National Institute of Standards and Technology mark.

SP 800-53 Rev. 5 is a catalogue of security and privacy controls for information systems and organisations. Its controls support selection and tailoring within a risk-management process; it is not one universal checklist for every system. See the NIST publication and update notices.

Use in a programme

Identify the applicable baseline, system context and tailoring decisions. Record the selected controls, accountable implementers and evidence used to assess them. Control functionality and the confidence established through assurance both matter.

Use the corresponding assessment and baseline publications where relevant. A control catalogue, assessment procedure and baseline have different roles.

Use in CSFaaS

The reviewed library lists NIST SP 800-53 rev. 5 - EN. Verify the imported scope and control release before treating it as the intended baseline.

NIST's August 2025 release notice identifies control and assessment release 5.2.0. A release identifier and the Rev. 5 publication label are not interchangeable; preserve both when relevant.

Link policies and evidence to assessed requirements, explain exclusions and maintain the source history. A reference's row count does not establish complete coverage of every control enhancement or release change.