April 18, 2024

NIST 800-53 Controls

NIST 800-53 includes a set of controls designed to enhance the resilience and security of federal information systems. These controls encompass operational, technical, and management standards that information systems utilize to uphold privacy and security measures.

By
Full name
Share this post
https://www.hicomply.com/en-us/hub/nist-800-53-controls
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

These controls are categorised into three classes, which reflect the potential impact of each risk. These broad classes are:

  • High impact
  • Medium impact
  • Low impact

{{snapshot}}

NIST 800-53 controls in brief

  • Three impact classes: controls are categorised into high, medium and low impact, reflecting the potential impact of each risk.
  • 20 families, 322 controls: NIST 800-53 includes 20 control families containing 322 controls in total.
  • Choose what applies: each family has its own controls, which may or may not apply, so organisations select those most relevant to them.

{{/snapshot}}

How many NIST 800-53 controls are there?

The NIST 800-53 includes 20 different control families within its framework. Across the entire range of NIST 800-53 control families, there are 322 controls. Each NIST 800-53 control family has its own controls, which may or may not be applicable to any given organisation. Therefore, organisations using NIST 800-53 can choose the controls that are most applicable to them.

{{snapshot}}

Where the controls concentrate

  • Largest family: System and Communications Protection (SC) is the biggest, with 51 controls.
  • Programme Management: PM follows with 32 controls covering risk management, insider threats and scaling architecture.
  • Access Control: AC has 25 controls spanning account management, separation of duties and least privilege.

{{/snapshot}}

NIST 800-53 control families

CodeControl familyControlsFocus
ACAccess Control25Policies and procedures, account management, separation of duties and least privilege
ATAwareness and Training6Security awareness training for all employees; technical training for privileged users
AUAudit and Accountability16Auditing and retention of records; analysis, review and reporting
CAAssessment, Authorisation and Monitoring9Penetration testing; monitoring of network connections and external systems
CMConfiguration Management14Configuration change, data action mapping and software policies
CPContingency Planning13Business continuity strategies; alternative data processing and storage
IAIdentification and Authentication12Credential management, authentication policies and systems for users, devices and services
IRIncident Response10Incident response education and training; monitoring and reporting processes
MAMaintenance7Ongoing maintenance of systems, personnel and tools
MPMedia Protection8Securing the access, use, storage and transportation of media
PEPhysical and Environmental Protection23Protection against physical risk and damage; emergency power; physical access in an incident
PLPlanning11Security architecture, impact assessments, activity planning and rules of behaviour
PMProgramme Management32Risk management and insider threat strategies; scaling architecture
PSPersonnel Security9Screening, transferring and terminating personnel; position risk designation
PTPersonally Identifiable Information Processing and Transparency8Privacy notices, achieving consent and processing personally identifiable information
RARisk Assessment10Vulnerability scanning, risk assessments and ongoing privacy impact
SASystem and Services Acquisition23Acquisition processes, resource allocation and system development lifecycle
SCSystem and Communications Protection51Partition of applications, securing passwords and cryptographic key management
SISystem and Information Integrity23System monitoring, alerting, spam protection and flaw remediation
SRSupply Chain Risk Management12Supplier assessments and reviews, risk management plans, notification agreements and inspection of systems or components

{{snapshot}}

Hicomply’s take

322 controls sounds daunting, but you rarely implement them all — scope to your impact level and the families that fit your systems, establish baseline controls and then monitor performance continuously rather than reproving everything at audit time. Much of this overlaps with ISO 27001 Annex A, so map once and reuse the evidence.

{{/snapshot}}

Implementing NIST 800-53 Controls

Between 20 families and over 300 controls, implementing the necessary control families may seem daunting. However, the Hicomply platform enables organisations to prioritise activities with greater accuracy and visibility. Easily establish your baseline controls and monitor control performance to ensure continued compliance.

Learn more about the NIST 800-53 framework in our NIST 800-53 Information Hub.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status. Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Preparing for Your Audit
Computer Software
IT and Services
Legal Services
Professional Services
Growth