How many NIST 800-53 controls are there?

The NIST 800-53 Controls are organized into 20 different control families that help to identify and categorize them to the area of focus. The families are as follows:

  1. Access Control
  2. Awareness and Training
  3. Audit and Accountability
  4. Assessment, Authorization, and Monitoring
  5. Configuration Management
  6. Contingency Planning
  7. Identification and Authentication
  8. Incident Response
  9. Maintenance
  10. Media Protection
  11. Physical and Environmental Protection
  12. Planning
  13. Program Management
  14. Personnel Security
  15. Personal Identifiable Information Processing and Transparency
  16. Risk Assessment
  17. System and Services Acquisition
  18. System and Communications Protection
  19. System and Information Integrity
  20. Supply Chain Risk Management.

Within each of these families, there are multiple different Control Identifiers that are related to the overall group. Each security control identifier has a control name, base control, discussion, related controls, control enhancements, and references. Overall, there are over 1150 security controls within these 20 different families that make up the NIST 800-53 cybersecurity framework.

Share this post