NIST Artifact GuideGLOBALNIST SP 800-53 Rev. 5

NIST SP 800-53 Rev. 5 Control Families Explained

Use the 20 families to navigate the Rev. 5 catalog, then make selection, parameters, ownership, implementation, and assessment decisions at control level.

Family membership groups related controls. It does not set priority, make every control applicable, or prove that a family is implemented.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Revision 5 organizes base controls and their enhancements into 20 families: Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Assessment, Authorization, and Monitoring (CA), Configuration Management (CM), Contingency Planning (CP), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Physical and Environmental Protection (PE), Planning (PL), Program Management (PM), Personnel Security (PS), PII Processing and Transparency (PT), Risk Assessment (RA), System and Services Acquisition (SA), System and Communications Protection (SC), System and Information Integrity (SI), and Supply Chain Risk Management (SR). Seventeen align with FIPS 200 minimum-security-requirement areas; PM, PT, and SR add enterprise, privacy, and supply-chain groupings. A is an organizing label, not a ready-made scope or proof that every control in the family applies.

Section 1

How to read the catalog structure

Each control has a family code and number, a title, a control statement, discussion, related controls, references, and where applicable enhancements and . The control statement is the requirement to implement when selected; the discussion explains intent and possible approaches but does not replace the statement.

A augments its base control and cannot stand alone. Family, control, and enhancement numbering does not create a maturity scale or implementation order. Start from the approved and tailored control set, not from an assumption that every family or control applies.

  • Selection record: control ID, title, base-control dependency, selected enhancements, baseline or other source, and tailoring decision.
  • Specification record: completed parameters, system boundary, implementation level, responsible provider, dependencies, and intended outcome.
  • Assessment record: applicable SP 800-53A objective, selected methods and objects, evidence, determination findings, and open remediation.
Section 2

What each family covers

The summaries below are navigation aids, not substitutes for the current control statements. A selected control may address security, privacy, or both, and related controls can cross family boundaries.

  • AC - Access Control: account and access enforcement, information flow, separation of duties, remote and mobile access, and least privilege.
  • AT - Awareness and Training: security and privacy literacy, role-based training, insider-threat awareness, and training records.
  • AU - Audit and Accountability: event logging, audit-record content and protection, review and analysis, retention, time synchronization, and non-repudiation.
  • CA - Assessment, Authorization, and Monitoring: control assessments, POA&M, authorization, system connections, penetration testing, and continuous monitoring.
  • CM - Configuration Management: baselines, change control, configuration settings, least functionality, inventories, software restrictions, and information location.
  • CP - Contingency Planning: contingency plans, alternate sites, backup, recovery, reconstitution, and continuity testing.
  • IA - Identification and Authentication: identity proofing, authenticators, multifactor authentication, device identification, and re-authentication.
  • IR - Incident Response: preparation, training, testing, handling, monitoring, reporting, assistance, and response plans.
  • MA - Maintenance: controlled maintenance, tools, remote maintenance, maintenance personnel, and timely maintenance.
  • MP - Media Protection: media access, marking, storage, transport, sanitization, and use.
  • PE - Physical and Environmental Protection: physical access, monitoring, power, fire, water, temperature, alternate work sites, and component location.
  • PL - Planning: system security and privacy plans, rules of behavior, architecture, baseline selection, and baseline tailoring.
  • PM - Program Management: organization-level security, privacy, risk, resources, architecture, measures, testing, and program plans independent of one system.
  • PS - Personnel Security: position risk, screening, termination, transfer, access agreements, external personnel, and sanctions.
  • PT - PII Processing and Transparency: authority and purpose, consent, privacy notices, processing rules, individual access, correction, and complaint management.
  • RA - Risk Assessment: categorization, risk and supply-chain risk assessment, vulnerability monitoring, risk response, and criticality analysis.
  • SA - System and Services Acquisition: acquisition requirements, development lifecycle, external services, developer practices, system documentation, and software use.
  • SC - System and Communications Protection: boundary protection, separation, cryptography, transmission and storage protections, denial-of-service protection, and secure name or session services.
  • SI - System and Information Integrity: flaw remediation, malicious-code protection, monitoring, alerts, integrity checks, spam protection, error handling, and information management.
  • SR - Supply Chain Risk Management: supply-chain plans, supplier controls, provenance, tamper resistance, component authenticity, notification, and disposal.
Section 3

Assign responsibility at control level

A single family can contain organization-level, common, hybrid, and system-specific implementations owned by different roles. For example, enterprise identity services may implement parts of IA controls as common controls while the system owner configures and monitors the system-specific portions.

For a hybrid control, state the exact division. NIST assigns the common-control provider responsibility for the common part and the system owner responsibility for the system-specific part. Unclear ownership creates a gap even when both teams report the same control as covered.

  • Name the accountable system owner, implementation owner, common-control provider, assessor, and risk decision-maker as applicable.
  • Describe common, hybrid, system-specific, and program-management portions instead of assigning an entire family to one team.
  • Record provider version, parameters, service scope, consumer conditions, assessment status, exceptions, and change notifications for inherited controls.
  • Keep control ownership current when services, organizations, boundaries, or contracts change.
Section 4

Assess controls without hiding gaps in family totals

SP 800-53A decomposes control text into assessment objectives and determination statements. Assessors apply selected examine, interview, and test methods to the necessary objects, with depth and coverage set by assurance needs and risk. Record each determination as satisfied or other than satisfied.

A family total can help prioritize work, but it can also hide a failed enhancement, undefined parameter, stale inherited assessment, or untested part of a hybrid control. Keep the underlying determination-level record and surface material exceptions.

  • Do not average unselected controls into an implementation percentage; report the denominator and selection basis.
  • Do not mark a base control complete when a selected enhancement or parameter remains unresolved.
  • Do not treat missing evidence as satisfied; SP 800-53A allows an other-than-satisfied finding when sufficient information cannot be obtained.
  • Do not roll up inherited controls without the provider's current scope, result, and consumer conditions.
Section 5

Control-family working method

Start with the final selected and tailored set. Group controls by family for navigation, then complete control-specific parameters, ownership, implementation narratives, inheritance, evidence, and assessment objectives. Aggregate only after the detailed records are current.

Use the current Rev. 5 data. NIST Release 5.2.0, issued August 27, 2025, added SA-15(13), SA-24, and SI-02(07), revised SI-07(12), and updated selected discussions and related-control references. It did not create new families.

  • Step 1 | Select | Import the approved controls and enhancements with their baseline, overlay, or requirement source.
  • Step 2 | Specify | Complete , scope, implementation level, and dependencies.
  • Step 3 | Assign | Name providers, system owners, implementers, assessors, and decision-makers at control or control-part level.
  • Step 4 | Assess | Link evidence and SP 800-53A findings to each selected control, enhancement, and hybrid portion.
  • Step 5 | Report | Roll up by family while exposing material gaps, stale evidence, inherited conditions, and remediation.
Primary sources

References and citations

Related guides

Explore more topics

How do NIST SP 800-53A assessment methods work?
Use SP 800-53A examine, interview, and test methods against specific determination statements, with documented objects, depth, coverage, and findings.
How do teams select and tailor NIST SP 800-53B baselines?
Start with the applicable SP 800-53B security and privacy baselines, then document categorization, tailoring, parameters, overlays, responsibility, and additions.
How should teams complete NIST control parameters?
Complete every SP 800-53 assignment and selection operation with an approved, scoped, implementable value, then assess the completed control statement.
How should teams document NIST common controls?
Document the common-control provider, inherited capability, parameters, consumer boundary, assessment results, dependencies, and system-specific work.
How should teams document NIST control inheritance?
Verify actual control inheritance by comparing provider scope, completed parameters, assessment results, dependencies, and remaining system-specific work.
NIST SP 800-53 Rev. 5 Applicability Guide
Decide whether NIST SP 800-53 applies, identify the adopting authority and boundary, and document the control, assessment, and authorization path.
NIST SP 800-53 Rev. 5 Baseline Selection Guide
Choose the NIST SP 800-53B security and privacy starting baselines, document the basis, and preserve the tailoring decisions that produce the final control set.
NIST SP 800-53 Rev. 5 Control Assessment Evidence Workflow
Plan and document SP 800-53A assessments by mapping determination statements to examine, interview, and test evidence, coverage, findings, and risk decisions.
NIST SP 800-53 Rev. 5 Control Tailoring Method
Tailor an NIST SP 800-53B baseline with scoping, common controls, parameters, compensating controls, additions, implementation detail, and documented approvals.
NIST SP 800-53 Rev. 5 Evidence and Audit Readiness Guide
Prepare assessment evidence for NIST SP 800-53A by linking each determination statement to scoped, current, reproducible examine, interview, or test records.
NIST SP 800-53 Rev. 5 FAQ: practical implementation questions
Answers to NIST SP 800-53 Rev. 5 questions on applicability, baselines, tailoring, parameters, enhancements, inheritance, assessments, evidence, and POA&Ms.
NIST SP 800-53 Rev. 5 Overlays and Common Controls Guide
Apply NIST SP 800-53 overlays and document common, hybrid, and inherited controls with clear provider, consumer, assessment, and change responsibilities.
NIST SP 800-53 Rev. 5 POA&M Evidence Guide
Document POA&M source findings, planned remediation, milestones, status evidence, governance decisions, and reassessment-backed closure under NIST SP 800-53 CA-5.
NIST SP 800-53 Rev. 5 POA&M Evidence Workflow
Turn assessed control deficiencies into governed POA&M records with risk, corrective actions, resources, milestones, status evidence, and validated closure.
NIST SP 800-53 Rev. 5 SP 800-53A Assessment Procedures Guide
NIST SP 800-53A gives assessors a methodology and set of procedures for checking whether security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.
NIST SP 800-53 Rev. 5 vs CIS Controls Decision Guide
Decide when to use NIST SP 800-53 Rev. 5 or CIS Controls v8.1, how selection differs, and when control evidence can be reused.
NIST SP 800-53 Rev. 5 vs CIS Controls: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 and CIS Controls v8.1 by scope, selection method, safeguards, assessment evidence, and assurance.
NIST SP 800-53 Rev. 5 vs ISO/IEC 27001: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 with ISO/IEC 27001:2022 by scope, controls, ISMS requirements, evidence, and certification.
NIST SP 800-53 Rev. 5 vs NIST CSF 2.0: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 and CSF 2.0 by scope, controls, outcomes, Profiles, Tiers, evidence, and assurance.
NIST SP 800-53 Rev. 5 vs NIST CSF Decision Guide
Decide when to use NIST SP 800-53 Rev. 5 or CSF 2.0, how controls relate to outcomes, and when evidence can support both.
NIST SP 800-53 Rev. 5 vs NIST SP 800-171 Decision Guide
Decide when to use NIST SP 800-53 Rev. 5 or SP 800-171 Rev. 3, how their scopes differ, and when control evidence can be reused.
NIST SP 800-53 Rev. 5 vs NIST SP 800-171 Rev. 3: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 with SP 800-171 Rev. 3 by scope, adopting authority, CUI boundary, requirements, evidence, and assessment.
What evidence should teams collect for NIST SP 800-53A control assessments?
Collect evidence for each SP 800-53A determination statement, using the selected examine, interview, and test methods at the planned depth and coverage.
What should a POA&M item include for NIST SP 800-53 Rev. 5 control gaps?
A useful POA&M item identifies the finding, affected control and system, risk response, owner, milestones, status evidence, dependencies, and closure criteria.
When should teams select NIST control enhancements?
Select a control enhancement only with its base control, document the selection trigger and parameters, implement its added requirement, and assess it separately.