- Federal standard for categorizing information and systems by potential impact to confidentiality, integrity, and availability.
References and citations
- NIST source for the linked RMF stages and accountable risk-management decisions.
- NIST cautions that mappings and crosswalks do not establish equivalency and must be read in light of each publication's scope and intended use.
- NIST describes SP 800-53 as a flexible control catalog whose requirements can come from mission needs, laws, regulations, policies, standards, and guidance.
- Primary NIST publication for control structure, organization-defined parameters, implementation approaches, plans, and responsibilities.
- Current assessment publication page for assessment planning, procedures, findings, and Release 5.2.0 updates.
- NIST source for the scope of determination statements and the satisfied or other than satisfied findings produced by an assessment.
- Current NIST source for customizable assessment procedures and Release 5.2.0 assessment updates.
- NIST source for the three federal security baselines, the privacy baseline, and baseline tailoring.