// US Standards
NIST 800-53 Compliance Software
Comprehensive US federal security and privacy controls catalogue.
Framework at a glance
Short name
NIST 800-53
Version
—
Category
US Standards
Controls
130
What NIST 800-53 covers
130 controls across 76 domains — every one tracked, owned and evidenced in Cyber Horizon.
Identity & Access
6 controls- AC-1 Access Control Policy and Procedures
- AC-2 Account Management
- AC-3 Access Enforcement
- AC-17 Remote Access
- IA-2 Identification and Authentication (Users)
Identity
1 controls- AC-2(1) Account Management - Automated System Account Management
Data Flow
1 controls- AC-4 Information Flow Enforcement
Segregation
1 controls- AC-5 Separation of Duties
Authentication
2 controls- AC-7 Unsuccessful Logon Attempts
- IA-6 Authentication Feedback
Policy
14 controls- AC-8 System Use Notification
- AC-14 Permitted Actions Without Identification
- CP-1 Contingency Planning Policy
- IR-1 Incident Response Policy
- MA-1 Maintenance Policy
Session
3 controls- AC-11 Device Lock
- AC-12 Session Termination
- IA-11 Re-Authentication
Data Classification
1 controls- AC-16 Security and Privacy Attributes
Wireless
1 controls- AC-18 Wireless Access
Mobile
1 controls- AC-19 Access Control for Mobile Devices
Third-Party
2 controls- AC-20 Use of External Systems
- PS-7 External Personnel Security
Data Sharing
1 controls- AC-21 Information Sharing
Public Info
1 controls- AC-22 Publicly Accessible Content
Training
4 controls- AT-2 Literacy Training and Awareness
- AT-3 Role-Based Training
- CP-3 Contingency Training
- IR-2 Incident Response Training
Documentation
3 controls- AT-4 Training Records
- PL-7 Concept of Operations
- SA-5 System Documentation
Logging
5 controls- AU-2 Audit Events
- AU-4 Audit Log Storage Capacity
- AU-7 Audit Record Reduction and Report Generation
- AU-9 Protection of Audit Information
- AU-12 Audit Record Generation
Monitoring
2 controls- AU-5 Response to Audit Logging Process Failures
- CA-7 Continuous Monitoring
Time Sync
1 controls- AU-8 Time Stamps
Non-Repudiation
1 controls- AU-10 Non-repudiation
Retention
1 controls- AU-11 Audit Record Retention
POA&M
1 controls- CA-5 Plan of Action and Milestones
Governance
3 controls- CA-6 Authorization
- PL-9 Central Management
- SA-2 Allocation of Resources
Testing
2 controls- CA-8 Penetration Testing
- IR-3 Incident Response Testing
Network
1 controls- CA-9 Internal System Connections
System Hardening
2 controls- CM-2 Baseline Configuration
- CM-6 Configuration Settings
Change Management
2 controls- CM-3 Configuration Change Control
- CM-4 Impact Analysis
Access Control
3 controls- CM-5 Access Restrictions for Change
- MP-2 Media Access
- PE-3 Physical Access Control
Asset Inventory
1 controls- CM-8 System Component Inventory
Planning
3 controls- CM-9 Configuration Management Plan
- CP-2 Contingency Plan
- IR-8 Incident Response Plan
Licensing
1 controls- CM-10 Software Usage Restrictions
Software Control
1 controls- CM-11 User-Installed Software
Maintenance
1 controls- CP-5 Contingency Plan Update
Recovery
4 controls- CP-6 Alternate Storage Site
- CP-7 Alternate Processing Site
- CP-8 Telecommunications Services
- CP-11 Alternate Communications Protocols
Business Continuity
1 controls- CP-9 System Backup
Device Identity
1 controls- IA-3 Device Identification and Authentication
Identity Management
1 controls- IA-4 Identifier Management
Cryptography
1 controls- IA-7 Cryptographic Module Authentication
External Users
1 controls- IA-8 Identification and Authentication for Non-Organisational Users
Service Identity
1 controls- IA-9 Service Identification and Authentication
Adaptive Auth
1 controls- IA-10 Adaptive Authentication
Identity Verification
1 controls- IA-12 Identity Proofing
Operations
4 controls- IR-4 Incident Handling
- MA-2 Controlled Maintenance
- MA-4 Non-local Maintenance
- MA-6 Timely Maintenance
Support
1 controls- IR-7 Incident Response Assistance
Data Loss
1 controls- IR-9 Information Spillage Response
Tools
1 controls- MA-3 Maintenance Tools
Personnel
1 controls- MA-5 Maintenance Personnel
Classification
2 controls- MP-3 Media Marking
- RA-2 Security Categorisation
Physical
1 controls- MP-4 Media Storage
Data Management
1 controls- MP-6 Media Sanitisation
Cabling
1 controls- PE-4 Access Control for Transmission
Devices
1 controls- PE-5 Access Control for Output Devices
Visitors
1 controls- PE-7 Visitor Control
Records
1 controls- PE-8 Visitor Access Records
Infrastructure
2 controls- PE-9 Power Equipment and Cabling
- PE-12 Emergency Lighting
Emergency
1 controls- PE-10 Emergency Shutoff
Power
1 controls- PE-11 Emergency Power
Fire
1 controls- PE-13 Fire Protection
Environment
2 controls- PE-14 Environmental Controls
- PE-15 Water Damage Protection
Supply Chain
1 controls- PE-16 Delivery and Removal
Remote Work
1 controls- PE-17 Alternate Work Site
System Architecture
1 controls- PL-8 Security Architecture
Baseline
1 controls- PL-10 Baseline Selection
Risk
1 controls- PS-2 Position Risk Designation
HR
3 controls- PS-4 Personnel Termination
- PS-5 Personnel Transfer
- PS-8 Personnel Sanctions
Risk Management
1 controls- RA-4 Risk Assessment Update
Vulnerability Management
1 controls- RA-5 Vulnerability Scanning
Surveillance
1 controls- RA-6 Technical Surveillance Countermeasures
Risk Response
1 controls- RA-7 Risk Response
Criticality
1 controls- RA-9 Criticality Analysis
SDLC
2 controls- SA-3 System Development Life Cycle
- SA-15 Development Process, Standards, and Tools
Procurement
1 controls- SA-4 Acquisition Process
Architecture
2 controls- SA-8 Security and Privacy Engineering Principles
- SA-17 Developer Security and Privacy Architecture
CM
1 controls- SA-10 Developer Configuration Management
Development
1 controls- SA-11 Developer Testing
Network Security
1 controls- SC-8 Transmission Confidentiality and Integrity
Endpoint Security
1 controls- SI-3 Malicious Code Protection
How Cyber Horizon automates NIST 800-53
Every NIST 800-53 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is NIST 800-53?
Comprehensive US federal security and privacy controls catalogue.
How many controls does NIST 800-53 have?
NIST 800-53 has 130 controls in Cyber Horizon's catalogue, organised across 76 domains.
How does Cyber Horizon help with NIST 800-53?
Cyber Horizon maps NIST 800-53 into a shared control library alongside every other framework you run, so evidence collected once counts towards NIST 800-53 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More US Standards frameworks
See NIST 800-53 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of NIST 800-53 in Cyber Horizon.