Control library
A curated slice of the NIST SP 800-53 Rev.5 control catalog NIST SP 800-53 Rev.5, grouped by family. Set each control's implementation status; coverage rolls up here and feeds the POA&M. Filter by the baseline a system's FIPS 199 categorization selects.
Baseline: Low
Showing the 131 controls in the Low baseline (and below). Implementation credit: full for Implemented, half for Partial → 0% covered.
Access Control AC
0/11 implemented| ID | Control | Baseline | Status | Change |
|---|
| AC-1 | Policy and Procedures | Low | ✗ Not implemented | |
| AC-2 | Account Management | Low | ✗ Not implemented | |
| AC-3 | Access Enforcement | Low | ✗ Not implemented | |
| AC-7 | Unsuccessful Logon Attempts | Low | ✗ Not implemented | |
| AC-8 | System Use Notification | Low | ✗ Not implemented | |
| AC-14 | Permitted Actions Without Identification or Authentication | Low | ✗ Not implemented | |
| AC-17 | Remote Access | Low | ✗ Not implemented | |
| AC-18 | Wireless Access | Low | ✗ Not implemented | |
| AC-19 | Access Control for Mobile Devices | Low | ✗ Not implemented | |
| AC-20 | Use of External Systems | Low | ✗ Not implemented | |
| AC-22 | Publicly Accessible Content | Low | ✗ Not implemented | |
Awareness and Training AT
0/4 implemented| ID | Control | Baseline | Status | Change |
|---|
| AT-1 | Policy and Procedures | Low | ✗ Not implemented | |
| AT-2 | Literacy Training and Awareness | Low | ✗ Not implemented | |
| AT-3 | Role-based Training | Low | ✗ Not implemented | |
| AT-4 | Training Records | Low | ✗ Not implemented | |
Audit and Accountability AU
0/10 implemented| ID | Control | Baseline | Status | Change |
|---|
| AU-1 | Policy and Procedures | Low | ✗ Not implemented | |
| AU-2 | Event Logging | Low | ✗ Not implemented | |
| AU-3 | Content of Audit Records | Low | ✗ Not implemented | |
| AU-4 | Audit Log Storage Capacity | Low | ✗ Not implemented | |
| AU-5 | Response to Audit Logging Process Failures | Low | ✗ Not implemented | |
| AU-6 | Audit Record Review, Analysis, and Reporting | Low | ✗ Not implemented | |
| AU-8 | Time Stamps | Low | ✗ Not implemented | |
| AU-9 | Protection of Audit Information | Low | ✗ Not implemented | |
| AU-11 | Audit Record Retention | Low | ✗ Not implemented | |
| AU-12 | Audit Record Generation | Low | ✗ Not implemented | |
Assessment, Authorization, and Monitoring CA
0/7 implemented| ID | Control | Baseline | Status | Change |
|---|
| CA-1 | Policy and Procedures | Low | ✗ Not implemented | |
| CA-2 | Control Assessments | Low | ✗ Not implemented | |
| CA-3 | Information Exchange | Low | ✗ Not implemented | |
| CA-5 | Plan of Action and Milestones | Low | ✗ Not implemented | |
| CA-6 | Authorization | Low | ✗ Not implemented | |
| CA-7 | Continuous Monitoring | Low | ✗ Not implemented | |
| CA-9 | Internal System Connections | Low | ✗ Not implemented | |
Configuration Management CM
0/9 implemented| ID | Control | Baseline | Status | Change |
|---|
| CM-1 | Policy and Procedures | Low | ✗ Not implemented | |
| CM-2 | Baseline Configuration | Low | ✗ Not implemented | |
| CM-4 | Impact Analyses | Low | ✗ Not implemented | |
| CM-5 | Access Restrictions for Change | Low | ✗ Not implemented | |
| CM-6 | Configuration Settings | Low | ✗ Not implemented | |
| CM-7 | Least Functionality | Low | ✗ Not implemented | |
| CM-8 | System Component Inventory | Low | ✗ Not implemented | |
| CM-10 | Software Usage Restrictions | Low | ✗ Not implemented | |
| CM-11 | User-installed Software | Low | ✗ Not implemented | |
Contingency Planning CP
0/6 implemented| ID | Control | Baseline | Status | Change |
|---|
| CP-1 | Policy and Procedures | Low | ✗ Not implemented | |
| CP-2 | Contingency Plan | Low | ✗ Not implemented | |
| CP-3 | Contingency Training | Low | ✗ Not implemented | |
| CP-4 | Contingency Plan Testing | Low | ✗ Not implemented | |
| CP-9 | System Backup | Low | ✗ Not implemented | |
| CP-10 | System Recovery and Reconstitution | Low | ✗ Not implemented | |
Identification and Authentication IA
0/8 implemented| ID | Control | Baseline | Status | Change |
|---|
| IA-1 | Policy and Procedures | Low | ✗ Not implemented | |
| IA-2 | Identification and Authentication (Organizational Users) | Low | ✗ Not implemented | |
| IA-4 | Identifier Management | Low | ✗ Not implemented | |
| IA-5 | Authenticator Management | Low | ✗ Not implemented | |
| IA-6 | Authentication Feedback | Low | ✗ Not implemented | |
| IA-7 | Cryptographic Module Authentication | Low | ✗ Not implemented | |
| IA-8 | Identification and Authentication (Non-organizational Users) | Low | ✗ Not implemented | |
| IA-11 | Re-authentication | Low | ✗ Not implemented | |
Incident Response IR
0/7 implemented| ID | Control | Baseline | Status | Change |
|---|
| IR-1 | Policy and Procedures | Low | ✗ Not implemented | |
| IR-2 | Incident Response Training | Low | ✗ Not implemented | |
| IR-4 | Incident Handling | Low | ✗ Not implemented | |
| IR-5 | Incident Monitoring | Low | ✗ Not implemented | |
| IR-6 | Incident Reporting | Low | ✗ Not implemented | |
| IR-7 | Incident Response Assistance | Low | ✗ Not implemented | |
| IR-8 | Incident Response Plan | Low | ✗ Not implemented | |
Maintenance MA
0/4 implemented| ID | Control | Baseline | Status | Change |
|---|
| MA-1 | Policy and Procedures | Low | ✗ Not implemented | |
| MA-2 | Controlled Maintenance | Low | ✗ Not implemented | |
| MA-4 | Nonlocal Maintenance | Low | ✗ Not implemented | |
| MA-5 | Maintenance Personnel | Low | ✗ Not implemented | |
Media Protection MP
0/4 implemented| ID | Control | Baseline | Status | Change |
|---|
| MP-1 | Policy and Procedures | Low | ✗ Not implemented | |
| MP-2 | Media Access | Low | ✗ Not implemented | |
| MP-6 | Media Sanitization | Low | ✗ Not implemented | |
| MP-7 | Media Use | Low | ✗ Not implemented | |
Physical and Environmental Protection PE
0/10 implemented| ID | Control | Baseline | Status | Change |
|---|
| PE-1 | Policy and Procedures | Low | ✗ Not implemented | |
| PE-2 | Physical Access Authorizations | Low | ✗ Not implemented | |
| PE-3 | Physical Access Control | Low | ✗ Not implemented | |
| PE-6 | Monitoring Physical Access | Low | ✗ Not implemented | |
| PE-8 | Visitor Access Records | Low | ✗ Not implemented | |
| PE-12 | Emergency Lighting | Low | ✗ Not implemented | |
| PE-13 | Fire Protection | Low | ✗ Not implemented | |
| PE-14 | Environmental Controls | Low | ✗ Not implemented | |
| PE-15 | Water Damage Protection | Low | ✗ Not implemented | |
| PE-16 | Delivery and Removal | Low | ✗ Not implemented | |
Planning PL
0/5 implemented| ID | Control | Baseline | Status | Change |
|---|
| PL-1 | Policy and Procedures | Low | ✗ Not implemented | |
| PL-2 | System Security and Privacy Plans | Low | ✗ Not implemented | |
| PL-4 | Rules of Behavior | Low | ✗ Not implemented | |
| PL-10 | Baseline Selection | Low | ✗ Not implemented | |
| PL-11 | Baseline Tailoring | Low | ✗ Not implemented | |
Personnel Security PS
0/9 implemented| ID | Control | Baseline | Status | Change |
|---|
| PS-1 | Policy and Procedures | Low | ✗ Not implemented | |
| PS-2 | Position Risk Designation | Low | ✗ Not implemented | |
| PS-3 | Personnel Screening | Low | ✗ Not implemented | |
| PS-4 | Personnel Termination | Low | ✗ Not implemented | |
| PS-5 | Personnel Transfer | Low | ✗ Not implemented | |
| PS-6 | Access Agreements | Low | ✗ Not implemented | |
| PS-7 | External Personnel Security | Low | ✗ Not implemented | |
| PS-8 | Personnel Sanctions | Low | ✗ Not implemented | |
| PS-9 | Position Descriptions | Low | ✗ Not implemented | |
Risk Assessment RA
0/5 implemented| ID | Control | Baseline | Status | Change |
|---|
| RA-1 | Policy and Procedures | Low | ✗ Not implemented | |
| RA-2 | Security Categorization | Low | ✗ Not implemented | |
| RA-3 | Risk Assessment | Low | ✗ Not implemented | |
| RA-5 | Vulnerability Monitoring and Scanning | Low | ✗ Not implemented | |
| RA-7 | Risk Response | Low | ✗ Not implemented | |
System and Services Acquisition SA
0/8 implemented| ID | Control | Baseline | Status | Change |
|---|
| SA-1 | Policy and Procedures | Low | ✗ Not implemented | |
| SA-2 | Allocation of Resources | Low | ✗ Not implemented | |
| SA-3 | System Development Life Cycle | Low | ✗ Not implemented | |
| SA-4 | Acquisition Process | Low | ✗ Not implemented | |
| SA-5 | System Documentation | Low | ✗ Not implemented | |
| SA-8 | Security and Privacy Engineering Principles | Low | ✗ Not implemented | |
| SA-9 | External System Services | Low | ✗ Not implemented | |
| SA-22 | Unsupported System Components | Low | ✗ Not implemented | |
System and Communications Protection SC
0/10 implemented| ID | Control | Baseline | Status | Change |
|---|
| SC-1 | Policy and Procedures | Low | ✗ Not implemented | |
| SC-5 | Denial-of-service Protection | Low | ✗ Not implemented | |
| SC-7 | Boundary Protection | Low | ✗ Not implemented | |
| SC-12 | Cryptographic Key Establishment and Management | Low | ✗ Not implemented | |
| SC-13 | Cryptographic Protection | Low | ✗ Not implemented | |
| SC-15 | Collaborative Computing Devices and Applications | Low | ✗ Not implemented | |
| SC-20 | Secure Name/Address Resolution Service (Authoritative Source) | Low | ✗ Not implemented | |
| SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | Low | ✗ Not implemented | |
| SC-22 | Architecture and Provisioning for Name/Address Resolution Service | Low | ✗ Not implemented | |
| SC-39 | Process Isolation | Low | ✗ Not implemented | |
System and Information Integrity SI
0/6 implemented| ID | Control | Baseline | Status | Change |
|---|
| SI-1 | Policy and Procedures | Low | ✗ Not implemented | |
| SI-2 | Flaw Remediation | Low | ✗ Not implemented | |
| SI-3 | Malicious Code Protection | Low | ✗ Not implemented | |
| SI-4 | System Monitoring | Low | ✗ Not implemented | |
| SI-5 | Security Alerts, Advisories, and Directives | Low | ✗ Not implemented | |
| SI-12 | Information Management and Retention | Low | ✗ Not implemented | |
Supply Chain Risk Management SR
0/8 implemented| ID | Control | Baseline | Status | Change |
|---|
| SR-1 | Policy and Procedures | Low | ✗ Not implemented | |
| SR-2 | Supply Chain Risk Management Plan | Low | ✗ Not implemented | |
| SR-3 | Supply Chain Controls and Processes | Low | ✗ Not implemented | |
| SR-5 | Acquisition Strategies, Tools, and Methods | Low | ✗ Not implemented | |
| SR-8 | Notification Agreements | Low | ✗ Not implemented | |
| SR-10 | Inspection of Systems or Components | Low | ✗ Not implemented | |
| SR-11 | Component Authenticity | Low | ✗ Not implemented | |
| SR-12 | Component Disposal | Low | ✗ Not implemented | |