• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » NIST 800-53

NIST 800-53

Definition

NIST 800-53

NIST 800-53 is the United States catalogue of security and privacy controls for federal information systems and the organisations running them. It is a catalogue, not a checklist, and selecting the applicable baseline is the work that actually matters.

That distinction defeats a lot of procurement conversations.

Nobody implements all of NIST 800-53 — the catalogue is deliberately comprehensive so that different systems, at different sensitivity levels, can draw different subsets from it.

A provider claiming to be “800-53 compliant” without naming a baseline has said very little. The meaningful question is which controls apply to your system and who operates each one.

Key takeaways

  • The full title is Security and Privacy Controls for Information Systems and Organizations.
  • Revision 5 was published in September 2020, with updates through December 2020.
  • Supply Chain Risk Management is one of the named control families.
  • Controls are selected into baselines by system impact level, not applied wholesale.

How it works

The publication is Security and Privacy Controls for Information Systems and Organizations, Revision 5, published in September 2020 with updates issued through December of that year. It organises controls into families.

Security and privacy were merged in Revision 5. Earlier revisions treated privacy controls as a separate appendix, and consolidating them reflected how the two disciplines had converged in practice.

Supply Chain Risk Management is among the named families, which is the part that speaks directly to outsourcing. Controls in that family address the risk that a supplier introduces into a system you are accountable for.

Baselines are how the catalogue becomes usable. A system is categorised by impact, and a corresponding set of controls is selected — which is why two organisations can both claim alignment and be doing quite different things.

FedRAMP is the clearest working example of that selection. The programme draws its cloud baselines from this catalogue rather than writing separate requirements, and publishes authorised services on its marketplace.

QuestionWhy it matters in outsourcing
Which baseline applies?Determines how many controls are in scope
Who operates each control?The provider, you, or both
Are privacy controls included?Revision 5 merged them into the catalogue
Is supply chain risk addressed?It is a named family, often skipped
Which revision is referenced?Contracts sometimes cite superseded ones

Ask for the control implementation summary rather than a compliance statement — the summary shows the allocation, the statement shows the marketing.

Examples

Control catalogues become real at the moment someone has to say which party operates which control, and outsourcing forces that conversation. Each example here is drawn from work that is running under contract right now.

A cloud provider inherits most infrastructure controls while the customer retains application and access controls. That allocation is the substance of the relationship.

A buyer asks a provider for its control implementation summary and finds forty controls marked customer responsibility. Those had never been assigned internally, a common compliance outsourcing gap.

An agency programme references an older revision in its contract. The provider is compliant with the cited revision and behind the current one, which is a contractual rather than technical problem.

A commercial firm adopts the catalogue voluntarily for its government outsourcing pipeline. Adopting federal controls before winning federal work is a reasonable investment.

Related terms

Control catalogues, frameworks, programmes and certifications occupy different layers that buyers routinely flatten. Every entry here defines a single thing and stops before it starts overlapping.

FAQ

What is NIST 800-53?

The United States catalogue of security and privacy controls for information systems and organisations, maintained by the National Institute of Standards and Technology.

Which revision is current?

Revision 5, published in September 2020 with updates issued through December 2020. Contracts sometimes still reference earlier revisions.

Do organisations implement every control?

No. Controls are selected into baselines according to a system’s impact level, so the applicable set varies considerably.

Can you be certified against it?

No. There is no certification scheme. Federal systems are authorised, and programmes such as FedRAMP assess against baselines drawn from it.

Does it cover supply chain risk?

Yes. Supply Chain Risk Management is a named control family, which is the part most relevant to outsourced arrangements.

How does it relate to FedRAMP?

FedRAMP draws its cloud security baselines from this catalogue rather than maintaining a separate set of control requirements.

Begin at Outsource Accelerator and map the baseline to the systems you actually run.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image