Compliance & Frameworks
NIST SP 800-53
Also known as: SP 800-53, NIST 800-53
Definition
A NIST publication providing a comprehensive catalog of security and privacy controls for U.S. federal information systems and many private-sector adopters.
Examples
- A federal agency implementing the moderate baseline to authorize a new system under FISMA.
- A FedRAMP cloud service provider mapping controls to the high baseline.
Related terms
NIST Cybersecurity Framework
A voluntary risk-based framework published by the U.S. National Institute of Standards and Technology that organizes cybersecurity outcomes into six core functions.
NIST SP 800-171
A NIST publication defining security requirements for protecting Controlled Unclassified Information (CUI) stored or processed by non-federal organizations.
FISMA
FISMA — definition coming soon.
FedRAMP
FedRAMP — definition coming soon.
NIST Risk Management Framework
NIST Risk Management Framework — definition coming soon.
Security Controls
Safeguards or countermeasures — technical, administrative, or physical — used to prevent, detect, or respond to threats against information assets.