All frameworks
nist-80053-rev5version Rev. 5

NIST SP 800-53 Rev. 5

Official source

1,196 controls.

ReferenceFamilyTitle
SC-45(2)System and Communications ProtectionSecondary Authoritative Time Source
SC-46System and Communications ProtectionCross Domain Policy Enforcement
SC-47System and Communications ProtectionAlternate Communications Paths
SC-48System and Communications ProtectionSensor Relocation
SC-48(1)System and Communications ProtectionDynamic Relocation of Sensors or Monitoring Capabilities
SC-49System and Communications ProtectionHardware-enforced Separation and Policy Enforcement
SC-5System and Communications ProtectionDenial-of-service Protection
SC-5(1)System and Communications ProtectionRestrict Ability to Attack Other Systems
SC-5(2)System and Communications ProtectionCapacity, Bandwidth, and Redundancy
SC-5(3)System and Communications ProtectionDetection and Monitoring
SC-50System and Communications ProtectionSoftware-enforced Separation and Policy Enforcement
SC-51System and Communications ProtectionHardware-based Protection
SC-6System and Communications ProtectionResource Availability
SC-7System and Communications ProtectionBoundary Protection
SC-7(1)System and Communications ProtectionPhysically Separated Subnetworks
SC-7(10)System and Communications ProtectionPrevent Exfiltration
SC-7(11)System and Communications ProtectionRestrict Incoming Communications Traffic
SC-7(12)System and Communications ProtectionHost-based Protection
SC-7(13)System and Communications ProtectionIsolation of Security Tools, Mechanisms, and Support Components
SC-7(14)System and Communications ProtectionProtect Against Unauthorized Physical Connections
SC-7(15)System and Communications ProtectionNetworked Privileged Accesses
SC-7(16)System and Communications ProtectionPrevent Discovery of System Components
SC-7(17)System and Communications ProtectionAutomated Enforcement of Protocol Formats
SC-7(18)System and Communications ProtectionFail Secure
SC-7(19)System and Communications ProtectionBlock Communication from Non-organizationally Configured Hosts
SC-7(2)System and Communications ProtectionPublic Access
SC-7(20)System and Communications ProtectionDynamic Isolation and Segregation
SC-7(21)System and Communications ProtectionIsolation of System Components
SC-7(22)System and Communications ProtectionSeparate Subnets for Connecting to Different Security Domains
SC-7(23)System and Communications ProtectionDisable Sender Feedback on Protocol Validation Failure
SC-7(24)System and Communications ProtectionPersonally Identifiable Information
SC-7(25)System and Communications ProtectionUnclassified National Security System Connections
SC-7(26)System and Communications ProtectionClassified National Security System Connections
SC-7(27)System and Communications ProtectionUnclassified Non-national Security System Connections
SC-7(28)System and Communications ProtectionConnections to Public Networks
SC-7(29)System and Communications ProtectionSeparate Subnets to Isolate Functions
SC-7(3)System and Communications ProtectionAccess Points
SC-7(4)System and Communications ProtectionExternal Telecommunications Services
SC-7(5)System and Communications ProtectionDeny by Default — Allow by Exception
SC-7(6)System and Communications ProtectionResponse to Recognized Failures
SC-7(7)System and Communications ProtectionSplit Tunneling for Remote Devices
SC-7(8)System and Communications ProtectionRoute Traffic to Authenticated Proxy Servers
SC-7(9)System and Communications ProtectionRestrict Threatening Outgoing Communications Traffic
SC-8System and Communications ProtectionTransmission Confidentiality and Integrity
SC-8(1)System and Communications ProtectionCryptographic Protection
SC-8(2)System and Communications ProtectionPre- and Post-transmission Handling
SC-8(3)System and Communications ProtectionCryptographic Protection for Message Externals
SC-8(4)System and Communications ProtectionConceal or Randomize Communications
SC-8(5)System and Communications ProtectionProtected Distribution System
SC-9System and Communications ProtectionTransmission Confidentiality

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.