NIST SP 800-53 Rev 5

Security and Privacy Controls for Information Systems and Organizations

Current: Rev 5.2.0 (Aug 2025)Authority: FISMA20 Control Families

Overview

NIST Special Publication 800-53 Revision 5 is the definitive catalog of security and privacy controls for information systems and organizations. Published by the National Institute of Standards and Technology, it provides the control framework that underpins federal cybersecurity compliance and increasingly serves as the baseline for private sector security programs in regulated industries.

Why 800-53 Matters for AI Governance

While NIST AI RMF addresses AI-specific risks, 800-53 provides the foundational security and privacy infrastructure that AI systems require. Organizations deploying AI must integrate AI governance with existing 800-53 control implementations—particularly for training data protection, model access control, and audit trails.

Control Architecture

NIST 800-53 Rev 5 organizes controls into 20 families covering the full spectrum of security and privacy requirements:

FamilyCodeFocus Area
Access ControlACSystem and data access restrictions
Awareness and TrainingATSecurity education and awareness
Audit and AccountabilityAULogging, monitoring, and audit trails
Assessment, Authorization, MonitoringCAContinuous assessment and authorization
Configuration ManagementCMBaseline configurations and change control
Contingency PlanningCPBusiness continuity and disaster recovery
Identification and AuthenticationIAIdentity management and authentication
Incident ResponseIRSecurity incident handling
MaintenanceMASystem maintenance procedures
Media ProtectionMPData storage and media handling
Physical and EnvironmentalPEFacility security
PlanningPLSecurity planning and policies
Program ManagementPMEnterprise security program
Personnel SecurityPSPersonnel screening and management
PII Processing and TransparencyPTPrivacy controls (NEW in Rev 5)
Risk AssessmentRARisk identification and analysis
System and Services AcquisitionSASecure development and procurement
System and Communications ProtectionSCCommunications and data protection
System and Information IntegritySISystem integrity and malware protection
Supply Chain Risk ManagementSRThird-party risk (NEW in Rev 5)

Key Rev 5 Changes

Control Baselines

BaselineImpact LevelTypical Use Cases
LowLimited adverse effectPublic information systems, non-sensitive data
ModerateSerious adverse effectBusiness-sensitive data, most federal systems
HighSevere/catastrophic effectNational security, critical infrastructure

Integration with AI Governance

Mapping to NIST AI RMF

AI RMF FunctionRelevant 800-53 Families
GOVERNPM, PL, PS, AT
MAPRA, SA, CA
MEASUREAU, CA, SI
MANAGEIR, CM, CP, SR

Critical Controls for AI Systems

Related Frameworks

Need Help With 800-53 and AI Governance?

KAiM helps regulated organizations integrate 800-53 controls with AI governance programs.