The Fundamentals of NIST 800-53
Source Matters
No matter what you want to understand about NIST, begin at the COMPUTER SECURITY RESOURCE CENTER. While the Downloads and Notification mechanisms for the SP 800-53 provide the current and complete version-controlled content CSRC serves related information used for scoping, the overlays, all referenced regulatory requirements, related standards, and links to everything necessary in providing a "package" of materials & evidence used for any type of conformity assessment. NIST Special Publications SP 800-53 rev 5 and SP 800-53B (FedRamp) contain additional background, scoping, and implementation guidance. Relative to the growing demands and complexities of the most recent changes to the law and NIST guidance, the CSRC NIST SP 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations is the one place where all associated reference content is consistently and continuously updated and mapped. The CSRC interface includes the materials necessary to fully implement control processes as determined by their type of conformity, risk rating (baseline), and technical context.
The 800-53 is part of the six steps in the Risk Management Framework, step two, selecting controls. The process to evaluate the enterprise risk and categorize systems always precedes the selection of controls. Historically, the intended use for NIST SP 800-53 was exclusively Federal Systems, but today this framework is "the catalog" and assessment models "derive" their controls from it. The catalog serves as an index to determine which are the other necessary implementation and assessment standards. These other requirements may appear as related SP, IR, FIPS, or government and US regulations. As part two of the RMF wheel, note that step four, Assessment, uses 800-53B, followed by step five requiring monitoring frameworks such as the 800-137 and the "ConMon" which is associated to the FedRAMP PMO aspects of the 800-53B. Assessment cycles, be they annual or triennial return each year to the FIPS 199 for risk impact analysis and the 800-60 for the proper categorization of systems. 800-53 is part two of the continuous cycle of Government Regulatory Compliance.


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics