ConceptioArchiveNIST
NISTpublic full text

NIST SP 800-53Ar5: Assessing Security and Privacy Controls in Information Systems and Organizations

Joint Task Force · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
accesscontrolcomputersecurityidentityincidentresponsenistriskmanagement
cybersecurity, computer security, cryptography, access control, incident response, privacy, identity, risk management, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 800-53A Rev. 5 Assessing Security and Privacy Controls in Information Systems and Organizations Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: January 2022 Supersedes: SP 800-53A Rev. 4 (12/18/2014) Planning Note ( 08/27/2025 ): On August 27, 2025, NIST issued a minor release of SP 800-53A (Release 5.2.0) that includes the following changes: New Assessment Procedures: SA-15(13), SA-24, SI-02(07) *** As stakeholders use NIST SP 800-53A and its derivative data formats, updates are identified to improve the quality of the publication.  Updates can include corrections, clarifications, or other minor changes in the publication that are either editorial or substantive in nature. Any potential updates for SP 800-53A and its derivative data formats that are not yet published in an errata update or revision—including additional issues and potential corrections—will be posted as they are identified.  Please report any potential updates to [email protected] . Author(s) Joint Task Force Abstract This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results. This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life... See full abstract This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results. Hide full abstract Keywords assessment ; assessment plan ; assurance ; control assessment ; FISMA ; Privacy Act ; privacy controls ; Open Security Controls Assessment Language ; OSCAL ; privacy requirements ; Risk Management Framework ; security controls ; security requirements Control Families None selected Documentation Publication: https://doi.org/10.6028/NIST.SP.800-53Ar5 Download URL Supplemental Material: SP 800-53A Release 5.2.0 OSCAL GitHub Publication Parts: SP 800-53B SP 800-53 Rev. 5 Document History: 08/03/21: SP 800-53A Rev. 5 (Draft) 01/25/22: SP 800-53A Rev. 5 (Final) Topics Security and Privacy controls assessment Laws and Regulations Executive Order 14306 , Federal Information Security Modernization Act HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 3013 · SHA-256 712051e5f8b88a74
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.