The NIST 800-53 Controls are organized into 20 different control families that help to identify and categorize them to the area of focus. The families are as follows:
- Access Control
- Awareness and Training
- Audit and Accountability
- Assessment, Authorization, and Monitoring
- Configuration Management
- Contingency Planning
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Physical and Environmental Protection
- Planning
- Program Management
- Personnel Security
- Personal Identifiable Information Processing and Transparency
- Risk Assessment
- System and Services Acquisition
- System and Communications Protection
- System and Information Integrity
- Supply Chain Risk Management.
Within each of these families, there are multiple different Control Identifiers that are related to the overall group. Each security control identifier has a control name, base control, discussion, related controls, control enhancements, and references. Overall, there are over 1150 security controls within these 20 different families that make up the NIST 800-53 cybersecurity framework.