The Control Catalog

NIST compliance is a verb. We implement controls through an array of associated and related tasks and then validate their effectiveness and related problems through their testing.

Beneath the Domain and Control, the framework's third tier is identified as its 710 "enhancements", or as in NIST 800-171 as the 110 "requirements". Third-tier objects represent the context-specific detail-level implementation. Information associated with the control's Control ID, or with the enhancement's Enhancement ID includes test plans, exceptions, Plan of Action and Milestone (POA&M) records, findings, and evidence collections. This catalog of extensible and tagged content is consumed by instances of Assessment Plans, System Security Plans, with its item records assigned or unassigned according to tailoring criteria established by the Control Baseline (800-53B) and further refined by the risk profile (800-37), boundaries (800-60), previous audit results (800-137), and the entity-based risk conditions for each assessment. 

The following image is one of the models presented by OSCAL. If this is your main area of interest, take a moment to review this outstanding OSCAL training delivered by NIST on February 2, 2021.  This link will download a PDF from nist.gov Presentation: OSCAL Content - NIST | More at Learning Resources (nist.gov)

NIST 800-53 r5 defines "security control and privacy control" as "The means of managing risk, including policies, procedures, guidelines, practices, or organizational structures, which can be of an administrative, technical, management, or legal nature." Concretely, NIST SP 800-53 r5 has 20 Domains, 298 Controls, 720 Enhancements, and 400 Supporting NISTIR, FIPS, and SP reference documents. 18 out of the 20 “Families” are defined in FIPS 200. Two of the Revision 5 families, PT - PERSONALLY IDENTIFIABLE INFORMATION PROCESSING AND TRANSPARENCY and SR - SUPPLY CHAIN RISK MANAGEMENT exist since the transition from Revision 4 to Revision 5.

“Controls” inherit naming properties from their parent domain/family. In the case of NIST 800-53, these are the 20 Control Families. Within the control families, there are 298 active (as opposed to withdrawn) controls. The number of active v. inactive controls and enhancement changes with each revision. The most recent transition from revision 4 to revision 5 added, withdrew, or substantially altered 268 controls and enhancements. The 800-53B, also known as the FedRAMP v4 is slated to update to 800-53C (FedRAMP v5) in May of 2022 with an increase of 17 or more moderate baseline controls.

OSCAL DATA MODEL

Figure: NIST OSCAL: represents the portion of the OSCAL stack as it relates to an OSCAL Assessment Results.

Mapping and Tagging

Due to the proliferation of frameworks required by any one entity, organizations often map and associate similar controls. For example, the array of system-specific requirements found in CIS Benchmarks or DISA STIGS might collectively roll up to Access Control and Configuration Control requirements at the level of NIST 800-53. We map common problems with their similar design, testing, and monitoring tasks, and maintain a dashboard to show the current state and periodic effectiveness of their aggregate environment. NIST documentation provides "crosswalks" and mapping appendixes for this reason. Companies with more detailed cloud service offerings will invest in research teams who can extend that mapping to real-time development and systems management. Generally speaking, regardless of which frameworks we use, there is an objective or control that is measured according to an assessment model. Depending on the depth of your assessment, these control objectives need to tie out to the components of any product or service designed or in use.

Most standards (reference document) have a three-tier high-general, medium-specific, low-context and technology-driven, hierarchy. For each reference document, there are major sections also known as domains or families, followed by controls, and including details known as enhancements or requirements. (See Families) 

Nationally recognized standards are expressed as a schema communicated via XML, JSON, and or YAML. The schema includes the record attributes and their relationship to each other. In the case of SP 800-53, the schema is available via NIST GitHub repository https://github.com/usnistgov and https://github.com/usnistgov/oscal-content.

SP 800-53 Family ID appears as two uppercase letters, more commonly representing two main words of the Family, such as CM for Configuration Management or AC for Access Control. With 298 Control Names, across 20 Families, the array is numbered as [:upper:][:upper:]-[:digit:]. The use of this two-letter dash number notation or Control ID tag is prevalent in STIGS, Baselines, the CSF tools, and frequently appears as mapped in appendixes within all major ISO and NIST publications.

Software and Cloud Vendors have a tall task in keeping their references and notation current, which is why this paper emphasizes using OSCAL and maintaining well-formed tags that correspond to the latest NIST referencing. SP 800-53 Rev 5.1 and SP 800-53B begins as a set of the top-level Control Families, a base hierarchy also used in the organization of SP 800-171 and SP 800 172. In the case of the online SP 800-53, the 20 Control Families link or drill to the current 298 Controls, and their 710 Enhancements. When accounting for previously withdrawn Controls and Enhancements, the full standard has 1189 elements. As of 2021, 182 SP 800-53 Controls and Enhancements are withdrawn and incorporated to other parts of the catalog since release in February of 2005.

The Control ID notation uses two letters from the Family Control Name (for example AC, IR, PT) followed by a dash and a number. Each Control has as few as zero Enhancements and currently as many as 33, as for example enhancements SA-8(33). Enhancements appear as the Control ID followed by no space and a number in parenthesis.

The following table shows Control Families in the SP 800-53 Note that each control family is linked to its CSRC record.

Table 2 NIST 800-53 Rev.5 Control Families (These are linked to their CSRC page)

Main Menu