All frameworks
nist-80053-rev5version Rev. 5

NIST SP 800-53 Rev. 5

Official source

1,196 controls.

ReferenceFamilyTitle
PT-3(2)Personally Identifiable Information Processing and TransparencyAutomation
PT-4Personally Identifiable Information Processing and TransparencyConsent
PT-4(1)Personally Identifiable Information Processing and TransparencyTailored Consent
PT-4(2)Personally Identifiable Information Processing and TransparencyJust-in-time Consent
PT-4(3)Personally Identifiable Information Processing and TransparencyRevocation
PT-5Personally Identifiable Information Processing and TransparencyPrivacy Notice
PT-5(1)Personally Identifiable Information Processing and TransparencyJust-in-time Notice
PT-5(2)Personally Identifiable Information Processing and TransparencyPrivacy Act Statements
PT-6Personally Identifiable Information Processing and TransparencySystem of Records Notice
PT-6(1)Personally Identifiable Information Processing and TransparencyRoutine Uses
PT-6(2)Personally Identifiable Information Processing and TransparencyExemption Rules
PT-7Personally Identifiable Information Processing and TransparencySpecific Categories of Personally Identifiable Information
PT-7(1)Personally Identifiable Information Processing and TransparencySocial Security Numbers
PT-7(2)Personally Identifiable Information Processing and TransparencyFirst Amendment Information
PT-8Personally Identifiable Information Processing and TransparencyComputer Matching Requirements
RA-1Risk AssessmentPolicy and Procedures
RA-10Risk AssessmentThreat Hunting
RA-2Risk AssessmentSecurity Categorization
RA-2(1)Risk AssessmentImpact-level Prioritization
RA-3Risk AssessmentRisk Assessment
RA-3(1)Risk AssessmentSupply Chain Risk Assessment
RA-3(2)Risk AssessmentUse of All-source Intelligence
RA-3(3)Risk AssessmentDynamic Threat Awareness
RA-3(4)Risk AssessmentPredictive Cyber Analytics
RA-4Risk AssessmentRisk Assessment Update
RA-5Risk AssessmentVulnerability Monitoring and Scanning
RA-5(1)Risk AssessmentUpdate Tool Capability
RA-5(10)Risk AssessmentCorrelate Scanning Information
RA-5(11)Risk AssessmentPublic Disclosure Program
RA-5(2)Risk AssessmentUpdate Vulnerabilities to Be Scanned
RA-5(3)Risk AssessmentBreadth and Depth of Coverage
RA-5(4)Risk AssessmentDiscoverable Information
RA-5(5)Risk AssessmentPrivileged Access
RA-5(6)Risk AssessmentAutomated Trend Analyses
RA-5(7)Risk AssessmentAutomated Detection and Notification of Unauthorized Components
RA-5(8)Risk AssessmentReview Historic Audit Logs
RA-5(9)Risk AssessmentPenetration Testing and Analyses
RA-6Risk AssessmentTechnical Surveillance Countermeasures Survey
RA-7Risk AssessmentRisk Response
RA-8Risk AssessmentPrivacy Impact Assessments
RA-9Risk AssessmentCriticality Analysis
SA-1System and Services AcquisitionPolicy and Procedures
SA-10System and Services AcquisitionDeveloper Configuration Management
SA-10(1)System and Services AcquisitionSoftware and Firmware Integrity Verification
SA-10(2)System and Services AcquisitionAlternative Configuration Management Processes
SA-10(3)System and Services AcquisitionHardware Integrity Verification
SA-10(4)System and Services AcquisitionTrusted Generation
SA-10(5)System and Services AcquisitionMapping Integrity for Version Control
SA-10(6)System and Services AcquisitionTrusted Distribution
SA-10(7)System and Services AcquisitionSecurity and Privacy Representatives

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.