CyberGlossary

Compliance & Frameworks

NIST SP 800-53

Also known as: SP 800-53, NIST 800-53

Definition

A NIST publication providing a comprehensive catalog of security and privacy controls for U.S. federal information systems and many private-sector adopters.

NIST Special Publication 800-53 is the authoritative catalog of security and privacy controls developed by the U.S. National Institute of Standards and Technology. Currently in Revision 5, it defines hundreds of controls organized into 20 control families (e.g., Access Control, Audit and Accountability, System and Communications Protection) along with control enhancements and supplemental guidance. SP 800-53 is mandatory for U.S. federal information systems under FISMA and FedRAMP, and is widely adopted by contractors, state governments, and critical-infrastructure operators worldwide. Organizations typically select a baseline (low, moderate, high) using NIST SP 800-53B and tailor it to their risk profile.

Examples

  • A federal agency implementing the moderate baseline to authorize a new system under FISMA.
  • A FedRAMP cloud service provider mapping controls to the high baseline.

Related terms