What are control enhancements in NIST SP 800-53 Rev. 5?
Control enhancements are additional requirements that build on a base control and make it more specific, stronger, or more targeted for a particular risk or operating need.
In practical terms, a control enhancement tells you what extra action, condition, or parameter must be in place beyond the base control statement.
- Use the enhancement to narrow or strengthen the base control for the system or process in scope.
- Tie the enhancement to the exact source and implementation context so reviewers can see why it applies.
- Review the enhancement again when the source, product, supplier, platform, audit evidence, or process changes.
Primary NIST source for the integrated security and privacy control catalog.
Primary NIST source for control assessment objectives, methods, depth, and coverage.
NIST source for baseline allocation of controls and control enhancements.