All frameworks
nist-80053-rev5version Rev. 5

NIST SP 800-53 Rev. 5

Official source

1,196 controls.

ReferenceFamilyTitle
SA-8(13)System and Services AcquisitionMinimized Security Elements
SA-8(14)System and Services AcquisitionLeast Privilege
SA-8(15)System and Services AcquisitionPredicate Permission
SA-8(16)System and Services AcquisitionSelf-reliant Trustworthiness
SA-8(17)System and Services AcquisitionSecure Distributed Composition
SA-8(18)System and Services AcquisitionTrusted Communications Channels
SA-8(19)System and Services AcquisitionContinuous Protection
SA-8(2)System and Services AcquisitionLeast Common Mechanism
SA-8(20)System and Services AcquisitionSecure Metadata Management
SA-8(21)System and Services AcquisitionSelf-analysis
SA-8(22)System and Services AcquisitionAccountability and Traceability
SA-8(23)System and Services AcquisitionSecure Defaults
SA-8(24)System and Services AcquisitionSecure Failure and Recovery
SA-8(25)System and Services AcquisitionEconomic Security
SA-8(26)System and Services AcquisitionPerformance Security
SA-8(27)System and Services AcquisitionHuman Factored Security
SA-8(28)System and Services AcquisitionAcceptable Security
SA-8(29)System and Services AcquisitionRepeatable and Documented Procedures
SA-8(3)System and Services AcquisitionModularity and Layering
SA-8(30)System and Services AcquisitionProcedural Rigor
SA-8(31)System and Services AcquisitionSecure System Modification
SA-8(32)System and Services AcquisitionSufficient Documentation
SA-8(33)System and Services AcquisitionMinimization
SA-8(4)System and Services AcquisitionPartially Ordered Dependencies
SA-8(5)System and Services AcquisitionEfficiently Mediated Access
SA-8(6)System and Services AcquisitionMinimized Sharing
SA-8(7)System and Services AcquisitionReduced Complexity
SA-8(8)System and Services AcquisitionSecure Evolvability
SA-8(9)System and Services AcquisitionTrusted Components
SA-9System and Services AcquisitionExternal System Services
SA-9(1)System and Services AcquisitionRisk Assessments and Organizational Approvals
SA-9(2)System and Services AcquisitionIdentification of Functions, Ports, Protocols, and Services
SA-9(3)System and Services AcquisitionEstablish and Maintain Trust Relationship with Providers
SA-9(4)System and Services AcquisitionConsistent Interests of Consumers and Providers
SA-9(5)System and Services AcquisitionProcessing, Storage, and Service Location
SA-9(6)System and Services AcquisitionOrganization-controlled Cryptographic Keys
SA-9(7)System and Services AcquisitionOrganization-controlled Integrity Checking
SA-9(8)System and Services AcquisitionProcessing and Storage Location — U.S. Jurisdiction
SC-1System and Communications ProtectionPolicy and Procedures
SC-10System and Communications ProtectionNetwork Disconnect
SC-11System and Communications ProtectionTrusted Path
SC-11(1)System and Communications ProtectionIrrefutable Communications Path
SC-12System and Communications ProtectionCryptographic Key Establishment and Management
SC-12(1)System and Communications ProtectionAvailability
SC-12(2)System and Communications ProtectionSymmetric Keys
SC-12(3)System and Communications ProtectionAsymmetric Keys
SC-12(4)System and Communications ProtectionPKI Certificates
SC-12(5)System and Communications ProtectionPKI Certificates / Hardware Tokens
SC-12(6)System and Communications ProtectionPhysical Control of Keys
SC-13System and Communications ProtectionCryptographic Protection

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.