All frameworks
nist-80053-rev5version Rev. 5

NIST SP 800-53 Rev. 5

Official source

1,196 controls.

ReferenceFamilyTitle
AC-2(12)Access ControlAccount Monitoring for Atypical Usage
AC-2(13)Access ControlDisable Accounts for High-risk Individuals
AC-2(2)Access ControlAutomated Temporary and Emergency Account Management
AC-2(3)Access ControlDisable Accounts
AC-2(4)Access ControlAutomated Audit Actions
AC-2(5)Access ControlInactivity Logout
AC-2(6)Access ControlDynamic Privilege Management
AC-2(7)Access ControlPrivileged User Accounts
AC-2(8)Access ControlDynamic Account Management
AC-2(9)Access ControlRestrictions on Use of Shared and Group Accounts
AC-20Access ControlUse of External Systems
AC-20(1)Access ControlLimits on Authorized Use
AC-20(2)Access ControlPortable Storage Devices — Restricted Use
AC-20(3)Access ControlNon-organizationally Owned Systems — Restricted Use
AC-20(4)Access ControlNetwork Accessible Storage Devices — Prohibited Use
AC-20(5)Access ControlPortable Storage Devices — Prohibited Use
AC-21Access ControlInformation Sharing
AC-21(1)Access ControlAutomated Decision Support
AC-21(2)Access ControlInformation Search and Retrieval
AC-22Access ControlPublicly Accessible Content
AC-23Access ControlData Mining Protection
AC-24Access ControlAccess Control Decisions
AC-24(1)Access ControlTransmit Access Authorization Information
AC-24(2)Access ControlNo User or Process Identity
AC-25Access ControlReference Monitor
AC-3Access ControlAccess Enforcement
AC-3(1)Access ControlRestricted Access to Privileged Functions
AC-3(10)Access ControlAudited Override of Access Control Mechanisms
AC-3(11)Access ControlRestrict Access to Specific Information Types
AC-3(12)Access ControlAssert and Enforce Application Access
AC-3(13)Access ControlAttribute-based Access Control
AC-3(14)Access ControlIndividual Access
AC-3(15)Access ControlDiscretionary and Mandatory Access Control
AC-3(2)Access ControlDual Authorization
AC-3(3)Access ControlMandatory Access Control
AC-3(4)Access ControlDiscretionary Access Control
AC-3(5)Access ControlSecurity-relevant Information
AC-3(6)Access ControlProtection of User and System Information
AC-3(7)Access ControlRole-based Access Control
AC-3(8)Access ControlRevocation of Access Authorizations
AC-3(9)Access ControlControlled Release
AC-4Access ControlInformation Flow Enforcement
AC-4(1)Access ControlObject Security and Privacy Attributes
AC-4(10)Access ControlEnable and Disable Security or Privacy Policy Filters
AC-4(11)Access ControlConfiguration of Security or Privacy Policy Filters
AC-4(12)Access ControlData Type Identifiers
AC-4(13)Access ControlDecomposition into Policy-relevant Subcomponents
AC-4(14)Access ControlSecurity or Privacy Policy Filter Constraints
AC-4(15)Access ControlDetection of Unsanctioned Information
AC-4(16)Access ControlInformation Transfers on Interconnected Systems

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.