Skip to content
Sentinel Unity
Control catalogue

NIST SP 800-53 Rev. 5: Security and Privacy Controls

The most granular control catalogue most programmes will ever import, which is exactly why it belongs in a library that maps controls to one another. Import it once and let ISO/IEC 27001, CSF functions and your own standard reference it rather than restate it.

Published by the National Institute of Standards and Technology. Used well beyond its origin as the catalogue other frameworks are cross-referenced against.

Control

Privileged access is reviewed each quarter by the system owner

PeopleProcessTechnologyDataFacility

PPTDF applicability

One owner · one procedure · one evidence trail

20

Control families

0 to 5

Maturity scored

Graded

Mapping to other standards

PPTDF

Applicability on every control

Control families

A sample of the families, and where each lands in the platform

The full catalogue lives in the library with enhancements as sub-controls. These are the families a GRC team touches most.

Access Control (AC)

Account management, least privilege, separation of duties and session control.

  • Account management
  • Least privilege
  • Separation of duties

Assessment, Authorization and Monitoring (CA)

Control assessments, plans of action and milestones, and continuous monitoring.

  • Assessments
  • POA&M
  • Continuous monitoring

Configuration Management (CM)

Baselines, change control and component inventory, which is the asset register.

  • Baselines
  • Change control
  • Inventory

Incident Response (IR)

Handling, reporting and learning, recorded as findings and loss events.

  • Handling
  • Reporting
  • Lessons learned

Risk Assessment (RA)

Categorisation, vulnerability monitoring and the assessment itself, fed from the risk register.

  • Categorisation
  • Vulnerability scanning
  • Risk assessment

Supply Chain Risk Management (SR)

Supplier assessment, provenance and notification, which runs on the third-party register.

  • Supplier assessment
  • Provenance
  • Notification

Platform mapping

Why a control catalogue this size needs a library, not a spreadsheet

Families become domains

Each family imports as a domain with its controls and enhancements beneath, navigable and reportable without flattening the structure.

Mapped, not duplicated

Where an ISO/IEC 27001 or CSF requirement is satisfied by an 800-53 control, the mapping is recorded with its grade. One test, every framework that asks.

Plans of action are findings

A POA&M item is a finding with an owner, activities, dependencies and reviewed evidence, not a separate tracker.

Continuous monitoring is indicators and control tests

Scheduled control tests and indicators with thresholds are how the monitoring family is evidenced without a manual quarterly sweep.

Baselines as company frameworks

Scope which controls apply to which entity, so a low-impact subsidiary is not assessed against a high-impact baseline.

Applicability tags

People, Process, Technology, Data and Facility tags let a remediation programme be scoped by what kind of control it is.

Maturity

How maturity is scored

Every control in the catalogue is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.

Level 0

Not Performed

The practice does not happen. Recorded as an explicit level rather than a blank.

Level 1

Performed Informally

It happens, but it depends on individuals and is neither planned nor tracked.

Level 2

Planned & Tracked

Planned, resourced, and monitored, though practice still varies between teams.

Level 3

Well Defined

A defined standard process, applied consistently across the organisation.

Level 4

Quantitatively Controlled

Measured against targets, with deviation detected from the measurements themselves.

Level 5

Continuously Improving

Improvement is fed by the measurements, changing the process rather than the reporting.

Import the catalogue once and let every other framework reference it

Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.

No commitment required. A typical demo runs 45 minutes.