NIST 800-53 Controls
NIST 800-53 includes a set of controls designed to enhance the resilience and security of federal information systems. These controls encompass operational, technical, and management standards that information systems utilize to uphold privacy and security measures.

These controls are categorised into three classes, which reflect the potential impact of each risk. These broad classes are:
- High impact
- Medium impact
- Low impact
{{snapshot}}
NIST 800-53 controls in brief
- Three impact classes: controls are categorised into high, medium and low impact, reflecting the potential impact of each risk.
- 20 families, 322 controls: NIST 800-53 includes 20 control families containing 322 controls in total.
- Choose what applies: each family has its own controls, which may or may not apply, so organisations select those most relevant to them.
{{/snapshot}}
How many NIST 800-53 controls are there?
The NIST 800-53 includes 20 different control families within its framework. Across the entire range of NIST 800-53 control families, there are 322 controls. Each NIST 800-53 control family has its own controls, which may or may not be applicable to any given organisation. Therefore, organisations using NIST 800-53 can choose the controls that are most applicable to them.
{{snapshot}}
Where the controls concentrate
- Largest family: System and Communications Protection (SC) is the biggest, with 51 controls.
- Programme Management: PM follows with 32 controls covering risk management, insider threats and scaling architecture.
- Access Control: AC has 25 controls spanning account management, separation of duties and least privilege.
{{/snapshot}}
NIST 800-53 control families
| Code | Control family | Controls | Focus |
|---|---|---|---|
| AC | Access Control | 25 | Policies and procedures, account management, separation of duties and least privilege |
| AT | Awareness and Training | 6 | Security awareness training for all employees; technical training for privileged users |
| AU | Audit and Accountability | 16 | Auditing and retention of records; analysis, review and reporting |
| CA | Assessment, Authorisation and Monitoring | 9 | Penetration testing; monitoring of network connections and external systems |
| CM | Configuration Management | 14 | Configuration change, data action mapping and software policies |
| CP | Contingency Planning | 13 | Business continuity strategies; alternative data processing and storage |
| IA | Identification and Authentication | 12 | Credential management, authentication policies and systems for users, devices and services |
| IR | Incident Response | 10 | Incident response education and training; monitoring and reporting processes |
| MA | Maintenance | 7 | Ongoing maintenance of systems, personnel and tools |
| MP | Media Protection | 8 | Securing the access, use, storage and transportation of media |
| PE | Physical and Environmental Protection | 23 | Protection against physical risk and damage; emergency power; physical access in an incident |
| PL | Planning | 11 | Security architecture, impact assessments, activity planning and rules of behaviour |
| PM | Programme Management | 32 | Risk management and insider threat strategies; scaling architecture |
| PS | Personnel Security | 9 | Screening, transferring and terminating personnel; position risk designation |
| PT | Personally Identifiable Information Processing and Transparency | 8 | Privacy notices, achieving consent and processing personally identifiable information |
| RA | Risk Assessment | 10 | Vulnerability scanning, risk assessments and ongoing privacy impact |
| SA | System and Services Acquisition | 23 | Acquisition processes, resource allocation and system development lifecycle |
| SC | System and Communications Protection | 51 | Partition of applications, securing passwords and cryptographic key management |
| SI | System and Information Integrity | 23 | System monitoring, alerting, spam protection and flaw remediation |
| SR | Supply Chain Risk Management | 12 | Supplier assessments and reviews, risk management plans, notification agreements and inspection of systems or components |
{{snapshot}}
Hicomply’s take
322 controls sounds daunting, but you rarely implement them all — scope to your impact level and the families that fit your systems, establish baseline controls and then monitor performance continuously rather than reproving everything at audit time. Much of this overlaps with ISO 27001 Annex A, so map once and reuse the evidence.
{{/snapshot}}
Implementing NIST 800-53 Controls
Between 20 families and over 300 controls, implementing the necessary control families may seem daunting. However, the Hicomply platform enables organisations to prioritise activities with greater accuracy and visibility. Easily establish your baseline controls and monitor control performance to ensure continued compliance.
Learn more about the NIST 800-53 framework in our NIST 800-53 Information Hub.
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

.avif)




















