NIST SP 800-53 control families: the 20-family map
SP 800-53 organizes its controls into 20 families — from Access Control to Supply Chain Risk Management. You don't implement all of them; you implement your baseline's selection. Here's the map.
The families, grouped
- Technical: Access Control (AC), Audit and Accountability (AU), Identification and Authentication (IA), System and Communications Protection (SC), System and Information Integrity (SI).
- Operational: Configuration Management (CM), Contingency Planning (CP), Incident Response (IR), Maintenance (MA), Media Protection (MP), Physical and Environmental Protection (PE), Personnel Security (PS), System and Services Acquisition (SA).
- Management: Assessment, Authorization, and Monitoring (CA), Planning (PL), Program Management (PM), Risk Assessment (RA), Security and Privacy Governance (GV) — plus PII Processing and Transparency (PT) and Supply Chain Risk Management (SR).
Baselines: low, moderate, high
800-53 defines security control baselines — the moderate baseline is the common target for federal systems and FedRAMP. Higher baselines add controls and enhancements; tailoring adjusts the baseline to your system. Scoping the right baseline before assessment is where consultants earn their fee.
Using the catalog without drowning
Start from your baseline, not from page one. Map each selected control to an owner, an implementation statement, and evidence — that mapping is your assessment readiness. Our readiness check covers the habits that matter across every family.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.