Standard

    NIST 800-53

    NIST Special Publication 800-53: Security and Privacy Controls

    National Institute of Standards and Technology (NIST), a non-regulatory US federal agency

    Why It Exists

    Originally built to secure US federal information systems under FISMA. It has since become the reference control catalog that other frameworks, including FedRAMP, build on, because it's exhaustive, regularly maintained, and free to use.

    Who It's For

    Directly mandatory for US federal agencies and their contractors. Widely adopted as a control-catalog baseline well beyond government, especially by organizations that need to demonstrate rigor to US government customers or regulators.

    Current Status

    Current is Revision 5, originally published September 23, 2020, with an updated release (5.2.0) on August 27, 2025. Rev 5 catalogs 1,196 controls across 20 control families, including two added in this revision: Personally Identifiable Information Processing and Transparency, and Supply Chain Risk Management.

    NIST SP 800-53 Rev. 5

    Frequently Asked Questions

    KloudSec, built by the team behind Toc Consulting

    See NIST 800-53 checked automatically, continuously

    What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.

    Try KloudSec free