ConceptioArchiveNIST
NISTpublic full text

NIST SP 800-53r5-upd1: Security and Privacy Controls for Information Systems and Organizations

Joint Task Force · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
accesscontrolcomputersecurityidentityincidentresponsenistriskmanagement
cybersecurity, computer security, cryptography, access control, incident response, privacy, identity, risk management, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 800-53 Rev. 5 Security and Privacy Controls for Information Systems and Organizations Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: September 2020 (includes updates as of Dec. 10, 2020) Supersedes: SP 800-53 Rev. 5 (09/23/2020) Planning Note ( 08/27/2025 ): On August 27, 2025, NIST issued a minor release of SP 800-53 (Release 5.2.0) that includes: New Control/Control Enhancements: SA-15(13), SA-24, SI-02(07) Revisions to Existing Controls: SI-07(12) Updates to Control Discussion: SA-04, SA-05, SA-08, SA-08(14), SI-02, SI-02(05) Updates to Related Controls: All -01 Controls, AU-02, AU-03, CA-07, IR-04, IR-06, IR-08, SA-15, SI-02, SI-07 A list of all the changes in the patch release is available under Supplemental Material. *** Summary of supplemental files: Analysis of updates between 800-53 Rev. 5 and Rev. 4 (Updated 1/07/22) Describes the changes to each control and control enhancement, provides a brief summary of the changes, and includes an assessment of the significance of the changes. Note that this comparison was authored by The MITRE Corporation for the Director of National Intelligence (DNI) and is being shared with permission by DNI. Mapping of Appendix J Privacy Controls (Rev. 4) to Rev. 5 Supports organizations using the privacy controls in Appendix J of SP 800-53 Rev. 4 that are transitioning to the integrated control catalog in Rev. 5. Mappings and crosswalks between 800-53 Rev. 5 and other frameworks and standards ( NIST Cybersecurity Framework and NIST Privacy Framework ; ISO/IEC 27001:2022 ) Mappings and crosswalks provide a general indication of SP 800-53 control coverage with respect to other frameworks and standards. When leveraging these relationships, consider the scope and intended use of each publication. Do not assume equivalency based solely on relationship tables; mappings and crosswalks are not always one-to-one and relationship analysis can be subjective. Also available: Security and Privacy Control Collaboration Index Template ( Excel & Word ) The collaboration index template supports information security and privacy program collaboration to help ensure that the objectives of both disciplines are met and that risks are appropriately managed. It is an optional tool for information security and privacy programs to identify the degree of collaboration needed between security and privacy programs with respect to the selection and/or implementation of controls in Rev. 5. OSCAL version of 800-53 Rev. 5 controls Rev. 5 controls are provided using the Open Security Controls Assessment Language (OSCAL); currently available in JSON, XML, and YAML. Author(s) Joint Task Force Abstract This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk. The controls address diverse requirements derived from mission and business needs, laws, executive orders, directives, regulations, policies, standards, and guidelines. Finally, the consolidated control catalog addresses security and privacy from a functionality perspective (i.e., the strength of functions and mechanisms provided by the controls) and from an assurance perspective (i.e., the measure of confidence in the security or privacy capability provided by the controls). Addressing functionality and assurance helps to ensure that information technology products and the systems that rely on those products are sufficiently trustworthy. This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural... See full abstract This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk. The controls address diverse requirements derived from mission and business needs, laws, executive orders, directives, regulations, policies, standards, and guidelines. Finally, the consolidated control catalog addresses security and privacy from a functionality perspective (i.e., the strength of functions and mechanisms provided by the controls) and from an assurance perspective (i.e., the measure of confidence in the security or privacy capability provided by the controls). Addressing functionality and assurance helps to ensure that information technology products and the systems that rely on those products are sufficiently trustworthy. Hide full abstract Keywords assurance ; availability ; computer security ; confidentiality ; control ; cybersecurity ; FISMA ; information security ; information system ; integrity ; personally identifiable information ; Privacy Act ; privacy controls ; privacy functions ; privacy requirements ; Risk Management Framework ; security controls ; security functions ; security requirements ; system ; system security Control Families Access Control ; Awareness and Training ; Audit and Accountability ; Assessment, Authorization and Monitoring ; Configuration Management ; Contingency Planning ; Identification and Authentication ; Incident Response ; Maintenance ; Media Protection ; Physical and Environmental Protection ; Planning ; Program Management ; Personnel Security ; PII Processing and Transparency ; Risk Assessment ; System and Services Acquisition ; System and Communications Protection ; System and Information Integrity ; Supply Chain Risk Management Documentation Publication: https://doi.org/10.6028/NIST.SP.800-53r5 Download URL Supplemental Material: SP 800-53 Release 5.2.0 Summary of Changes SP 800-53 Release 5.2.0 (pdf) Analysis of updates between 800-53 Rev. 5 and Rev. 4, by MITRE Corp. for ODNI (xlsx) Mapping: Appendix J Privacy Controls (Rev. 4) to Rev. 5 (xlsx) Mappings: Cybersecurity Framework and Privacy Framework to Rev. 5 (xlsx) Crosswalk: 800-53 Rev. 5 to ISO/IEC 27001:2022 (OLIR) OSCAL Version of Rev. 5 controls Control Collaboration Index Template (xlsx) Control Collaboration Index Template (docx) Blog post Publication Parts: SP 800-53A Rev. 5 SP 800-53B Related NIST Publications: IR 8170 Document History: 12/10/20: SP 800-53 Rev. 5 (Final) Topics Security and Privacy privacy controls , security controls , security programs & operations Laws and Regulations E-Government Act , Executive Order 14306 , Federal Information Security Modernization Act , Homeland Security Presidential Directive 12 , Homeland Security Presidential Directive 7 , OMB Circular A-11 , OMB Circular A-130 HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 3015 · SHA-256 65fabe541e86e198
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.