What NIST SP 800-53 is, in one paragraph
NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations, is the catalog of controls federal systems are measured against. The current revision is Revision 5, first published in September 2020. NIST issues minor releases of the catalog, and the most recent at the time of writing is release 5.2.0 from August 2025. Revision 5 merged privacy controls into the main catalog instead of keeping them in a separate appendix, and it added a family for supply chain risk management.
The catalog is large, but it is not a checklist you must complete in full. Small teams succeed with it by understanding its structure, selecting the right baseline, and tailoring.
The 20 control families
Revision 5 organizes controls into 20 families, each with a two-letter identifier. Knowing the families helps you route work: some belong to engineering, some to operations, and many are organization-wide policy that a small vendor inherits from the agency or prime.
- Mostly engineering: Access Control (AC), Audit and Accountability (AU), Identification and Authentication (IA), System and Communications Protection (SC), System and Information Integrity (SI), Configuration Management (CM)
- Mostly operations: Contingency Planning (CP), Incident Response (IR), Maintenance (MA), Media Protection (MP)
- Mostly program and policy: Assessment, Authorization and Monitoring (CA), Planning (PL), Program Management (PM), Risk Assessment (RA), System and Services Acquisition (SA), Supply Chain Risk Management (SR)
- Mostly people and facilities: Awareness and Training (AT), Personnel Security (PS), Physical and Environmental Protection (PE)
- Privacy: PII Processing and Transparency (PT)
How an SP 800-53 control is structured
Each control has a base statement of what must be done, a discussion section that explains intent, a list of related controls, and often a set of control enhancements that add strength or specificity. Enhancements are numbered after the base control, so AC-2(1) is the first enhancement to AC-2, Account Management. Baselines specify which enhancements are required, and higher baselines generally require more of them.
Many controls include organization-defined parameters: blanks the organization fills in, such as a time period, a frequency or a list of roles. These are where vague documentation usually comes from. A statement that says sessions time out after an organization-defined period is not evidence. A statement that names the period, the setting and the place it is configured is.
Baselines: low, moderate and high
You do not choose controls from scratch. FIPS 199 has the agency rate the potential impact of a loss of confidentiality, integrity and availability as low, moderate or high. Because those three ratings can differ, FIPS 200 applies a high water mark: the system takes the highest of the three as its overall impact level.
That impact level selects one of the three security control baselines in NIST SP 800-53B: low, moderate or high. SP 800-53B also defines a privacy baseline that applies regardless of impact level. The baseline is your starting set. For most small teams supporting a civilian agency, the system categorization is set by the agency, so the first question to ask is simply: which baseline are we working to?
Tailoring: making the baseline fit your system
A baseline is a starting point, not the answer. SP 800-53B describes tailoring, which can include:
- Identifying and designating common controls that are provided once and inherited by many systems
- Applying scoping considerations, so controls that do not apply to your technology or environment are documented as such
- Selecting compensating controls when a baseline control cannot be implemented as written
- Assigning values to organization-defined parameters, such as how long a session can sit idle
- Supplementing the baseline with additional controls or enhancements when risk calls for it
Mapping controls without drowning in paperwork
The paperwork burden comes mainly from documenting the same fact many times. These habits keep it under control.
- Start with inheritance. List what the cloud provider, the agency and the prime already cover, and get it in writing. For a small team this often removes a large share of the physical, personnel and policy controls from your plate.
- Map controls to things you already do. A pull request review process supports configuration and change control. Centralized logging supports audit controls. Single sign-on supports identification and authentication. Write each fact once and reference it from every control it supports, so a change to the process means one update, not ten.
- Keep the evidence where the work happens. Pipeline logs, scan reports and ticket history are better evidence than a screenshot pasted into a document months later.
- Write implementation statements in plain, specific language: what component, what setting, who reviews it, how often.
- Track gaps honestly in the plan of action and milestones, with owners and dates.
- Review your statements whenever the architecture changes. A new service, data store or external connection can change which controls apply and how.
A practical first month for a small team
If you are new to 800-53 work, this sequence keeps effort where it matters.
- Week 1: confirm the baseline, get the agency or prime templates, and collect the responsibility matrix from your hosting provider.
- Week 2: mark every control in the baseline as inherited, shared, system-specific, or not applicable, with a one-line reason for each.
- Week 3: draft implementation statements for the engineering families first: AC, AU, IA, SC, SI and CM.
- Week 4: connect evidence sources, such as pipeline logs, scan output and change tickets, and open POA&M items for real gaps.
- After that: review the draft with the security officer, fix what they flag, and set a monthly time to keep the documentation current.
How SP 800-53 fits with the RMF and assessments
SP 800-53 is the catalog. The Risk Management Framework in SP 800-37 is the process that uses it: categorize, select, implement, assess, authorize and monitor. NIST SP 800-53A provides the matching assessment procedures, which tell you how an assessor will examine, interview and test each control. Reading the 800-53A procedures for your highest-risk controls is one of the fastest ways to learn what good evidence looks like.
Expect the catalog to keep moving. Minor releases such as 5.2.0 add or revise individual controls, and agencies adopt new releases on their own schedules. Note which release your documentation targets, and check with the security officer before updating references to a newer one.
If your organization handles controlled unclassified information on its own systems rather than a federal one, the requirements usually come from NIST SP 800-171 instead, whose current revision is Revision 3 from May 2024. Check your contract to see which applies.
Where Foundry Peak fits
Foundry Peak builds to NIST SP 800-53 Revision 5 controls on federal work and writes control implementation statements alongside the code. We do not claim certifications, and we do not sell compliance as a product. We help agencies and primes produce systems, and evidence, that hold up under assessment.
Sources
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
- NIST SP 800-53 Rev. 5 full text (PDF)
- NIST SP 800-53B, Control Baselines for Information Systems and Organizations
- FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
- NIST CSRC, About the RMF
- NIST SP 800-171 Rev. 3, Protecting CUI in Nonfederal Systems