Which controls are associated with the Privacy Baseline? It's a lot. In fact, there are 97 controls designated as part of Privacy in the entirety of the SP 800-53 r5 catalog.
| Control ID | Control and Enhancement Name |
| AC-1 | Policy and Procedures |
| AC-3(14) | Access Enforcement | Individual Access |
| AT-1 | Policy and Procedures |
| AT-2 | Literacy Training and Awareness |
| AT-3 | Role-based Training |
| AT-3(5) | Role-based Training | Processing Personally Identifiable Information |
| AT-4 | Training Records |
| AU-1 | Policy and Procedures |
| AU-2 | Event Logging |
| AU-3(3) | Content of Audit Records | Limit Personally Identifiable Information Elements |
| AU-11 | Audit Record Retention |
| CA-1 | Policy and Procedures |
| CA-2 | Control Assessments |
| CA-5 | Plan of Action and Milestones |
| CA-6 | Authorization |
| CA-7 | Continuous Monitoring |
| CA-7(4) | Continuous Monitoring | Risk Monitoring |
| CM-1 | Policy and Procedures |
| CM-4 | Impact Analyses |
| IR-1 | Policy and Procedures |
| IR-2 | Incident Response Training |
| IR-2(3) | Incident Response Training | Breach |
| IR-3 | Incident Response Testing |
| IR-4 | Incident Handling |
| IR-5 | Incident Monitoring |
| IR-6 | Incident Reporting |
| IR-7 | Incident Response Assistance |
| IR-8 | Incident Response Plan |
| IR-8(1) | Incident Response Plan | Breaches |
| MP-1 | Policy and Procedures |
| MP-6 | Media Sanitization |
| PE-8(3) | Visitor Access Records | Limit Personally Identifiable Information Elements |
| PL-1 | Policy and Procedures |
| PL-2 | System Security and Privacy Plans |
| PL-4 | Rules of Behavior |
| PL-4(1) | Rules of Behavior | Social Media and External Site/application Usage Restrictions |
| PL-8 | Security and Privacy Architectures |
| PL-9 | Central Management |
| PM-3 | Information Security and Privacy Resources |
| PM-4 | Plan of Action and Milestones Process |
| PM-5(1) | System Inventory | Inventory of Personally Identifiable Information |
| PM-6 | Measures of Performance |
| PM-7 | Enterprise Architecture |
| PM-8 | Critical Infrastructure Plan |
| PM-9 | Risk Management Strategy |
| PM-10 | Authorization Process |
| PM-11 | Mission and Business Process Definition |
| PM-13 | Security and Privacy Workforce |
| PM-14 | Testing, Training, and Monitoring |
| PM-17 | Protecting Controlled Unclassified Information on External Systems |
| PM-18 | Privacy Program Plan |
| PM-19 | Privacy Program Leadership Role |
| PM-20 | Dissemination of Privacy Program Information |
| PM-20(1) | Dissemination of Privacy Program Information | Privacy Policies on Websites, Applications, and Digital Services |
| PM-21 | Accounting of Disclosures |
| PM-22 | Personally Identifiable Information Quality Management |
| PM-24 | Data Integrity Board |
| PM-25 | Minimization of Personally Identifiable Information Used in Testing, Training, and Research |
| PM-26 | Complaint Management |
| PM-27 | Privacy Reporting |
| PM-28 | Risk Framing |
| PM-31 | Continuous Monitoring Strategy |
| PS-6 | Access Agreements |
| PT-1 | Policy and Procedures |
| PT-2 | Authority to Process Personally Identifiable Information |
| PT-3 | Personally Identifiable Information Processing Purposes |
| PT-4 | Consent |
| PT-5 | Privacy Notice |
| PT-5(2) | Privacy Notice | Privacy Act Statements |
| PT-6 | System of Records Notice |
| PT-6(1) | System of Records Notice | Routine Uses |
| PT-6(2) | System of Records Notice | Exemption Rules |
| PT-7 | Specific Categories of Personally Identifiable Information |
| PT-7(1) | Specific Categories of Personally Identifiable Information | Social Security Numbers |
| PT-7(2) | Specific Categories of Personally Identifiable Information | First Amendment Information |
| PT-8 | Computer Matching Requirements |
| RA-1 | Policy and Procedures |
| RA-3 | Risk Assessment |
| RA-7 | Risk Response |
| RA-8 | Privacy Impact Assessments |
| SA-1 | Policy and Procedures |
| SA-2 | Allocation of Resources |
| SA-3 | System Development Life Cycle |
| SA-4 | Acquisition Process |
| SA-8(33) | Security and Privacy Engineering Principles | Minimization |
| SA-9 | External System Services |
| SA-11 | Developer Testing and Evaluation |
| SC-7(24) | Boundary Protection | Personally Identifiable Information |
| SI-1 | Policy and Procedures |
| SI-12 | Information Management and Retention |
| SI-12(1) | Information Management and Retention | Limit Personally Identifiable Information Elements |
| SI-12(2) | Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training, and Research |
| SI-12(3) | Information Management and Retention | Information Disposal |
| SI-18 | Personally Identifiable Information Quality Operations |
| SI-18(4) | Personally Identifiable Information Quality Operations | Individual Requests |
| SI-19 | De-identification |

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics