NIST SP 800-53 Rev 5
Attaches to every site: the PE family for the premises and the alternate work site, MP for the media, AC-17, AC-19 and AC-20 for remote access, mobile devices and external systems, the CP family for the sites that lose their link, SC-7 for the boundary and SI-7 and CM-8 for what runs there.
On the register, tick "NIST SP 800-53 Rev 5" and these rows appear on every site. Source framework: NIST SP 800-53 Rev 5.
How the duties attach
| Reaches | Every site. |
|---|---|
| every site | CM-8, PE-3, SI-7 |
| site unattended | PE-6, PE-18 |
| site public | PE-6, PE-18 |
| site in a hostile place | PE-18 |
| link intermittent | CP-8, CP-9 |
| no link | CP-6, CP-9, CP-10 |
| holds personal data | MP-4, MP-5 |
| holds payment data | MP-4, MP-5, SC-7 |
| holds health data | MP-4, MP-5 |
| holds controlled data (CUI) | MP-4, MP-5, MP-6 |
| runs plant | SC-7, SI-7 |
| remote access named | AC-17, SC-7 |
| Home and remote worker | PE-17, AC-17, AC-19 |
| Field and temporary site | AC-19, MP-5, AC-20 |
| Vehicle, vessel and aircraft | AC-19, MP-5 |
| Unattended kiosk and terminal | SC-7, PE-6 |
| Ground station and telemetry site | SC-7, CP-8 |
The clauses, quoted
17 of 300 in the frameworkRequirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.
SP 800-53 AC-17 Remote accessRequires each type of remote access to the system to be governed by documented usage restrictions, connection and configuration requirements and implementation guidance, and to be explicitly authorized before any remote connection is permitted.
Common gap: Vendor support tools provide a remote path that was never authorized as a remote access type
Source framework: NIST SP 800-53 Rev 5
SP 800-53 AC-19 Access control for mobile devicesRequires documented configuration settings, connection rules and implementation guidance for mobile devices the organization controls, including their use away from controlled areas, and explicit authorization before any such device connects to an organizational system.
Common gap: Personally owned devices reach corporate mail with no enrolment or authorization
Source framework: NIST SP 800-53 Rev 5
SP 800-53 AC-20 Use of external systemsRequires terms to be established, or existing external system relationships identified, before authorized individuals may reach the system from external systems or handle organizational information on them, or alternatively requires organization-defined types of external system to be prohibited outright.
Common gap: Terms exist on paper while unmanaged home devices connect freely in practice
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CM-8 System component inventoryRequires an accurate inventory of system components that covers every component, avoids duplicate or cross system accounting, is held at the granularity needed for tracking and reporting, carries the information the organization has defined for accountability, and is reviewed and updated on a defined frequency.
Common gap: Cloud and container assets absent because inventory is built from a fixed asset register
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-6 Alternate storage siteRequires an alternate storage site to be established with the agreements needed to store and retrieve backup information, and requires that site to provide controls equivalent to those protecting the primary site.
Common gap: Alternate storage shares the same power, network or hazard zone as the primary site
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-8 Telecommunications servicesRequires alternate telecommunications services, with the necessary agreements, to allow defined system operations for essential functions to resume within a defined period when primary telecommunications are unavailable at either the primary or the alternate site.
Common gap: Second circuit purchased from a different reseller that uses the same physical path
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-9 System backupRequires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.
Common gap: Documentation and configuration backed up nowhere, only application data
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-10 System recovery and reconstitutionRequires the system to be recoverable and reconstitutable to a known state within an organization-defined period consistent with its recovery time and recovery point objectives after disruption, compromise or failure.
Common gap: Objectives stated by the business but never tested against actual recovery times
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-4 Media storageRequires organization-defined media types to be physically controlled and securely stored within organization-defined controlled areas, and requires that protection to continue until the media is destroyed or sanitised using approved equipment, techniques and procedures.
Common gap: Media awaiting destruction accumulates in unsecured areas for months
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-5 Media transportRequires organization-defined media types to be protected and controlled by defined controls while in transit outside controlled areas, accountability for the media to be maintained throughout, transport activity to be documented, and transport to be carried out only by authorized personnel.
Common gap: Backup media couriered with a signature on collection but no custody record in between
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-6 Media sanitizationRequires organization-defined media to be sanitised before disposal, before it leaves organizational control and before reuse, using defined techniques, with the mechanism chosen to match the sensitivity of the information the media held in strength and integrity.
Common gap: Technique chosen by convenience rather than matched to the information classification
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-3 Physical access controlRequires physical access authorizations to be enforced at defined entry and exit points by verifying authorization before entry and controlling ingress and egress with defined mechanisms or guards, physical access audit logs to be kept, publicly accessible areas to be controlled, visitors to be escorted and their activity controlled in defined circumstances, keys and combinations to be secured with inventories and changes made on defined events and frequencies.
Common gap: Tailgating unaddressed, so an authorization check happens for only the first person through
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-6 Monitoring physical accessRequires physical access to the facility to be monitored so that physical security incidents are detected and responded to, physical access logs to be reviewed at a defined frequency and on defined events, and review and investigation results to be coordinated with the incident response capability.
Common gap: Surveillance recorded but never reviewed unless something is already known to be wrong
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-17 Alternate work siteRequires the alternate work sites permitted for employees to be identified and documented, organization-defined controls to be applied at those sites, the effectiveness of those controls to be assessed, and a means to be provided for employees there to contact information security and privacy personnel about incidents.
Common gap: Home working permitted in practice with no documented control expectations
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-18 Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized accessLocation of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access
Common gap: Placement driven by available space and cabling, with the hazard rationale written afterwards
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SC-7 Boundary protectionRequires communications to be monitored and controlled at external managed interfaces and at key internal interfaces, publicly accessible components to sit in subnetworks physically or logically separated from internal networks, and connections to external networks or systems to pass only through managed interfaces built from boundary protection devices arranged per the security architecture.
Common gap: Undocumented external connections such as vendor tunnels bypass the managed interfaces
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SI-7 Software, firmware, and information integrityRequires integrity verification tools to be employed to detect unauthorized changes to organization-defined software, firmware and information, and requires organization-defined actions to be taken when such unauthorized changes are detected.
Common gap: Integrity monitoring produces constant noise from routine change and is therefore ignored
Source framework: NIST SP 800-53 Rev 5
See what it attaches to your list
Paste the site list, tick the regime, and every site it reaches carries these rows by its exposure, link, data and plant. Eight sites free, no account.
Build my edge register