NIST SP 800-53: the control catalog, checked rather than tabulated
Map the controls of NIST SP 800-53 Revision 5 to automated checks and structured evidence at the baseline you need, keep the system security plan and the assessment evidence in one place, and share the work with FedRAMP, NIST CSF and ISO 27001.
What is NIST 800-53?
NIST Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations, is the US National Institute of Standards and Technology's catalog of controls. Revision 5, published in September 2020, contains twenty control families, including access control, awareness and training, audit and accountability, configuration management, contingency planning, identification and authentication, incident response, risk assessment, system and communications protection, system and information integrity, supply chain risk management and privacy, with more than a thousand controls and control enhancements between them. A companion publication, SP 800-53B, defines the low, moderate and high baselines an organization starts from and tailors to its system. The catalog is the foundation of FISMA compliance in US federal agencies, of FedRAMP for the cloud services they buy, of many state programs, and of contractual security requirements that flow down to suppliers. There is no certificate: a system is assessed against its tailored baseline and granted an authorization to operate by an authorizing official, and the assessment evidence is what the work produces.
NIST Special Publication 800-53 is the US government's catalog of security and privacy controls for information systems and organizations. Revision 5, published in 2020, organizes the controls into twenty families, from access control and audit to supply chain risk and privacy, with low, moderate and high baselines defined in SP 800-53B. It underpins FISMA compliance for federal agencies, FedRAMP for cloud services they buy, and many state and contractual requirements. There is no 800-53 certificate; systems are assessed and authorized to operate.
Companies selling to US federal and state agencies, their contractors and suppliers, and anyone pursuing FedRAMP or a customer's 800-53-based security requirements.
How Viglyn runs NIST 800-53
- The Revision 5 catalog mapped to controls in the library, with the low, moderate or high baseline selected and tailored with our practitioners
- Technical controls checked automatically in your cloud, identity, device and code systems: access, audit logging, configuration, vulnerability, encryption, backup
- The system security plan, policies and procedures held as controlled documents with owners and review dates
- Assessment evidence organized by control, exportable with integrity hashes for an assessor or an authorizing official
- Shared evidence with NIST CSF, FedRAMP preparation, ISO 27001 and SOC 2 through the published mappings
The NIST 800-53 questions that decide it
Is NIST 800-53 a certification?
No. It is a control catalog. Systems are assessed against a tailored baseline and authorized to operate; FedRAMP adds its own authorization process on top for cloud services sold to federal agencies. What you produce is a system security plan and the assessment evidence, which Viglyn keeps organized by control.
How long does an 800-53 baseline take?
A moderate baseline is hundreds of controls, so months, not weeks, for a first assessment, though a company with ISO 27001 or SOC 2 already in place has most of the technical evidence. The system security plan and the policy set are where the time goes; our practitioners write them with you.
How much does NIST 800-53 cost with Viglyn?
NIST 800-53 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. An independent assessor's fee, where one is required, is separate and paid by you directly; we take no commission.
More NIST 800-53 questions
What is the difference between NIST 800-53 and NIST CSF?
Do we need 800-53 for FedRAMP?
What are the baselines?
See NIST 800-53 run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
