PlumbTrackLive demoGRC Risk System

Control library

A curated slice of the NIST SP 800-53 Rev.5 control catalog NIST SP 800-53 Rev.5, grouped by family. Set each control's implementation status; coverage rolls up here and feeds the POA&M. Filter by the baseline a system's FIPS 199 categorization selects.

131
Controls
0%
Coverage
0
Implemented
0
Partial
131
Gaps
Show baseline: AllLowModerateHigha system's FIPS 199 level selects its SP 800-53B baseline NIST SP 800-53B

Baseline: Low

Showing the 131 controls in the Low baseline (and below). Implementation credit: full for Implemented, half for Partial → 0% covered.

Access Control AC

0/11 implemented
IDControlBaselineStatusChange
AC-1Policy and ProceduresLow✗ Not implemented
AC-2Account ManagementLow✗ Not implemented
AC-3Access EnforcementLow✗ Not implemented
AC-7Unsuccessful Logon AttemptsLow✗ Not implemented
AC-8System Use NotificationLow✗ Not implemented
AC-14Permitted Actions Without Identification or AuthenticationLow✗ Not implemented
AC-17Remote AccessLow✗ Not implemented
AC-18Wireless AccessLow✗ Not implemented
AC-19Access Control for Mobile DevicesLow✗ Not implemented
AC-20Use of External SystemsLow✗ Not implemented
AC-22Publicly Accessible ContentLow✗ Not implemented

Awareness and Training AT

0/4 implemented
IDControlBaselineStatusChange
AT-1Policy and ProceduresLow✗ Not implemented
AT-2Literacy Training and AwarenessLow✗ Not implemented
AT-3Role-based TrainingLow✗ Not implemented
AT-4Training RecordsLow✗ Not implemented

Audit and Accountability AU

0/10 implemented
IDControlBaselineStatusChange
AU-1Policy and ProceduresLow✗ Not implemented
AU-2Event LoggingLow✗ Not implemented
AU-3Content of Audit RecordsLow✗ Not implemented
AU-4Audit Log Storage CapacityLow✗ Not implemented
AU-5Response to Audit Logging Process FailuresLow✗ Not implemented
AU-6Audit Record Review, Analysis, and ReportingLow✗ Not implemented
AU-8Time StampsLow✗ Not implemented
AU-9Protection of Audit InformationLow✗ Not implemented
AU-11Audit Record RetentionLow✗ Not implemented
AU-12Audit Record GenerationLow✗ Not implemented

Assessment, Authorization, and Monitoring CA

0/7 implemented
IDControlBaselineStatusChange
CA-1Policy and ProceduresLow✗ Not implemented
CA-2Control AssessmentsLow✗ Not implemented
CA-3Information ExchangeLow✗ Not implemented
CA-5Plan of Action and MilestonesLow✗ Not implemented
CA-6AuthorizationLow✗ Not implemented
CA-7Continuous MonitoringLow✗ Not implemented
CA-9Internal System ConnectionsLow✗ Not implemented

Configuration Management CM

0/9 implemented
IDControlBaselineStatusChange
CM-1Policy and ProceduresLow✗ Not implemented
CM-2Baseline ConfigurationLow✗ Not implemented
CM-4Impact AnalysesLow✗ Not implemented
CM-5Access Restrictions for ChangeLow✗ Not implemented
CM-6Configuration SettingsLow✗ Not implemented
CM-7Least FunctionalityLow✗ Not implemented
CM-8System Component InventoryLow✗ Not implemented
CM-10Software Usage RestrictionsLow✗ Not implemented
CM-11User-installed SoftwareLow✗ Not implemented

Contingency Planning CP

0/6 implemented
IDControlBaselineStatusChange
CP-1Policy and ProceduresLow✗ Not implemented
CP-2Contingency PlanLow✗ Not implemented
CP-3Contingency TrainingLow✗ Not implemented
CP-4Contingency Plan TestingLow✗ Not implemented
CP-9System BackupLow✗ Not implemented
CP-10System Recovery and ReconstitutionLow✗ Not implemented

Identification and Authentication IA

0/8 implemented
IDControlBaselineStatusChange
IA-1Policy and ProceduresLow✗ Not implemented
IA-2Identification and Authentication (Organizational Users)Low✗ Not implemented
IA-4Identifier ManagementLow✗ Not implemented
IA-5Authenticator ManagementLow✗ Not implemented
IA-6Authentication FeedbackLow✗ Not implemented
IA-7Cryptographic Module AuthenticationLow✗ Not implemented
IA-8Identification and Authentication (Non-organizational Users)Low✗ Not implemented
IA-11Re-authenticationLow✗ Not implemented

Incident Response IR

0/7 implemented
IDControlBaselineStatusChange
IR-1Policy and ProceduresLow✗ Not implemented
IR-2Incident Response TrainingLow✗ Not implemented
IR-4Incident HandlingLow✗ Not implemented
IR-5Incident MonitoringLow✗ Not implemented
IR-6Incident ReportingLow✗ Not implemented
IR-7Incident Response AssistanceLow✗ Not implemented
IR-8Incident Response PlanLow✗ Not implemented

Maintenance MA

0/4 implemented
IDControlBaselineStatusChange
MA-1Policy and ProceduresLow✗ Not implemented
MA-2Controlled MaintenanceLow✗ Not implemented
MA-4Nonlocal MaintenanceLow✗ Not implemented
MA-5Maintenance PersonnelLow✗ Not implemented

Media Protection MP

0/4 implemented
IDControlBaselineStatusChange
MP-1Policy and ProceduresLow✗ Not implemented
MP-2Media AccessLow✗ Not implemented
MP-6Media SanitizationLow✗ Not implemented
MP-7Media UseLow✗ Not implemented

Physical and Environmental Protection PE

0/10 implemented
IDControlBaselineStatusChange
PE-1Policy and ProceduresLow✗ Not implemented
PE-2Physical Access AuthorizationsLow✗ Not implemented
PE-3Physical Access ControlLow✗ Not implemented
PE-6Monitoring Physical AccessLow✗ Not implemented
PE-8Visitor Access RecordsLow✗ Not implemented
PE-12Emergency LightingLow✗ Not implemented
PE-13Fire ProtectionLow✗ Not implemented
PE-14Environmental ControlsLow✗ Not implemented
PE-15Water Damage ProtectionLow✗ Not implemented
PE-16Delivery and RemovalLow✗ Not implemented

Planning PL

0/5 implemented
IDControlBaselineStatusChange
PL-1Policy and ProceduresLow✗ Not implemented
PL-2System Security and Privacy PlansLow✗ Not implemented
PL-4Rules of BehaviorLow✗ Not implemented
PL-10Baseline SelectionLow✗ Not implemented
PL-11Baseline TailoringLow✗ Not implemented

Personnel Security PS

0/9 implemented
IDControlBaselineStatusChange
PS-1Policy and ProceduresLow✗ Not implemented
PS-2Position Risk DesignationLow✗ Not implemented
PS-3Personnel ScreeningLow✗ Not implemented
PS-4Personnel TerminationLow✗ Not implemented
PS-5Personnel TransferLow✗ Not implemented
PS-6Access AgreementsLow✗ Not implemented
PS-7External Personnel SecurityLow✗ Not implemented
PS-8Personnel SanctionsLow✗ Not implemented
PS-9Position DescriptionsLow✗ Not implemented

Risk Assessment RA

0/5 implemented
IDControlBaselineStatusChange
RA-1Policy and ProceduresLow✗ Not implemented
RA-2Security CategorizationLow✗ Not implemented
RA-3Risk AssessmentLow✗ Not implemented
RA-5Vulnerability Monitoring and ScanningLow✗ Not implemented
RA-7Risk ResponseLow✗ Not implemented

System and Services Acquisition SA

0/8 implemented
IDControlBaselineStatusChange
SA-1Policy and ProceduresLow✗ Not implemented
SA-2Allocation of ResourcesLow✗ Not implemented
SA-3System Development Life CycleLow✗ Not implemented
SA-4Acquisition ProcessLow✗ Not implemented
SA-5System DocumentationLow✗ Not implemented
SA-8Security and Privacy Engineering PrinciplesLow✗ Not implemented
SA-9External System ServicesLow✗ Not implemented
SA-22Unsupported System ComponentsLow✗ Not implemented

System and Communications Protection SC

0/10 implemented
IDControlBaselineStatusChange
SC-1Policy and ProceduresLow✗ Not implemented
SC-5Denial-of-service ProtectionLow✗ Not implemented
SC-7Boundary ProtectionLow✗ Not implemented
SC-12Cryptographic Key Establishment and ManagementLow✗ Not implemented
SC-13Cryptographic ProtectionLow✗ Not implemented
SC-15Collaborative Computing Devices and ApplicationsLow✗ Not implemented
SC-20Secure Name/Address Resolution Service (Authoritative Source)Low✗ Not implemented
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)Low✗ Not implemented
SC-22Architecture and Provisioning for Name/Address Resolution ServiceLow✗ Not implemented
SC-39Process IsolationLow✗ Not implemented

System and Information Integrity SI

0/6 implemented
IDControlBaselineStatusChange
SI-1Policy and ProceduresLow✗ Not implemented
SI-2Flaw RemediationLow✗ Not implemented
SI-3Malicious Code ProtectionLow✗ Not implemented
SI-4System MonitoringLow✗ Not implemented
SI-5Security Alerts, Advisories, and DirectivesLow✗ Not implemented
SI-12Information Management and RetentionLow✗ Not implemented

Supply Chain Risk Management SR

0/8 implemented
IDControlBaselineStatusChange
SR-1Policy and ProceduresLow✗ Not implemented
SR-2Supply Chain Risk Management PlanLow✗ Not implemented
SR-3Supply Chain Controls and ProcessesLow✗ Not implemented
SR-5Acquisition Strategies, Tools, and MethodsLow✗ Not implemented
SR-8Notification AgreementsLow✗ Not implemented
SR-10Inspection of Systems or ComponentsLow✗ Not implemented
SR-11Component AuthenticityLow✗ Not implemented
SR-12Component DisposalLow✗ Not implemented
Export⇩ controls.csv