As quickly as I save this it will be out of date, but it's here to make an important point. Most people think they can "do NIST" by downloading the SP 800-53 r5 and using it like an ingredients list. They are very wrong. The process to earn Government Certifications is arduous and complex. There are distinct roles in who and how you prepare for attaining authority to operate, ATO. Even this table, which is embedded in several templates includes out-of-date references. For example, NIST SP 800-54 r4 is obsolete and no typo is going to change that. The SP 800-53A released a substantial new version this week. Many people confuse the NIST SP 800-53A R5 is here with the 800-53B and so will likely miss this positively critical new resource.
|
FedRAMP References for 800-53 High Impact May 21, 2021
|
In Package - Tabs 2 and 3
|
|||||||||
| Requirement Type | Document Link | Title | Date | SSP | SAP | SAR | PIA/PTA | ISCP | FIPS 199 | |
| Standards and Guidance | FIPS 140-2 | Security Requirements for Cryptographic Modules | May 2001 | x | x | x | x | |||
| Standards and Guidance | FIPS 140-3 | Security Requirements for Cryptographic Modules (supersedes FIPS PUB 140-2). This standard becomes effective six months after approval. | March 2019 | x | x | x | x | |||
| Standards and Guidance | FIPS 199 | Standards for Security Categorization of Federal Information and Information Systems | February 2004 | x | x | x | x |
Federal Government Data
|
||
| Standards and Guidance | FIPS 200 | Minimum Security Requirements for Federal Information and Information Systems | March 2006 | x | x | x | x |
Federal Government Data
|
||
| Standards and Guidance | FIPS 201-2 | Personal Identity Verification (PIV) of Federal Employees and Contractors | August 2013 | x | x | x | x | x |
Federal Government Data
|
|
| Standards and Guidance | SP 800-18 | Guide for Developing Security Plans for Federal Information Systems, Revision 1 | February 2006 | x | x | x | x | x |
Federal Government Data
|
|
| Standards and Guidance | SP 800-30 | Guide for Conducting Risk Assessments, Revision 1 | September 2012 | x | x | x | x | x | ||
| Standards and Guidance | SP 800-34 | Contingency Planning Guide for Federal Information Systems, Revision 1 [includes updates as of 11-11-10] | May 2010 | x | x | x | x | x |
Federal Government Data
|
|
| Standards and Guidance | SP 800-37 | Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, Revision 2 | December 2018 | x | x | x | x | x | ||
| Standards and Guidance | SP 800-39 | Managing Information Security Risk: Organization, Mission, and Information System View | March 2011 | x | x | x | ||||
| Standards and Guidance | SP 800-47 | Security Guide for Interconnecting Information Technology Systems | August 2002 | x | ||||||
| Standards and Guidance | SP 800-53 | Security and Privacy Controls for Federal Information Systems and Organizations, Revision 4 [includes updates as of 1/22/2015] | April 2013 | x | x | x | x | x | x |
Federal Government Data
|
| Standards and Guidance | SP 800-53A WITHDRAWN New SP 800-53A Rev. 5 | Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans, Revision 4 [includes updates as of 12/18/2014] replaced by Assessing Security and Privacy Controls in Info Sys and Orgs | CSRC (nist.gov) | December 2014 new release 1/25/2022 | x | x | x | x | x |
Federal Government Data
|
|
| Standards and Guidance | SP 800-60 Vol I | Volume I: Guide for Mapping Types of Information Systems to Security Categories, Revision 1 | August 2008 | x | x | x | ||||
| Standards and Guidance | SP 800-60 Vol II | Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Revision 1 | August 2008 | x | x | x | ||||
| Standards and Guidance | SP 800-61 | Computer Security Incident Handling Guide, Revision 2 | August 2012 | x | x | x | ||||
| Standards and Guidance | SP 800-63-3 | Digital Identity Guidelines, Revision 3 [includes updates as of 12/1/2017] | June 2017 | x | ||||||
| Standards and Guidance | SP 800-115 | Technical Guide to Information Security Testing and Assessment | September 2008 | x | x | x | x | |||
| Standards and Guidance | SP 800-122 | Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) | April 2010 | x | ||||||
| Standards and Guidance | SP 800-128 | Guide for Security-Focused Configuration Management of Information Systems | August 2011 | x | x | x | ||||
| Standards and Guidance | SP 800-137 | Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations | September 2011 | x | x | x |
Federal Government Data
|
|||
| Standards and Guidance | SP 800-144 | Guidelines on Security and Privacy in Public Cloud Computing | December 2011 | x | x | |||||
| Standards and Guidance | SP 800-145 | The NIST Definition of Cloud Computing | September 2011 | x | x | x | ||||
| Standards and Guidance | SP 800-160 Vol I | Systems Security Engineering, Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems [updated March 2018] | November 2016 | x | x | x | ||||
| Standards and Guidance | FTC Privacy Online | Privacy Online: Fair Information Practices in the Electronic Marketplace: A Federal Trade Commission Report to Congress | May 2000 | x | ||||||
| Standards and Guidance | NARA 2010-05 | Guidance on Managing Records in Cloud Computing Environments | September 2010 | x | x | |||||
| Laws and Regulations | 44 USC 31 | Title 44 Public Printing and Documents; Chapter 31 Records Management by Federal Agencies; Sections 3101 through 3107 | As amended | x | x | x | x |
Federal Government Data
|
||
| Laws and Regulations | 5 USC 552a | Title 5 Government Organization and Employees; Chapter 5 Administrative Procedure; Section 552a Records maintained on individuals | As amended | x | x | x | x |
Federal Government Data
|
||
| Laws and Regulations | HSPD-12 | Homeland Security Presidential Directive 12: Policy for a Common Identification Standard for Federal Employees and Contractors | August 2004 | x | x |
Federal Government Data
|
||||
| Laws and Regulations | HSPD-7 | Homeland Security Presidential Directive 7: Critical Infrastructure Identification, Prioritization, and Protection | December 2003 | x | x | x | ||||
| Laws and Regulations | OMB A-108 | Federal Agency Responsibilities for Maintaining Records About Individuals (Reissuance) | December 2016 | x | x |
Federal Government Data
|
||||
| Laws and Regulations | OMB A-123 | Management’s Responsibility for Enterprise Risk Management and Internal Control | July 2016 | x | x | x | ||||
| Laws and Regulations | OMB A-130 | Managing Information as a Strategic Resource | July 2016 | x | x | x | x | x | x | |
| Laws and Regulations | OMB M-01-05 | Guidance on Inter-Agency Sharing of Personal Data – Protecting Personal Privacy | December 2000 | x | x | x | x |
Federal Government Data
|
||
| Laws and Regulations | OMB M-03-22 | OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002 | September 2003 | x | ||||||
| Laws and Regulations | OMB M-17-12 | Preparing for and Responding to a Breach of Personally Identifiable Information (PII) | January 2017 | x | ||||||
| Laws and Regulations | OMB M-10-23 | Guidance for Agency Use of Third-Party Websites and Applications | June 2010 | x |
Federal Government Data
|
|||||
| Laws and Regulations | OMB M-99-18 | Privacy Policies on Federal Web Sites | June 1999 | x |
Federal Government Data
|
|||||
| Laws and Regulations | PL 99-474 | Computer Fraud and Abuse Act of 1986, 18 USC 1030 | As amended | x | x | x | x | |||
| Laws and Regulations | PL 100-503 | Computer Matching and Privacy Protection Act of 1988 | As amended | x | x | |||||
| Laws and Regulations | PL 104-191 | Health Insurance Portability and Accountability Act of 1996 (HIPAA) | As amended | x | ||||||
| Laws and Regulations | PL 104-231 | Electronic Freedom of Information Act Amendments of 1996 | As amended | x | x | x | x | x | ||
| Laws and Regulations | PL 107-56 | USA Patriot Act (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism) | As amended | x | ||||||
| Laws and Regulations | PL 107-347 | E-Government Act of 2002 - Federal Information Security Management Act (FISMA) of 2002, Title III | As amended | x | x | x | x | x | x |
Federal Government Data
|
| Laws and Regulations | PL 107-347 | E-Government Act of 2002 - Section 208. Privacy provisions. | As amended | x | x | x | x | x | x |
Federal Government Data
|
| Laws and Regulations | PL 107-347 | E-Government Act of 2002 - Confidential Information Protection and Statistical Efficiency Act of 2002 (CIPSEA), Title V | As amended | x | x | x | x | x | x |
Federal Government Data
|
| Laws and Regulations | PL 108-447 | Consolidated Appropriations Act, 2005, Section 522, a-e | As amended | x | ||||||
| Laws and Regulations | PL 113-187 | The Presidential and Federal Records Act Amendments of 2014 | As amended | x |
Federal Government Data
|
|||||
| Laws and Regulations | PL 113-283 | Federal Information Security Modernization Act (FISMA) of 2014 | As amended | x | x | x | x | x | x |
Federal Government Data
|
| Laws and Regulations | NARA 44 USC | 44 U.S.C. Federal Records Act, Chapters 21, 29, 31, 33 (see Public Law 113-187) | As amended | x |
Federal Government Data
|
|||||
| Laws and Regulations | FTC Sec-5 | Federal Trade Commission Act Section 5: Unfair or Deceptive Acts or Practices | June 2008 | x | ||||||
| Laws and Regulations | e-CFR data | Title 36, Code of Federal Regulations, Chapter XII, Subchapter B | As amended | x |
Federal Government Data
|
|||||
| Laws and Regulations | NCSL | State Laws Related to Internet Privacy | February 2019 | x | x | |||||

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics