NIST 800-53 Security Controls Reference
A practical reference guide to NIST SP 800-53 security and privacy controls for IT auditors assessing federal and enterprise information systems.
NIST Special Publication 800-53 provides a comprehensive catalog of security and privacy controls for information systems and organizations. While originally developed for U.S. federal agencies, the control catalog is widely adopted by private sector organizations as a benchmark for information security programs. CISA professionals benefit from understanding this framework for auditing both government and commercial environments.
Framework Structure
NIST 800-53 Revision 5 organizes controls into 20 families, each addressing a specific area of security or privacy. Controls are designated with a family identifier and number (for example, AC-1 for the first control in the Access Control family). Each control includes a description, supplemental guidance, and related controls.
Control Families Overview
Access Control (AC)
Controls governing who can access information systems and data. Includes account management, access enforcement, separation of duties, least privilege, unsuccessful logon attempts, session management, and remote access controls. Auditors should verify that access policies are implemented technically and reviewed periodically.
Audit and Accountability (AU)
Controls ensuring that information system activities are recorded, reviewed, and retained. Covers audit events, content of audit records, audit storage, audit log review, audit reduction and report generation, and protection of audit information. This family is critical for IT auditors assessing detection and monitoring capabilities.
Security Assessment and Authorization (CA)
Controls related to security assessments, system authorization, continuous monitoring, and penetration testing. Auditors should evaluate the organization's approach to security authorization (previously known as certification and accreditation) and ongoing assessment activities.
Configuration Management (CM)
Controls for establishing and maintaining baseline configurations, managing system changes, analyzing security impact, restricting access to change, and managing configuration settings. Configuration management is foundational to ITGC assessments.
Identification and Authentication (IA)
Controls for identifying and authenticating users, devices, and processes. Covers multi-factor authentication, identifier management, authenticator management, and cryptographic module authentication. The strength of identification and authentication controls directly impacts the effectiveness of access controls.
Incident Response (IR)
Controls for establishing incident response capabilities, including training, testing, handling, monitoring, and reporting. Auditors should assess whether incident response plans are comprehensive, tested regularly, and updated based on lessons learned.
Risk Assessment (RA)
Controls for conducting risk assessments, vulnerability scanning, and risk response. This family supports the risk-based approach that underpins the entire NIST framework and aligns with CISA Domain 1 audit methodology.
System and Communications Protection (SC)
Controls protecting information in transit and at rest, including boundary protection, cryptographic mechanisms, network segmentation, and denial-of-service protection. These technical controls are frequently tested in IT audit engagements.
Control Baselines
NIST 800-53 defines three control baselines corresponding to system impact levels:
- Low Baseline: For systems where loss of confidentiality, integrity, or availability would have limited adverse effect
- Moderate Baseline: For systems where loss would have serious adverse effect
- High Baseline: For systems where loss would have severe or catastrophic adverse effect
Organizations select a baseline based on their system categorization (following FIPS 199) and then tailor it by adding or removing controls based on their specific risk assessment.
Practical Audit Application
- Control Selection Review: Verify that the organization has appropriately categorized systems and selected the correct baseline
- Implementation Assessment: Evaluate whether selected controls are implemented as described in system security plans
- Effectiveness Testing: Test a sample of controls for operating effectiveness
- Continuous Monitoring: Assess whether the organization monitors controls on an ongoing basis
- Plan of Action and Milestones: Review documented weaknesses and remediation plans
Relationship to Other Frameworks
NIST 800-53 controls map to many other frameworks including ISO 27001, NIST CSF, and COBIT. NIST provides crosswalks that facilitate mapping between frameworks, enabling auditors to satisfy multiple compliance requirements through a single assessment when possible.
Proficiency with NIST 800-53 is particularly valuable for IT auditors working with government agencies, contractors, and organizations that adopt NIST standards as their security baseline. The comprehensive nature of the control catalog also makes it an excellent reference for evaluating security programs in any context.