Framework · US

NIST 800-53, without the spreadsheets.

Work from the control catalogue behind US federal security.

What is NIST 800-53?

NIST SP 800-53 is a catalogue of security and privacy controls for information systems, organised into 20 families. It is mandatory for US federal systems, forms the basis of FedRAMP, and is used by many other organisations as a comprehensive control reference.

Who needs it

  • US federal agencies and their contractors
  • Cloud providers pursuing FedRAMP
  • Organisations that need a detailed control catalogue

What NIST 800-53 looks at

Access control (AC)

Account management, least privilege and session controls.

Audit and accountability (AU)

Event logging, review and protection of audit information.

Configuration management (CM)

Baselines, change control and least functionality.

Risk assessment (RA) and system integrity (SI)

Vulnerability scanning, flaw remediation and monitoring.

How Beviso gets you there

  • Core controls pre-loaded across the key families, with evidence from your tools
  • Shared evidence with FedRAMP, CMMC and NIST CSF
  • Policy templates for family-level policies and procedures

15 NIST 800-53 controls, ready on day one

These controls are loaded when you enable NIST 800-53, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

AC-2

Account Management

Manage information system accounts, including establishing, activating, modifying, reviewing, disabling, and removing accounts.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • AWS
  • JumpCloud
  • GitHub

AC-3

Access Enforcement

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Evidence from

  • Okta
  • AWS
  • HashiCorp Vault
  • Microsoft Azure
  • Cloudflare

AC-17

Remote Access

Authorize remote access sessions prior to allowing such connections. Enforce requirements for remote connections to the information system.

Evidence from

  • Okta
  • Cloudflare
  • Duo

AU-2

Audit Events

Identify the types of events that the system is capable of logging in support of the audit function.

Evidence from

  • Datadog
  • AWS
  • Okta
  • Splunk
  • HashiCorp Vault
  • Salesforce

AU-6

Audit Record Review, Analysis, and Reporting

Review and analyse information system audit records for indications of inappropriate or unusual activity.

Evidence from

  • Datadog
  • Splunk
  • Grafana
  • New Relic
  • AWS

CM-2

Baseline Configuration

Develop, document, and maintain a current baseline configuration of the information system.

Evidence from

  • Terraform Cloud
  • AWS
  • Doppler
  • Microsoft Azure
  • GitHub

CM-6

Configuration Settings

Establish and document configuration settings for information technology products employed within the information system.

Evidence from

  • Terraform Cloud
  • Doppler
  • AWS
  • Jamf
  • Kandji

IA-2

Identification and Authentication — Organizational Users

Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • AWS
  • JumpCloud
  • OneLogin

IA-2(1)

MFA for Privileged Accounts

Implement multi-factor authentication for access to privileged accounts.

Evidence from

  • Okta
  • Duo
  • Microsoft Azure
  • JumpCloud
  • 1Password

IR-4

Incident Handling

Implement an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira
  • CrowdStrike

RA-5

Vulnerability Monitoring and Scanning

Monitor and scan for vulnerabilities in the information system and hosted applications periodically.

Evidence from

  • Snyk
  • Wiz
  • Qualys
  • Rapid7
  • Lacework
  • GitHub

SC-7

Boundary Protection

Monitor and control communications at the external boundary of the system and at key internal boundaries.

Evidence from

  • Cloudflare
  • AWS
  • DigitalOcean
  • Hetzner

SC-28

Protection of Information at Rest

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of sensitive information at rest.

Evidence from

  • HashiCorp Vault
  • Doppler
  • Bitwarden
  • 1Password
  • AWS

SI-3

Malicious Code Protection

Implement malicious code protection mechanisms at information system entry and exit points.

Evidence from

  • CrowdStrike
  • SentinelOne
  • Jamf
  • Kandji

SI-4

System Monitoring

Monitor the information system to detect attacks and indicators of potential attacks, and unauthorized local, network, and remote connections.

Evidence from

  • Datadog
  • Grafana
  • Splunk
  • AWS
  • Lacework
  • New Relic

NIST 800-53 questions

Does Beviso include every 800-53 control?
No. Beviso loads a core set covering the most commonly assessed controls and lets you add your own. The list below is exactly what is loaded today.

Start your NIST 800-53 programme today.

Free while Beviso is in beta. No credit card required.

Get started free