Governance, risk & compliance
NIST SP 800-53 - Security and Privacy Controls Rev. 5
The catalogue that most other North American frameworks are derived from.
Twenty control families, and three baselines selected by the impact level of the system: Low (149 controls), Moderate (287), and High (370). Mandatory for US federal systems through FIPS 200 and the Risk Management Framework, and adopted voluntarily by state, municipal, and private organizations that want one control set their auditors already recognize.
Two families - Program Management (PM) and PII Processing and Transparency (PT) - are not assigned to a baseline; they are selected from organizational governance and privacy needs. Pick the baseline that matches the worst outcome if the system were compromised, not the one that looks achievable.
Assessment tiers & levels Lavawall supports
Lavawall assesses NIST SP 800-53 - Security and Privacy Controls at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Low Baseline | For systems where loss of confidentiality, integrity, or availability would have a limited adverse effect. 149 controls. The right starting point for a municipal system that holds no criminal justice information, no health information, and nothing whose loss would disrupt a service people depend on. | Yes |
| Moderate Baseline | For systems where the loss would have a serious adverse effect - significant financial loss, significant harm to individuals short of loss of life, or major degradation of a service. 287 controls. Where most municipal systems holding resident personal information actually belong, and the baseline CJIS effectively assumes. | Yes |
| High Baseline | For systems where the loss would have a severe or catastrophic adverse effect - loss of life, major damage to assets, or an inability to carry out a primary function. 370 controls. Emergency dispatch, water treatment control systems, and anything a life-safety service depends on. | Yes |
How Lavawall® helps you get to NIST SP 800-53 - Security and Privacy Controls compliance
Most of NIST SP 800-53 - Security and Privacy Controls comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to NIST SP 800-53 - Security and Privacy Controls, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against NIST SP 800-53 - Security and Privacy Controls in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports NIST SP 800-53 - Security and Privacy Controls as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- NIST SP 800-53 - Security and Privacy Controls Rev. 5
- Category
- Security
- Region
- Global
- Levels
- 3 assessment tiers
Map this framework freeTalk to our team