NIST 800-53, without the spreadsheets.
Work from the control catalogue behind US federal security.
What is NIST 800-53?
NIST SP 800-53 is a catalogue of security and privacy controls for information systems, organised into 20 families. It is mandatory for US federal systems, forms the basis of FedRAMP, and is used by many other organisations as a comprehensive control reference.
Who needs it
- US federal agencies and their contractors
- Cloud providers pursuing FedRAMP
- Organisations that need a detailed control catalogue
What NIST 800-53 looks at
Access control (AC)
Account management, least privilege and session controls.
Audit and accountability (AU)
Event logging, review and protection of audit information.
Configuration management (CM)
Baselines, change control and least functionality.
Risk assessment (RA) and system integrity (SI)
Vulnerability scanning, flaw remediation and monitoring.
How Beviso gets you there
- Core controls pre-loaded across the key families, with evidence from your tools
- Shared evidence with FedRAMP, CMMC and NIST CSF
- Policy templates for family-level policies and procedures
15 NIST 800-53 controls, ready on day one
These controls are loaded when you enable NIST 800-53, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
AC-2
Account Management
Manage information system accounts, including establishing, activating, modifying, reviewing, disabling, and removing accounts.
Evidence from
- Okta
- Google Workspace
- Microsoft Azure
- AWS
- JumpCloud
- GitHub
AC-3
Access Enforcement
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
Evidence from
- Okta
- AWS
- HashiCorp Vault
- Microsoft Azure
- Cloudflare
AC-17
Remote Access
Authorize remote access sessions prior to allowing such connections. Enforce requirements for remote connections to the information system.
Evidence from
- Okta
- Cloudflare
- Duo
AU-2
Audit Events
Identify the types of events that the system is capable of logging in support of the audit function.
Evidence from
- Datadog
- AWS
- Okta
- Splunk
- HashiCorp Vault
- Salesforce
AU-6
Audit Record Review, Analysis, and Reporting
Review and analyse information system audit records for indications of inappropriate or unusual activity.
Evidence from
- Datadog
- Splunk
- Grafana
- New Relic
- AWS
CM-2
Baseline Configuration
Develop, document, and maintain a current baseline configuration of the information system.
Evidence from
- Terraform Cloud
- AWS
- Doppler
- Microsoft Azure
- GitHub
CM-6
Configuration Settings
Establish and document configuration settings for information technology products employed within the information system.
Evidence from
- Terraform Cloud
- Doppler
- AWS
- Jamf
- Kandji
IA-2
Identification and Authentication — Organizational Users
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Evidence from
- Okta
- Google Workspace
- Microsoft Azure
- AWS
- JumpCloud
- OneLogin
IA-2(1)
MFA for Privileged Accounts
Implement multi-factor authentication for access to privileged accounts.
Evidence from
- Okta
- Duo
- Microsoft Azure
- JumpCloud
- 1Password
IR-4
Incident Handling
Implement an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery.
Evidence from
- PagerDuty
- ServiceNow
- Jira
- CrowdStrike
RA-5
Vulnerability Monitoring and Scanning
Monitor and scan for vulnerabilities in the information system and hosted applications periodically.
Evidence from
- Snyk
- Wiz
- Qualys
- Rapid7
- Lacework
- GitHub
SC-7
Boundary Protection
Monitor and control communications at the external boundary of the system and at key internal boundaries.
Evidence from
- Cloudflare
- AWS
- DigitalOcean
- Hetzner
SC-28
Protection of Information at Rest
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of sensitive information at rest.
Evidence from
- HashiCorp Vault
- Doppler
- Bitwarden
- 1Password
- AWS
SI-3
Malicious Code Protection
Implement malicious code protection mechanisms at information system entry and exit points.
Evidence from
- CrowdStrike
- SentinelOne
- Jamf
- Kandji
SI-4
System Monitoring
Monitor the information system to detect attacks and indicators of potential attacks, and unauthorized local, network, and remote connections.
Evidence from
- Datadog
- Grafana
- Splunk
- AWS
- Lacework
- New Relic
NIST 800-53 questions
- Does Beviso include every 800-53 control?
- No. Beviso loads a core set covering the most commonly assessed controls and lets you add your own. The list below is exactly what is loaded today.
Often run alongside NIST 800-53
FedRAMP
Prepare your cloud service for US government authorisation.
CMMC
Protect Controlled Unclassified Information and stay eligible for defence contracts.
NIST CSF 2.0
Measure and improve your security programme against a common language.
CIS Controls v8
Start with the safeguards that stop the most common attacks.
Start your NIST 800-53 programme today.
Free while Beviso is in beta. No credit card required.
Get started free