NIST published the final version of SP 800-53 Revision 5 on September 23, 2020, the first full revision of the control catalog since Rev. 4 in 2013. The headline changes: control statements are now outcome-based and no longer name "the information system" or "the organization" as the responsible party, privacy controls are integrated into the main catalog, and a new Supply Chain Risk Management (SR) family brings the total to 20 families. The control baselines moved out into a separate publication, SP 800-53B, released October 29, 2020. Rev. 4 will be withdrawn on September 23, 2021.

If you run federal systems, you'll need to transition. If you use 800-53 as a reference framework in a private organization, Rev. 5 is worth adopting on its own merits.

What is NIST SP 800-53?

SP 800-53 is NIST's catalog of security and privacy controls. Federal agencies must use it: FIPS 200 requires federal systems to meet minimum security requirements by selecting controls from 800-53. FedRAMP builds its cloud baselines on it, and many private organizations use it as a reference framework because it's detailed, free and widely mapped to other standards.

Rev. 5 went through several drafts, including an initial public draft in August 2017 and a final public draft in March 2020. The final version also has a new title. "Security and Privacy Controls for Federal Information Systems and Organizations" became "Security and Privacy Controls for Information Systems and Organizations." Dropping "Federal" signals that NIST intends the catalog for any organization.

What changed in NIST 800-53 Rev. 5?

NIST's announcement of the final publication lists the main changes:

  • Controls are more outcome-based, with the responsible entity removed from control statements
  • Security and privacy controls are integrated into one consolidated catalog
  • A new supply chain risk management family, with supply chain considerations integrated throughout
  • New state-of-the-practice controls, for example to support cyber resiliency and secure system design
  • Clearer relationships between requirements and controls, and between security and privacy controls
  • Control selection separated from the controls themselves, with baselines and tailoring guidance moved to SP 800-53B

Outcome-based control statements

In Rev. 4, most controls began with "The organization..." or "The information system..." Rev. 5 removes that subject. Take SC-8, Transmission Confidentiality and Integrity. In Rev. 4 it opened with "The information system protects..." In Rev. 5, it simply starts with "Protect..." and goes on to the transmitted information.

It looks cosmetic, but it has a purpose. Without a named entity, the same control can be implemented by a system, by an organizational process, or by both. That makes the catalog easier for systems engineers, software developers, security architects and business owners to use, not only assessors.

It also means you have to be explicit in your own documentation about who or what satisfies each control. The catalog no longer says it for you.

Privacy controls integrated into the catalog

In Rev. 4, privacy controls sat in a separate appendix, Appendix J, with eight privacy families of their own. Rev. 5 merges privacy into the main catalog. Some privacy content was folded into existing families, and a new family was created: PII Processing and Transparency (PT). It covers:

  • PT-1 Policy and Procedures
  • PT-2 Authority to Process Personally Identifiable Information
  • PT-3 Personally Identifiable Information Processing Purposes
  • PT-4 Consent
  • PT-5 Privacy Notice
  • PT-6 System of Records Notice
  • PT-7 Specific Categories of Personally Identifiable Information
  • PT-8 Computer Matching Requirements

For security managers, the practical effect is that security and privacy now share one catalog. You'll need to agree with your privacy colleagues on who owns which controls, especially where a control serves both purposes.

The new Supply Chain Risk Management (SR) family

Rev. 4 addressed supply chain mainly through SA-12, Supply Chain Protection. Rev. 5 withdraws SA-12 and replaces it with a full family:

  • SR-1 Policy and Procedures
  • SR-2 Supply Chain Risk Management Plan
  • SR-3 Supply Chain Controls and Processes
  • SR-4 Provenance
  • SR-5 Acquisition Strategies, Tools, and Methods
  • SR-6 Supplier Assessments and Reviews
  • SR-7 Supply Chain Operations Security
  • SR-8 Notification Agreements
  • SR-9 Tamper Resistance and Detection
  • SR-10 Inspection of Systems or Components
  • SR-11 Component Authenticity
  • SR-12 Component Disposal

Supply chain considerations also appear in controls in other families. If your vendor risk program has been a questionnaire and a contract clause, the SR family gives you a much fuller model.

The 20 control families

ID Family ID Family
AC Access Control PE Physical and Environmental Protection
AT Awareness and Training PL Planning
AU Audit and Accountability PM Program Management
CA Assessment, Authorization, and Monitoring PS Personnel Security
CM Configuration Management PT PII Processing and Transparency (new)
CP Contingency Planning RA Risk Assessment
IA Identification and Authentication SA System and Services Acquisition
IR Incident Response SC System and Communications Protection
MA Maintenance SI System and Information Integrity
MP Media Protection SR Supply Chain Risk Management (new)

Note the renamed CA family. In Rev. 4 it was Security Assessment and Authorization, so update any documents or tooling that reference the old name.

Where did the baselines go?

Rev. 4 included the low, moderate and high baselines within the catalog. Rev. 5 doesn't. They now live in SP 800-53B, Control Baselines for Information Systems and Organizations, which NIST released on October 29, 2020.

SP 800-53B contains:

  • Three security control baselines, one each for low-impact, moderate-impact and high-impact systems
  • A new privacy control baseline, supporting agencies' privacy program responsibilities under OMB Circular A-130
  • Tailoring guidance and the assumptions behind the baselines

Separating the catalog from the baselines lets communities outside the federal government build their own control selections from the same catalog, without inheriting federal assumptions.

What does Rev. 5 mean for FISMA and FedRAMP systems?

Federal agencies (FISMA)

Agencies will have to move their systems to Rev. 5 and the SP 800-53B baselines. Look to OMB and your agency's own guidance for the schedule that applies to existing systems. New systems in design now are the obvious place to start with Rev. 5, since retrofitting later costs more effort.

The assessment side isn't ready yet. SP 800-53A, which contains the assessment procedures, hasn't been updated for Rev. 5. Until it is, assessors don't have official Rev. 5 procedures to work from.

Cloud service providers (FedRAMP)

FedRAMP's current baselines are based on Rev. 4. In late November 2020, FedRAMP published a transition plan with four steps:

  1. Develop draft FedRAMP baselines from the Rev. 5 updates (the current stage)
  2. Release the draft baselines for public comment
  3. Update the baselines and documentation based on comments
  4. Release the final Rev. 5 baseline documentation and an implementation plan for cloud service providers

FedRAMP also said it will update its test cases once NIST releases the final version of SP 800-53A. The plan lays out steps rather than deadlines. Until FedRAMP publishes its implementation plan, keep working to the current baselines while you start your gap analysis.

What does Rev. 5 mean for private organizations?

If no regulation requires you to use 800-53, Rev. 5 is still an improvement worth considering:

  • It's easier to apply. Outcome-based statements fit organizations whose controls are delivered by cloud services, automation and teams rather than a single system.
  • Security and privacy line up. If you're building a privacy program, the integrated catalog and PT family give security and privacy one shared control set.
  • Supply chain gets real structure. The SR family is a solid model for third-party risk, even if you implement only part of it.

A few cautions. If you're a defense contractor, your obligation is NIST SP 800-171, and Rev. 2 of 800-171 still maps to 800-53 Rev. 4. Rev. 5 doesn't change your 800-171 requirements. And if you map 800-53 to the NIST Cybersecurity Framework or ISO/IEC 27001, check which revision your mappings use. NIST said at publication that updated mappings would follow.

How should you plan the transition?

  1. Find every reference to 800-53. Policies, system security plans, control matrices, GRC tooling, audit programs and contracts.
  2. Get the catalog in usable formats. Alongside the PDF, NIST offers or has promised supplemental materials, including spreadsheet and OSCAL (machine-readable) versions of the catalog and a comparison of Revisions 4 and 5.
  3. Run a gap analysis. Identify withdrawn controls, new controls and enhancements, and changed control text.
  4. Rewrite implementation statements. State clearly whether each control is implemented by a system, a process, a common control provider or a combination.
  5. Bring in your privacy team. Agree on ownership of privacy and joint controls.
  6. Build out supply chain risk management. Start with a policy (SR-1), a plan (SR-2) and supplier assessments (SR-6).
  7. Pick baselines deliberately. Federal systems use SP 800-53B. Other organizations can use 800-53B as a reference and tailor from there.

Frequently asked questions

When will Rev. 4 be withdrawn?

NIST has said Rev. 4 will be withdrawn on September 23, 2021, one year after Rev. 5's publication.

Where are the low, moderate and high baselines now?

In SP 800-53B, published October 29, 2020, alongside a new privacy baseline.

Are there Rev. 5 assessment procedures yet?

Not yet. SP 800-53A still needs to be updated for Rev. 5, and FedRAMP has said it will update its test cases after NIST finalizes it.

Do we need to move to Rev. 5 right away?

It depends on why you use 800-53. Federal agencies and cloud service providers should follow OMB and FedRAMP direction on timing. Private organizations can move on their own schedule, and starting with a gap analysis now makes sense before Rev. 4 is withdrawn.

Key takeaways

  • NIST published SP 800-53 Rev. 5 on September 23, 2020. Rev. 4 will be withdrawn on September 23, 2021.
  • Controls are outcome-based and no longer name the responsible entity, so your documentation has to.
  • Privacy is integrated into the catalog, with the new PT family, and supply chain risk management gets its own SR family, for 20 families in total.
  • Baselines, including a new privacy baseline, are now in SP 800-53B, released October 29, 2020.
  • FedRAMP has published its transition steps but not dates. SP 800-53A hasn't been updated for Rev. 5 yet.
  • Start with an inventory of where you reference 800-53, then run a gap analysis.