home / frameworks / nist-800-53

// U.S. frameworks that reach Canada

NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations

NIST SP 800-53 Rev. 5 is the U.S. federal catalogue of security and privacy controls, organized into 20 families. SP 800-53B selects controls into Low, Moderate, High, and privacy baselines that agencies and FedRAMP use.

United States (used internationally)

Overview

SP 800-53 is the control catalogue behind most U.S. federal security programs, and it also underpins FedRAMP, CMMC, and many state and private sector programs. Revision 5 was first published in September 2020 and merged security and privacy controls into one catalogue. Scope widened too. The controls became outcome-based, so they apply to any organization rather than only to federal agencies. The controls are grouped into 20 families, from access control to supply chain risk management, and many have optional enhancements.

NIST now issues minor releases through its Cybersecurity and Privacy Reference Tool. Release 5.2.0 came out on August 27, 2025, in response to Executive Order 14306. It added new controls and enhancements on software update and patch integrity (SA-15(13), SA-24, and SI-2(7)), revised SI-7(12), and updated guidance in several SA and SI controls. SP 800-53B, which holds the control baselines, was updated to Release 5.2.0 on the same day with no changes to the baselines themselves. Assessment procedures are in SP 800-53A.

The catalogue is used inside the NIST Risk Management Framework (SP 800-37). An agency categorizes a system as low, moderate, or high impact, selects the matching baseline, tailors it, implements and assesses the controls, and then authorizes the system to operate. FedRAMP baselines for cloud services are derived from these baselines. Canada has its own adapted version: the Canadian Centre for Cyber Security's Security and privacy controls and assurance activities catalogue (ITSP.10.033), effective March 31, 2026, supersedes ITSG-33 Annex 3A and aligns with SP 800-53 Rev. 5.

Who it applies to in Canada

U.S. federal agencies and the contractors and cloud providers that operate systems for them. Many private organizations and other governments also use the catalogue as a control reference.

Canadian cloud and software companies meet SP 800-53 through FedRAMP and U.S. federal contracts, which are built on its baselines. In Canada, the Cyber Centre's ITSP.10.033 control catalogue, effective March 31, 2026, is an adapted version of SP 800-53 Rev. 5 for Government of Canada systems.

Controls at a glance

Rev. 5 groups its controls into 20 families, shown here in 7 thematic groups, and SP 800-53B assigns them to baselines.

Access and identity (AC, IA)

  • Account management and least privilege
  • Access enforcement and information flow control
  • Remote access and wireless access controls
  • User and device identification and authentication
  • Multi-factor authentication and credential management

Monitoring and assessment (AU, CA, RA)

  • Event logging, log review, and protection of audit records
  • Control assessments, authorization, and continuous monitoring
  • Plans of action and milestones for weaknesses
  • Risk assessment and security categorization
  • Vulnerability monitoring and scanning

Configuration and maintenance (CM, MA)

  • Baseline configurations and configuration change control
  • Least functionality and software usage restrictions
  • System component inventory
  • Controlled and nonlocal maintenance

Resilience and incidents (CP, IR)

  • Contingency plans, backups, and alternate sites
  • System recovery and reconstitution
  • Incident handling, monitoring, and reporting
  • Incident response plans, training, and testing

People, physical, and media (AT, PE, PS, MP)

  • Security and privacy awareness and role-based training
  • Physical access control and monitoring of facilities
  • Environmental protections such as power and fire
  • Personnel screening, termination, and transfer
  • Media access, marking, transport, and sanitization

Program, planning, and privacy (PL, PM, PT)

  • System security and privacy plans
  • Organization-wide information security and privacy program
  • Enterprise architecture and risk management strategy
  • Authority and purpose for processing personal information
  • Privacy notices and consent

System protection and acquisition (SA, SC, SI, SR)

  • Secure development, developer testing, and acquisition terms
  • Boundary protection and cryptographic protection
  • Flaw remediation, malware protection, and system monitoring
  • Software, firmware, and information integrity
  • Supply chain risk management plans and supplier assessments

Release 5.2.0 added SA-15(13), SA-24, and SI-2(7) on update and patch integrity.

Certification and assessment

Controls are assessed with the procedures in SP 800-53A as part of the Risk Management Framework. A senior official reviews the results and grants an authorization to operate. Private organizations that adopt the catalogue usually self-assess or hire an assessor to test against a chosen baseline.

Dates to know

2020-09
SP 800-53 Rev. 5 first published, merging security and privacy controls
2025-08-27
Release 5.2.0 published, adding controls on software update and patch integrity
2025-08-27
SP 800-53B Release 5.2.0 published with no changes to the baselines
2026-03-31
Canadian Centre for Cyber Security ITSP.10.033 catalogue, adapted from SP 800-53 Rev. 5, takes effect

Resources

Official texts and free tools for NIST 800-53. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. SP 800-53 Rev. 5 publication page, NIST
  2. NIST releases revision to SP 800-53 controls, NIST
  3. SP 800-53B publication page, NIST
  4. ITSP.10.033 foreword, overview, and introduction, Canadian Centre for Cyber Security