Edge Register
Regimes ยท SP 800-53

NIST SP 800-53 Rev 5

Attaches to every site: the PE family for the premises and the alternate work site, MP for the media, AC-17, AC-19 and AC-20 for remote access, mobile devices and external systems, the CP family for the sites that lose their link, SC-7 for the boundary and SI-7 and CM-8 for what runs there.

On the register, tick "NIST SP 800-53 Rev 5" and these rows appear on every site. Source framework: NIST SP 800-53 Rev 5.

How the duties attach

ReachesEvery site.
every siteCM-8, PE-3, SI-7
site unattendedPE-6, PE-18
site publicPE-6, PE-18
site in a hostile placePE-18
link intermittentCP-8, CP-9
no linkCP-6, CP-9, CP-10
holds personal dataMP-4, MP-5
holds payment dataMP-4, MP-5, SC-7
holds health dataMP-4, MP-5
holds controlled data (CUI)MP-4, MP-5, MP-6
runs plantSC-7, SI-7
remote access namedAC-17, SC-7
Home and remote workerPE-17, AC-17, AC-19
Field and temporary siteAC-19, MP-5, AC-20
Vehicle, vessel and aircraftAC-19, MP-5
Unattended kiosk and terminalSC-7, PE-6
Ground station and telemetry siteSC-7, CP-8

The clauses, quoted

17 of 300 in the framework

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.

SP 800-53 AC-17 Remote access

Requires each type of remote access to the system to be governed by documented usage restrictions, connection and configuration requirements and implementation guidance, and to be explicitly authorized before any remote connection is permitted.

Evidence an auditor accepts: Remote access standard listing each permitted access type and its restrictions; Authorization records approving each remote access method before use; VPN or remote gateway configuration showing the required settings in force
Common gap: Vendor support tools provide a remote path that was never authorized as a remote access type
Source framework: NIST SP 800-53 Rev 5
SP 800-53 AC-19 Access control for mobile devices

Requires documented configuration settings, connection rules and implementation guidance for mobile devices the organization controls, including their use away from controlled areas, and explicit authorization before any such device connects to an organizational system.

Evidence an auditor accepts: Mobile device standard covering encryption, lock, patching and off-site use; Mobile device management enrolment report reconciled to the device inventory; Authorization records for mobile device connection to each in scope system
Common gap: Personally owned devices reach corporate mail with no enrolment or authorization
Source framework: NIST SP 800-53 Rev 5
SP 800-53 AC-20 Use of external systems

Requires terms to be established, or existing external system relationships identified, before authorized individuals may reach the system from external systems or handle organizational information on them, or alternatively requires organization-defined types of external system to be prohibited outright.

Evidence an auditor accepts: Documented terms and conditions or agreements covering permitted external system use; Register of external systems recognised as trusted and the basis for that trust; Policy statement naming external system types that are prohibited
Common gap: Terms exist on paper while unmanaged home devices connect freely in practice
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CM-8 System component inventory

Requires an accurate inventory of system components that covers every component, avoids duplicate or cross system accounting, is held at the granularity needed for tracking and reporting, carries the information the organization has defined for accountability, and is reviewed and updated on a defined frequency.

Evidence an auditor accepts: Component inventory with the defined accountability fields populated; Reconciliation of the inventory against a discovery scan or cloud asset listing; Defined review frequency and evidence of review at that cadence
Common gap: Cloud and container assets absent because inventory is built from a fixed asset register
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-6 Alternate storage site

Requires an alternate storage site to be established with the agreements needed to store and retrieve backup information, and requires that site to provide controls equivalent to those protecting the primary site.

Evidence an auditor accepts: Agreement or contract covering the alternate storage site and retrieval rights; Assessment showing site controls are equivalent to the primary site; Evidence of separation from the primary site against the identified threats
Common gap: Alternate storage shares the same power, network or hazard zone as the primary site
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-8 Telecommunications services

Requires alternate telecommunications services, with the necessary agreements, to allow defined system operations for essential functions to resume within a defined period when primary telecommunications are unavailable at either the primary or the alternate site.

Evidence an auditor accepts: Contracts for alternate telecommunications services with priority and restoration terms; Documentation of the operations they must support and within what period; Evidence of path and carrier diversity from the primary service
Common gap: Second circuit purchased from a different reseller that uses the same physical path
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-9 System backup

Requires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.

Evidence an auditor accepts: Backup schedule and success reports covering user-level, system-level and documentation backups; Encryption and access control configuration protecting backup data; Restore test records proving backups are usable
Common gap: Documentation and configuration backed up nowhere, only application data
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-10 System recovery and reconstitution

Requires the system to be recoverable and reconstitutable to a known state within an organization-defined period consistent with its recovery time and recovery point objectives after disruption, compromise or failure.

Evidence an auditor accepts: Documented recovery time and recovery point objectives for the system; Recovery procedures describing return to a known and secure state; Recovery test results showing objectives met within the defined period
Common gap: Objectives stated by the business but never tested against actual recovery times
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-4 Media storage

Requires organization-defined media types to be physically controlled and securely stored within organization-defined controlled areas, and requires that protection to continue until the media is destroyed or sanitised using approved equipment, techniques and procedures.

Evidence an auditor accepts: Defined controlled areas and the media types stored in each; Physical security evidence for the storage locations; Inventory or custody records for stored media
Common gap: Media awaiting destruction accumulates in unsecured areas for months
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-5 Media transport

Requires organization-defined media types to be protected and controlled by defined controls while in transit outside controlled areas, accountability for the media to be maintained throughout, transport activity to be documented, and transport to be carried out only by authorized personnel.

Evidence an auditor accepts: Defined media types in scope for transport and the controls applied, such as encryption or tamper evident containers; Chain of custody records for each transport movement; List of personnel authorized to transport media
Common gap: Backup media couriered with a signature on collection but no custody record in between
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-6 Media sanitization

Requires organization-defined media to be sanitised before disposal, before it leaves organizational control and before reuse, using defined techniques, with the mechanism chosen to match the sensitivity of the information the media held in strength and integrity.

Evidence an auditor accepts: Sanitisation procedure specifying technique per media type and classification; Certificates of destruction or sanitisation logs with serial numbers; Verification records confirming sanitisation was effective
Common gap: Technique chosen by convenience rather than matched to the information classification
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-3 Physical access control

Requires physical access authorizations to be enforced at defined entry and exit points by verifying authorization before entry and controlling ingress and egress with defined mechanisms or guards, physical access audit logs to be kept, publicly accessible areas to be controlled, visitors to be escorted and their activity controlled in defined circumstances, keys and combinations to be secured with inventories and changes made on defined events and frequencies.

Evidence an auditor accepts: Entry and exit point register showing the enforcement mechanism at each; Physical access audit logs from badge or guard systems; Visitor escort procedure and completed visitor logs
Common gap: Tailgating unaddressed, so an authorization check happens for only the first person through
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-6 Monitoring physical access

Requires physical access to the facility to be monitored so that physical security incidents are detected and responded to, physical access logs to be reviewed at a defined frequency and on defined events, and review and investigation results to be coordinated with the incident response capability.

Evidence an auditor accepts: Monitoring arrangements such as alarms, surveillance or guard patrols; Physical access log review records at the defined frequency; Records of event driven reviews following an incident or alarm
Common gap: Surveillance recorded but never reviewed unless something is already known to be wrong
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-17 Alternate work site

Requires the alternate work sites permitted for employees to be identified and documented, organization-defined controls to be applied at those sites, the effectiveness of those controls to be assessed, and a means to be provided for employees there to contact information security and privacy personnel about incidents.

Evidence an auditor accepts: Documented list of permitted alternate work site types and the controls required at each; Assessment records evaluating control effectiveness at alternate sites; Published contact route for security and privacy incidents from remote locations
Common gap: Home working permitted in practice with no documented control expectations
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-18 Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access

Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access

Evidence an auditor accepts: The defined physical and environmental hazards that positioning is intended to mitigate; Floor plans or location documentation showing where system components sit relative to those hazards; Rationale linking each placement decision to the hazard it mitigates and to unauthorised access opportunity
Common gap: Placement driven by available space and cabling, with the hazard rationale written afterwards
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SC-7 Boundary protection

Requires communications to be monitored and controlled at external managed interfaces and at key internal interfaces, publicly accessible components to sit in subnetworks physically or logically separated from internal networks, and connections to external networks or systems to pass only through managed interfaces built from boundary protection devices arranged per the security architecture.

Evidence an auditor accepts: Network architecture diagram identifying external and key internal managed interfaces; Firewall and gateway rule sets with review records; Evidence publicly accessible components are separated from internal networks
Common gap: Undocumented external connections such as vendor tunnels bypass the managed interfaces
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SI-7 Software, firmware, and information integrity

Requires integrity verification tools to be employed to detect unauthorized changes to organization-defined software, firmware and information, and requires organization-defined actions to be taken when such unauthorized changes are detected.

Evidence an auditor accepts: Defined list of software, firmware and information subject to integrity verification; Integrity monitoring tool configuration and coverage report; Alerts generated by integrity checks and the response records
Common gap: Integrity monitoring produces constant noise from routine change and is therefore ignored
Source framework: NIST SP 800-53 Rev 5

See what it attaches to your list

Paste the site list, tick the regime, and every site it reaches carries these rows by its exposure, link, data and plant. Eight sites free, no account.

Build my edge register