Control Families in Special Publications 800-171, 800-53 r5, 800-53B, and FIPS PUB 200

As the “minimum” security requirement for Federal Information and Information Systems, anyone who operates within compliance requires a general understanding of the FIPS PUB 200 control families. These are the “Minimum Requirements.” In comparison to the minimum requirements of FIPS 200, compliance professionals should compare these high-level control definitions with their evolution to [SP 800-53 r5] catalog, shown in Table 5 as the hyperlinked control family names that launch to their NIST online repository. Since 79 of the 110 controls are derived from [SP 800-53B Moderate], it is helpful to understand the full context of the NIST 171 requirement at its origin and with its relationships to other controls and reference materials.

The following 14 items are represented in NIST 800-171 control requirements. NIST continuously evolves its frameworks and related resources, so it is essential to use the online delivery mechanism when establishing your program. For example, as of April 2022, the [SP 800-53B moderate] is expected to modify again, adopting around 18 additional controls from the SP 800-53 r5 catalog. [xxx] Families introduced or significantly increased within Revision 5 of SP 800-53 include PM - PROGRAM MANAGEMENT, PT - PERSONALLY IDENTIFIABLE INFORMATION PROCESSING, AND TRANSPARENCY, and SR - SUPPLY CHAIN RISK MANAGEMENT.

AC – 3.1 ACCESS CONTROL
AT – 3.2 AWARENESS AND TRAINING
AU – 3.3 AUDIT AND ACCOUNTABILITY
CM – 3.4 CONFIGURATION MANAGEMENT
IA – 3.5 IDENTIFICATION AND AUTHENTICATION
IR – 3.6 INCIDENT RESPONSE
MA – 3.7 MAINTENANCE
MP – 3.8 MEDIA PROTECTION
PS – 3.9 PERSONNEL SECURITY
PE – 3.10 PHYSICAL AND ENVIRONMENTAL PROTECTION
RA – 3.11 RISK ASSESSMENT
CA – 3.12 SECURITY ASSESSMENT
SC – 3.13 SYSTEM AND COMMUNICATIONS PROTECTION
SI – 3.14 System and Information Integrity

Table 3 Control Families in NIST SP 800-171

FIPS PUB 200 Minimum Security Requirements

The following items are the FIPS 200 Control families are the Minimum-Security Requirements. There is an added note to indicate when the item is not called out as part of the NIST 171 CUI-based control requirements. <Read more: FIPS PUB 200 Minimum Security Requirements

800-53r5 Control Families

The following grid represents hyperlinked Control Families used for the NIST SP 800-53 Catalog and leveraged for the NIST SP 800-53B and NIST SP 800-171A assessment methodologies. Control Families CP Contingency Planning, PL Planning, PM Program Management, PT Personally Identifiable Information Processing and Transparency, SA System and Service Acquisition, and SR Supply Chain Risk Management are not directly mapped to the NIST 171 Assessment Methodology. It is recommended that anyone working with NIST Compliance familiarize themselves with all control families.

Table 4 Control Families in NIST 800-171 series and NIST 800-53 Series linked to CSRC NIST 800-53

Main Menu