PlumbTrackLive demoGRC Risk System

Control library

A curated slice of the NIST SP 800-53 Rev.5 control catalog NIST SP 800-53 Rev.5, grouped by family. Set each control's implementation status; coverage rolls up here and feeds the POA&M. Filter by the baseline a system's FIPS 199 categorization selects.

188
Controls
0%
Coverage
0
Implemented
0
Partial
188
Gaps
Show baseline: AllLowModerateHigha system's FIPS 199 level selects its SP 800-53B baseline NIST SP 800-53B

Access Control AC

0/18 implemented
IDControlBaselineStatusChange
AC-1Policy and ProceduresLow✗ Not implemented
AC-2Account ManagementLow✗ Not implemented
AC-3Access EnforcementLow✗ Not implemented
AC-4Information Flow EnforcementModerate✗ Not implemented
AC-5Separation of DutiesModerate✗ Not implemented
AC-6Least PrivilegeModerate✗ Not implemented
AC-7Unsuccessful Logon AttemptsLow✗ Not implemented
AC-8System Use NotificationLow✗ Not implemented
AC-10Concurrent Session ControlHigh✗ Not implemented
AC-11Device LockModerate✗ Not implemented
AC-12Session TerminationModerate✗ Not implemented
AC-14Permitted Actions Without Identification or AuthenticationLow✗ Not implemented
AC-17Remote AccessLow✗ Not implemented
AC-18Wireless AccessLow✗ Not implemented
AC-19Access Control for Mobile DevicesLow✗ Not implemented
AC-20Use of External SystemsLow✗ Not implemented
AC-21Information SharingModerate✗ Not implemented
AC-22Publicly Accessible ContentLow✗ Not implemented

Awareness and Training AT

0/4 implemented
IDControlBaselineStatusChange
AT-1Policy and ProceduresLow✗ Not implemented
AT-2Literacy Training and AwarenessLow✗ Not implemented
AT-3Role-based TrainingLow✗ Not implemented
AT-4Training RecordsLow✗ Not implemented

Audit and Accountability AU

0/12 implemented
IDControlBaselineStatusChange
AU-1Policy and ProceduresLow✗ Not implemented
AU-2Event LoggingLow✗ Not implemented
AU-3Content of Audit RecordsLow✗ Not implemented
AU-4Audit Log Storage CapacityLow✗ Not implemented
AU-5Response to Audit Logging Process FailuresLow✗ Not implemented
AU-6Audit Record Review, Analysis, and ReportingLow✗ Not implemented
AU-7Audit Record Reduction and Report GenerationModerate✗ Not implemented
AU-8Time StampsLow✗ Not implemented
AU-9Protection of Audit InformationLow✗ Not implemented
AU-10Non-repudiationHigh✗ Not implemented
AU-11Audit Record RetentionLow✗ Not implemented
AU-12Audit Record GenerationLow✗ Not implemented

Assessment, Authorization, and Monitoring CA

0/8 implemented
IDControlBaselineStatusChange
CA-1Policy and ProceduresLow✗ Not implemented
CA-2Control AssessmentsLow✗ Not implemented
CA-3Information ExchangeLow✗ Not implemented
CA-5Plan of Action and MilestonesLow✗ Not implemented
CA-6AuthorizationLow✗ Not implemented
CA-7Continuous MonitoringLow✗ Not implemented
CA-8Penetration TestingHigh✗ Not implemented
CA-9Internal System ConnectionsLow✗ Not implemented

Configuration Management CM

0/12 implemented
IDControlBaselineStatusChange
CM-1Policy and ProceduresLow✗ Not implemented
CM-2Baseline ConfigurationLow✗ Not implemented
CM-3Configuration Change ControlModerate✗ Not implemented
CM-4Impact AnalysesLow✗ Not implemented
CM-5Access Restrictions for ChangeLow✗ Not implemented
CM-6Configuration SettingsLow✗ Not implemented
CM-7Least FunctionalityLow✗ Not implemented
CM-8System Component InventoryLow✗ Not implemented
CM-9Configuration Management PlanModerate✗ Not implemented
CM-10Software Usage RestrictionsLow✗ Not implemented
CM-11User-installed SoftwareLow✗ Not implemented
CM-12Information LocationModerate✗ Not implemented

Contingency Planning CP

0/9 implemented
IDControlBaselineStatusChange
CP-1Policy and ProceduresLow✗ Not implemented
CP-2Contingency PlanLow✗ Not implemented
CP-3Contingency TrainingLow✗ Not implemented
CP-4Contingency Plan TestingLow✗ Not implemented
CP-6Alternate Storage SiteModerate✗ Not implemented
CP-7Alternate Processing SiteModerate✗ Not implemented
CP-8Telecommunications ServicesModerate✗ Not implemented
CP-9System BackupLow✗ Not implemented
CP-10System Recovery and ReconstitutionLow✗ Not implemented

Identification and Authentication IA

0/10 implemented
IDControlBaselineStatusChange
IA-1Policy and ProceduresLow✗ Not implemented
IA-2Identification and Authentication (Organizational Users)Low✗ Not implemented
IA-3Device Identification and AuthenticationModerate✗ Not implemented
IA-4Identifier ManagementLow✗ Not implemented
IA-5Authenticator ManagementLow✗ Not implemented
IA-6Authentication FeedbackLow✗ Not implemented
IA-7Cryptographic Module AuthenticationLow✗ Not implemented
IA-8Identification and Authentication (Non-organizational Users)Low✗ Not implemented
IA-11Re-authenticationLow✗ Not implemented
IA-12Identity ProofingModerate✗ Not implemented

Incident Response IR

0/8 implemented
IDControlBaselineStatusChange
IR-1Policy and ProceduresLow✗ Not implemented
IR-2Incident Response TrainingLow✗ Not implemented
IR-3Incident Response TestingModerate✗ Not implemented
IR-4Incident HandlingLow✗ Not implemented
IR-5Incident MonitoringLow✗ Not implemented
IR-6Incident ReportingLow✗ Not implemented
IR-7Incident Response AssistanceLow✗ Not implemented
IR-8Incident Response PlanLow✗ Not implemented

Maintenance MA

0/6 implemented
IDControlBaselineStatusChange
MA-1Policy and ProceduresLow✗ Not implemented
MA-2Controlled MaintenanceLow✗ Not implemented
MA-3Maintenance ToolsModerate✗ Not implemented
MA-4Nonlocal MaintenanceLow✗ Not implemented
MA-5Maintenance PersonnelLow✗ Not implemented
MA-6Timely MaintenanceModerate✗ Not implemented

Media Protection MP

0/7 implemented
IDControlBaselineStatusChange
MP-1Policy and ProceduresLow✗ Not implemented
MP-2Media AccessLow✗ Not implemented
MP-3Media MarkingModerate✗ Not implemented
MP-4Media StorageModerate✗ Not implemented
MP-5Media TransportModerate✗ Not implemented
MP-6Media SanitizationLow✗ Not implemented
MP-7Media UseLow✗ Not implemented

Physical and Environmental Protection PE

0/17 implemented
IDControlBaselineStatusChange
PE-1Policy and ProceduresLow✗ Not implemented
PE-2Physical Access AuthorizationsLow✗ Not implemented
PE-3Physical Access ControlLow✗ Not implemented
PE-4Access Control for TransmissionModerate✗ Not implemented
PE-5Access Control for Output DevicesModerate✗ Not implemented
PE-6Monitoring Physical AccessLow✗ Not implemented
PE-8Visitor Access RecordsLow✗ Not implemented
PE-9Power Equipment and CablingModerate✗ Not implemented
PE-10Emergency ShutoffModerate✗ Not implemented
PE-11Emergency PowerModerate✗ Not implemented
PE-12Emergency LightingLow✗ Not implemented
PE-13Fire ProtectionLow✗ Not implemented
PE-14Environmental ControlsLow✗ Not implemented
PE-15Water Damage ProtectionLow✗ Not implemented
PE-16Delivery and RemovalLow✗ Not implemented
PE-17Alternate Work SiteModerate✗ Not implemented
PE-18Location of System ComponentsHigh✗ Not implemented

Planning PL

0/6 implemented
IDControlBaselineStatusChange
PL-1Policy and ProceduresLow✗ Not implemented
PL-2System Security and Privacy PlansLow✗ Not implemented
PL-4Rules of BehaviorLow✗ Not implemented
PL-8Security and Privacy ArchitecturesModerate✗ Not implemented
PL-10Baseline SelectionLow✗ Not implemented
PL-11Baseline TailoringLow✗ Not implemented

Personnel Security PS

0/9 implemented
IDControlBaselineStatusChange
PS-1Policy and ProceduresLow✗ Not implemented
PS-2Position Risk DesignationLow✗ Not implemented
PS-3Personnel ScreeningLow✗ Not implemented
PS-4Personnel TerminationLow✗ Not implemented
PS-5Personnel TransferLow✗ Not implemented
PS-6Access AgreementsLow✗ Not implemented
PS-7External Personnel SecurityLow✗ Not implemented
PS-8Personnel SanctionsLow✗ Not implemented
PS-9Position DescriptionsLow✗ Not implemented

Risk Assessment RA

0/6 implemented
IDControlBaselineStatusChange
RA-1Policy and ProceduresLow✗ Not implemented
RA-2Security CategorizationLow✗ Not implemented
RA-3Risk AssessmentLow✗ Not implemented
RA-5Vulnerability Monitoring and ScanningLow✗ Not implemented
RA-7Risk ResponseLow✗ Not implemented
RA-9Criticality AnalysisModerate✗ Not implemented

System and Services Acquisition SA

0/14 implemented
IDControlBaselineStatusChange
SA-1Policy and ProceduresLow✗ Not implemented
SA-2Allocation of ResourcesLow✗ Not implemented
SA-3System Development Life CycleLow✗ Not implemented
SA-4Acquisition ProcessLow✗ Not implemented
SA-5System DocumentationLow✗ Not implemented
SA-8Security and Privacy Engineering PrinciplesLow✗ Not implemented
SA-9External System ServicesLow✗ Not implemented
SA-10Developer Configuration ManagementModerate✗ Not implemented
SA-11Developer Testing and EvaluationModerate✗ Not implemented
SA-15Development Process, Standards, and ToolsModerate✗ Not implemented
SA-16Developer-Provided TrainingHigh✗ Not implemented
SA-17Developer Security and Privacy Architecture and DesignHigh✗ Not implemented
SA-21Developer ScreeningHigh✗ Not implemented
SA-22Unsupported System ComponentsLow✗ Not implemented

System and Communications Protection SC

0/20 implemented
IDControlBaselineStatusChange
SC-1Policy and ProceduresLow✗ Not implemented
SC-2Separation of System and User FunctionalityModerate✗ Not implemented
SC-3Security Function IsolationHigh✗ Not implemented
SC-4Information in Shared System ResourcesModerate✗ Not implemented
SC-5Denial-of-service ProtectionLow✗ Not implemented
SC-7Boundary ProtectionLow✗ Not implemented
SC-8Transmission Confidentiality and IntegrityModerate✗ Not implemented
SC-10Network DisconnectModerate✗ Not implemented
SC-12Cryptographic Key Establishment and ManagementLow✗ Not implemented
SC-13Cryptographic ProtectionLow✗ Not implemented
SC-15Collaborative Computing Devices and ApplicationsLow✗ Not implemented
SC-17Public Key Infrastructure CertificatesModerate✗ Not implemented
SC-18Mobile CodeModerate✗ Not implemented
SC-20Secure Name/Address Resolution Service (Authoritative Source)Low✗ Not implemented
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)Low✗ Not implemented
SC-22Architecture and Provisioning for Name/Address Resolution ServiceLow✗ Not implemented
SC-23Session AuthenticityModerate✗ Not implemented
SC-24Fail in Known StateHigh✗ Not implemented
SC-28Protection of Information at RestModerate✗ Not implemented
SC-39Process IsolationLow✗ Not implemented

System and Information Integrity SI

0/12 implemented
IDControlBaselineStatusChange
SI-1Policy and ProceduresLow✗ Not implemented
SI-2Flaw RemediationLow✗ Not implemented
SI-3Malicious Code ProtectionLow✗ Not implemented
SI-4System MonitoringLow✗ Not implemented
SI-5Security Alerts, Advisories, and DirectivesLow✗ Not implemented
SI-6Security and Privacy Function VerificationHigh✗ Not implemented
SI-7Software, Firmware, and Information IntegrityModerate✗ Not implemented
SI-8Spam ProtectionModerate✗ Not implemented
SI-10Information Input ValidationModerate✗ Not implemented
SI-11Error HandlingModerate✗ Not implemented
SI-12Information Management and RetentionLow✗ Not implemented
SI-16Memory ProtectionModerate✗ Not implemented

Supply Chain Risk Management SR

0/10 implemented
IDControlBaselineStatusChange
SR-1Policy and ProceduresLow✗ Not implemented
SR-2Supply Chain Risk Management PlanLow✗ Not implemented
SR-3Supply Chain Controls and ProcessesLow✗ Not implemented
SR-5Acquisition Strategies, Tools, and MethodsLow✗ Not implemented
SR-6Supplier Assessments and ReviewsModerate✗ Not implemented
SR-8Notification AgreementsLow✗ Not implemented
SR-9Tamper Resistance and DetectionHigh✗ Not implemented
SR-10Inspection of Systems or ComponentsLow✗ Not implemented
SR-11Component AuthenticityLow✗ Not implemented
SR-12Component DisposalLow✗ Not implemented
Export⇩ controls.csv