Skip to content
Cyber Horizon
All frameworks

// US Standards

NIST 800-53 Compliance Software

Comprehensive US federal security and privacy controls catalogue.

Framework at a glance

Short name

NIST 800-53

Version

Category

US Standards

Controls

130

What NIST 800-53 covers

130 controls across 76 domains — every one tracked, owned and evidenced in Cyber Horizon.

Identity & Access

6 controls
  • AC-1 Access Control Policy and Procedures
  • AC-2 Account Management
  • AC-3 Access Enforcement
  • AC-17 Remote Access
  • IA-2 Identification and Authentication (Users)

Identity

1 controls
  • AC-2(1) Account Management - Automated System Account Management

Data Flow

1 controls
  • AC-4 Information Flow Enforcement

Segregation

1 controls
  • AC-5 Separation of Duties

Authentication

2 controls
  • AC-7 Unsuccessful Logon Attempts
  • IA-6 Authentication Feedback

Policy

14 controls
  • AC-8 System Use Notification
  • AC-14 Permitted Actions Without Identification
  • CP-1 Contingency Planning Policy
  • IR-1 Incident Response Policy
  • MA-1 Maintenance Policy

Session

3 controls
  • AC-11 Device Lock
  • AC-12 Session Termination
  • IA-11 Re-Authentication

Data Classification

1 controls
  • AC-16 Security and Privacy Attributes

Wireless

1 controls
  • AC-18 Wireless Access

Mobile

1 controls
  • AC-19 Access Control for Mobile Devices

Third-Party

2 controls
  • AC-20 Use of External Systems
  • PS-7 External Personnel Security

Data Sharing

1 controls
  • AC-21 Information Sharing

Public Info

1 controls
  • AC-22 Publicly Accessible Content

Training

4 controls
  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • CP-3 Contingency Training
  • IR-2 Incident Response Training

Documentation

3 controls
  • AT-4 Training Records
  • PL-7 Concept of Operations
  • SA-5 System Documentation

Logging

5 controls
  • AU-2 Audit Events
  • AU-4 Audit Log Storage Capacity
  • AU-7 Audit Record Reduction and Report Generation
  • AU-9 Protection of Audit Information
  • AU-12 Audit Record Generation

Monitoring

2 controls
  • AU-5 Response to Audit Logging Process Failures
  • CA-7 Continuous Monitoring

Time Sync

1 controls
  • AU-8 Time Stamps

Non-Repudiation

1 controls
  • AU-10 Non-repudiation

Retention

1 controls
  • AU-11 Audit Record Retention

POA&M

1 controls
  • CA-5 Plan of Action and Milestones

Governance

3 controls
  • CA-6 Authorization
  • PL-9 Central Management
  • SA-2 Allocation of Resources

Testing

2 controls
  • CA-8 Penetration Testing
  • IR-3 Incident Response Testing

Network

1 controls
  • CA-9 Internal System Connections

System Hardening

2 controls
  • CM-2 Baseline Configuration
  • CM-6 Configuration Settings

Change Management

2 controls
  • CM-3 Configuration Change Control
  • CM-4 Impact Analysis

Access Control

3 controls
  • CM-5 Access Restrictions for Change
  • MP-2 Media Access
  • PE-3 Physical Access Control

Asset Inventory

1 controls
  • CM-8 System Component Inventory

Planning

3 controls
  • CM-9 Configuration Management Plan
  • CP-2 Contingency Plan
  • IR-8 Incident Response Plan

Licensing

1 controls
  • CM-10 Software Usage Restrictions

Software Control

1 controls
  • CM-11 User-Installed Software

Maintenance

1 controls
  • CP-5 Contingency Plan Update

Recovery

4 controls
  • CP-6 Alternate Storage Site
  • CP-7 Alternate Processing Site
  • CP-8 Telecommunications Services
  • CP-11 Alternate Communications Protocols

Business Continuity

1 controls
  • CP-9 System Backup

Device Identity

1 controls
  • IA-3 Device Identification and Authentication

Identity Management

1 controls
  • IA-4 Identifier Management

Cryptography

1 controls
  • IA-7 Cryptographic Module Authentication

External Users

1 controls
  • IA-8 Identification and Authentication for Non-Organisational Users

Service Identity

1 controls
  • IA-9 Service Identification and Authentication

Adaptive Auth

1 controls
  • IA-10 Adaptive Authentication

Identity Verification

1 controls
  • IA-12 Identity Proofing

Operations

4 controls
  • IR-4 Incident Handling
  • MA-2 Controlled Maintenance
  • MA-4 Non-local Maintenance
  • MA-6 Timely Maintenance

Support

1 controls
  • IR-7 Incident Response Assistance

Data Loss

1 controls
  • IR-9 Information Spillage Response

Tools

1 controls
  • MA-3 Maintenance Tools

Personnel

1 controls
  • MA-5 Maintenance Personnel

Classification

2 controls
  • MP-3 Media Marking
  • RA-2 Security Categorisation

Physical

1 controls
  • MP-4 Media Storage

Data Management

1 controls
  • MP-6 Media Sanitisation

Cabling

1 controls
  • PE-4 Access Control for Transmission

Devices

1 controls
  • PE-5 Access Control for Output Devices

Visitors

1 controls
  • PE-7 Visitor Control

Records

1 controls
  • PE-8 Visitor Access Records

Infrastructure

2 controls
  • PE-9 Power Equipment and Cabling
  • PE-12 Emergency Lighting

Emergency

1 controls
  • PE-10 Emergency Shutoff

Power

1 controls
  • PE-11 Emergency Power

Fire

1 controls
  • PE-13 Fire Protection

Environment

2 controls
  • PE-14 Environmental Controls
  • PE-15 Water Damage Protection

Supply Chain

1 controls
  • PE-16 Delivery and Removal

Remote Work

1 controls
  • PE-17 Alternate Work Site

System Architecture

1 controls
  • PL-8 Security Architecture

Baseline

1 controls
  • PL-10 Baseline Selection

Risk

1 controls
  • PS-2 Position Risk Designation

HR

3 controls
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • PS-8 Personnel Sanctions

Risk Management

1 controls
  • RA-4 Risk Assessment Update

Vulnerability Management

1 controls
  • RA-5 Vulnerability Scanning

Surveillance

1 controls
  • RA-6 Technical Surveillance Countermeasures

Risk Response

1 controls
  • RA-7 Risk Response

Criticality

1 controls
  • RA-9 Criticality Analysis

SDLC

2 controls
  • SA-3 System Development Life Cycle
  • SA-15 Development Process, Standards, and Tools

Procurement

1 controls
  • SA-4 Acquisition Process

Architecture

2 controls
  • SA-8 Security and Privacy Engineering Principles
  • SA-17 Developer Security and Privacy Architecture

CM

1 controls
  • SA-10 Developer Configuration Management

Development

1 controls
  • SA-11 Developer Testing

Network Security

1 controls
  • SC-8 Transmission Confidentiality and Integrity

Endpoint Security

1 controls
  • SI-3 Malicious Code Protection

How Cyber Horizon automates NIST 800-53

Every NIST 800-53 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is NIST 800-53?

Comprehensive US federal security and privacy controls catalogue.

How many controls does NIST 800-53 have?

NIST 800-53 has 130 controls in Cyber Horizon's catalogue, organised across 76 domains.

How does Cyber Horizon help with NIST 800-53?

Cyber Horizon maps NIST 800-53 into a shared control library alongside every other framework you run, so evidence collected once counts towards NIST 800-53 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See NIST 800-53 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of NIST 800-53 in Cyber Horizon.