All frameworks
nist-80053-rev5version Rev. 5

NIST SP 800-53 Rev. 5

Official source

1,196 controls.

ReferenceFamilyTitle
AC-4(17)Access ControlDomain Authentication
AC-4(18)Access ControlSecurity Attribute Binding
AC-4(19)Access ControlValidation of Metadata
AC-4(2)Access ControlProcessing Domains
AC-4(20)Access ControlApproved Solutions
AC-4(21)Access ControlPhysical or Logical Separation of Information Flows
AC-4(22)Access ControlAccess Only
AC-4(23)Access ControlModify Non-releasable Information
AC-4(24)Access ControlInternal Normalized Format
AC-4(25)Access ControlData Sanitization
AC-4(26)Access ControlAudit Filtering Actions
AC-4(27)Access ControlRedundant/Independent Filtering Mechanisms
AC-4(28)Access ControlLinear Filter Pipelines
AC-4(29)Access ControlFilter Orchestration Engines
AC-4(3)Access ControlDynamic Information Flow Control
AC-4(30)Access ControlFilter Mechanisms Using Multiple Processes
AC-4(31)Access ControlFailed Content Transfer Prevention
AC-4(32)Access ControlProcess Requirements for Information Transfer
AC-4(4)Access ControlFlow Control of Encrypted Information
AC-4(5)Access ControlEmbedded Data Types
AC-4(6)Access ControlMetadata
AC-4(7)Access ControlOne-way Flow Mechanisms
AC-4(8)Access ControlSecurity and Privacy Policy Filters
AC-4(9)Access ControlHuman Reviews
AC-5Access ControlSeparation of Duties
AC-6Access ControlLeast Privilege
AC-6(1)Access ControlAuthorize Access to Security Functions
AC-6(10)Access ControlProhibit Non-privileged Users from Executing Privileged Functions
AC-6(2)Access ControlNon-privileged Access for Nonsecurity Functions
AC-6(3)Access ControlNetwork Access to Privileged Commands
AC-6(4)Access ControlSeparate Processing Domains
AC-6(5)Access ControlPrivileged Accounts
AC-6(6)Access ControlPrivileged Access by Non-organizational Users
AC-6(7)Access ControlReview of User Privileges
AC-6(8)Access ControlPrivilege Levels for Code Execution
AC-6(9)Access ControlLog Use of Privileged Functions
AC-7Access ControlUnsuccessful Logon Attempts
AC-7(1)Access ControlAutomatic Account Lock
AC-7(2)Access ControlPurge or Wipe Mobile Device
AC-7(3)Access ControlBiometric Attempt Limiting
AC-7(4)Access ControlUse of Alternate Authentication Factor
AC-8Access ControlSystem Use Notification
AC-9Access ControlPrevious Logon Notification
AC-9(1)Access ControlUnsuccessful Logons
AC-9(2)Access ControlSuccessful and Unsuccessful Logons
AC-9(3)Access ControlNotification of Account Changes
AC-9(4)Access ControlAdditional Logon Information
AT-1Awareness and TrainingPolicy and Procedures
AT-2Awareness and TrainingLiteracy Training and Awareness
AT-2(1)Awareness and TrainingPractical Exercises

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.