Rev 5 ยท low, moderate, high
NIST SP 800-53
800-53 is the federal control catalogue, and it is the basis of FedRAMP and of most agency Authority to Operate processes. The catalogue is large, but the work is bounded by your baseline and your system boundary, which is where the scoping conversation should start.
What the engagement covers
Federal systems and the contractors operating them. Typical timeline: 6 to 18 months, driven by baseline and boundary.
- System categorisation under FIPS 199 and selection of the right baseline
- Boundary definition, because an over broad boundary is the most expensive mistake available
- Control implementation and tailoring, with the rationale documented
- System Security Plan and the supporting body of evidence
- Assessment support and continuous monitoring once authorised
Phases
Where an engagement sits at any point, in the language your assessor uses.
- Categorisation and baseline selection
- Boundary definition and control implementation
- Assessment
- Authorisation and continuous monitoring
Related reading
- Placeholder: NIST SP 800-53 article
Pulled from the legacy archive until this section is migrated.
- Placeholder: NIST SP 800-53 article
Legacy URL preserved.
Common questions
How is this different from 800-171?
800-171 protects controlled unclassified information in nonfederal systems and has 110 requirements. 800-53 is the full federal catalogue used for federal systems, with baselines that run into the hundreds of controls. 800-171 was derived from it.
Do we need every control in the catalogue?
No. Your FIPS 199 categorisation selects a low, moderate or high baseline, and controls are tailored from there with documented rationale. Tailoring is legitimate and expected. Ignoring controls without documenting why is not.
Is this the same as FedRAMP?
FedRAMP uses 800-53 baselines, but adds programme requirements, 3PAO assessment and PMO review. You can need 800-53 without needing FedRAMP, for example for an agency specific ATO.
START HERE
Do not guess how far away you are.
A scored assessment against the NIST SP 800-53 control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, but nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.