly. Tie updates to change management rather than to the next assessment.
  • Point-in-time evidence. Continuous monitoring is part of the framework, not an extra. Evidence gathered once a year does not demonstrate it.

Mapping 800-53 to other frameworks

Because 800-53 is so granular, it works well as a hub for cross-mapping. NIST publishes mappings between 800-53 and the NIST CSF 2.0, and between 800-53 and ISO/IEC 27001. The CUI requirements in NIST SP 800-171 were derived from the moderate baseline, which is why contractors pursuing CMMC find much of their work reusable. The one control, four frameworks article walks through how a single well-evidenced control can satisfy several standards at once.

How Asurvo helps with 800-53

Asurvo includes the NIST SP 800-53 Rev 5 catalog with baseline selection and control enhancements, and its AI cross-mapping links each control to ISO 27001, NIST CSF, and 800-171 so one piece of evidence counts everywhere it applies. Evidence flows in continuously through native integrations with AWS, Azure, GCP, Okta, Entra ID, CrowdStrike, and others listed on the integrations page, with expiry tracking so stale proof is flagged before an assessor finds it. POA&M-style remediation runs through the audit workflows with owners and deadlines.

FAQ

Frequently asked questions

What is the difference between NIST SP 800-53 and SP 800-53B?

SP 800-53 Rev 5 is the full catalog of security and privacy controls and their enhancements. SP 800-53B contains the control baselines: the low, moderate, and high security baselines and the privacy baseline. In earlier revisions the baselines were part of the main document; NIST separated them in Rev 5 so the catalog could serve audiences beyond federal systems.

Is NIST 800-53 a certification?

No. There is no NIST 800-53 certificate. Federal systems receive an authorization to operate from an authorizing official after an assessment, and cloud providers pursue FedRAMP authorization based on 800-53 baselines. Private organizations can have an independent assessor evaluate their implementation, but the result is an assessment report, not a certification issued by NIST.

How does NIST 800-53 relate to FedRAMP?

FedRAMP uses NIST SP 800-53 Rev 5 as its control catalog. It defines its own baselines built from the NIST baselines, sets values for many organization-defined parameters, and adds program-specific requirements and documentation templates. A cloud provider that has implemented an 800-53 moderate baseline has a strong foundation for FedRAMP but still needs to meet those FedRAMP-specific expectations.

Should a private company use 800-53 or NIST 800-171?

If you handle Controlled Unclassified Information on your own systems under a defense or federal contract, 800-171 is normally the contractual requirement. If you operate a system on behalf of a federal agency or sell cloud services to agencies, expect 800-53. Private companies with no federal obligation often use 800-53 as a detailed reference catalog alongside a lighter framework such as the NIST CSF.

What are control enhancements in NIST 800-53?

Enhancements are numbered additions to a base control that add functionality or strength, written with the enhancement number in parentheses, such as AC-2(1). They are not separate controls and only apply when the base control is selected. The moderate and high baselines add many enhancements, so they often account for much of the effort in higher-impact systems.

Ready to run NIST 800-53 on Asurvo?

Book a walkthrough and see the framework live.