Skip to content

    NIST CSF 2.0 to NIST SP 800-53 Rev 5 control mapping

    NIST CSF 2.0 maps to 233 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the NIST CSF 2.0 controls that map to it.

    Shared NIST 800-53 controls
    233
    NIST CSF 2.0 controls involved
    106
    NIST 800-53 families touched
    20

    How this pairing is derived

    NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored NIST CSF 2.0 to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls that NIST CSF 2.0 maps to, with the NIST CSF 2.0 controls that map to each one.
    NIST 800-53 controlFamilyNIST CSF 2.0 controls
    AC-1Policy and ProceduresACAccess ControlGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05
    AC-2(7)Privileged User AccountsACAccess ControlPR.AA-05
    AC-2(12)Account Monitoring for Atypical UsageACAccess ControlDE.CM-03
    AC-4(25)Data SanitizationACAccess ControlID.AM-07
    AC-5Separation of DutiesACAccess ControlPR.AA-05
    AC-6Least PrivilegeACAccess ControlPR.AA-05, PR.DS-10
    AC-20Use of External SystemsACAccess ControlID.AM-04
    AT-1Policy and ProceduresATAwareness and TrainingGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03
    AT-2Literacy Training and AwarenessATAwareness and TrainingPR.AT-01
    AT-2(2)Insider ThreatATAwareness and TrainingID.RA-03
    AT-2(6)Cyber Threat EnvironmentATAwareness and TrainingPR.AT-01, PR.AT-02
    AT-3Role-based TrainingATAwareness and TrainingPR.AT-01, PR.AT-02
    AT-3(2)Physical Security ControlsATAwareness and TrainingPR.AT-01, PR.AT-02
    AU-1Policy and ProceduresAUAudit and AccountabilityDE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-04
    AU-2Event LoggingAUAudit and AccountabilityDE.AE-03, DE.AE-06, DE.CM-01
    AU-3Content of Audit RecordsAUAudit and AccountabilityPR.PS-04
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and AccountabilityDE.AE-03, DE.AE-06
    AU-6(3)Correlate Audit Record RepositoriesAUAudit and AccountabilityDE.AE-03, DE.AE-06
    AU-6(9)Correlation with Information from Nontechnical SourcesAUAudit and AccountabilityDE.AE-03, DE.AE-06
    AU-10(3)Chain of CustodyAUAudit and AccountabilityRS.AN-06, RS.AN-07
    CA-1Policy and ProceduresCAAssessment, Authorization, and MonitoringGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.RA-01
    CA-2Control AssessmentsCAAssessment, Authorization, and MonitoringID.IM-01, ID.IM-02, ID.RA-01
    CA-5Plan of Action and MilestonesCAAssessment, Authorization, and MonitoringID.IM-01, ID.IM-02, ID.RA-01
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringGV.OC-03
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringGV.OC-03
    CM-1Policy and ProceduresCMConfiguration ManagementGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-01, PR.PS-05
    CM-2Baseline ConfigurationCMConfiguration ManagementPR.DS-10, PR.PS-05
    CM-3Configuration Change ControlCMConfiguration ManagementID.RA-07
    CM-3(1)Automated Documentation, Notification, and Prohibition of ChangesCMConfiguration ManagementID.RA-07
    CM-3(2)Testing, Validation, and Documentation of ChangesCMConfiguration ManagementID.RA-07
    CM-3(7)Review System ChangesCMConfiguration ManagementID.RA-07
    CM-4Impact AnalysesCMConfiguration ManagementID.RA-07
    CM-5Access Restrictions for ChangeCMConfiguration ManagementID.RA-07
    CM-6Configuration SettingsCMConfiguration ManagementPR.DS-10, PR.PS-05
    CM-7Least FunctionalityCMConfiguration ManagementPR.PS-05
    CM-7(2)Prevent Program ExecutionCMConfiguration ManagementPR.PS-05
    CM-8System Component InventoryCMConfiguration ManagementID.AM-01, ID.AM-02
    CM-9Configuration Management PlanCMConfiguration ManagementPR.PS-01, PR.PS-05
    CM-11User-installed SoftwareCMConfiguration ManagementPR.PS-05
    CM-11(2)Software Installation with Privileged StatusCMConfiguration ManagementPR.PS-05
    CP-1Policy and ProceduresCPContingency PlanningGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05
    CP-2Contingency PlanCPContingency PlanningGV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05
    CP-2(2)Capacity PlanningCPContingency PlanningPR.IR-04
    CP-2(3)Resume Mission and Business FunctionsCPContingency PlanningRC.RP-02, RC.RP-04
    CP-2(7)Coordinate with External Service ProvidersCPContingency PlanningGV.SC-08
    CP-2(8)Identify Critical AssetsCPContingency PlanningGV.OC-04, GV.OC-05, ID.AM-05, RC.RP-02, RC.RP-04
    CP-4Contingency Plan TestingCPContingency PlanningID.IM-02, ID.IM-03
    CP-6(2)Recovery Time and Recovery Point ObjectivesCPContingency PlanningRC.RP-02, RC.RP-04
    CP-9System BackupCPContingency PlanningPR.DS-11
    CP-9(1)Testing for Reliability and IntegrityCPContingency PlanningPR.DS-11
    CP-9(2)Test Restoration Using SamplingCPContingency PlanningPR.DS-11
    CP-9(5)Transfer to Alternate Storage SiteCPContingency PlanningPR.DS-11
    CP-10System Recovery and ReconstitutionCPContingency PlanningGV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-01, RC.RP-02, RC.RP-04, RC.RP-05, RS.MA-05
    CP-10(6)Component ProtectionCPContingency PlanningRC.RP-03
    IA-1Policy and ProceduresIAIdentification and AuthenticationGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05
    IA-2Identification and Authentication (Organizational Users)IAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-05
    IA-2(8)Access to Accounts — Replay ResistantIAIdentification and AuthenticationPR.AA-04
    IA-3Device Identification and AuthenticationIAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-05
    IA-3(1)Cryptographic Bidirectional AuthenticationIAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-05
    IA-3(4)Device AttestationIAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-05
    IA-4Identifier ManagementIAIdentification and AuthenticationPR.AA-03, PR.AA-04, PR.AA-05
    IA-4(4)Identify User StatusIAIdentification and AuthenticationPR.AA-03, PR.AA-04, PR.AA-05
    IA-8Identification and Authentication (Non-organizational Users)IAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-05
    IA-9Service Identification and AuthenticationIAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-05
    IA-12Identity ProofingIAIdentification and AuthenticationPR.AA-02
    IR-1Policy and ProceduresIRIncident ResponseGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-02, ID.IM-03, ID.IM-04, RS.AN-03
    IR-4Incident HandlingIRIncident ResponseDE.AE-02, DE.AE-03, DE.AE-04, DE.AE-06, DE.AE-08, GV.SC-08, RC.CO-03, RC.RP-06, RS.AN-06, RS.CO-02, RS.CO-03, RS.MA-01, RS.MA-02, RS.MA-04, RS.MI-01, RS.MI-02
    IR-4(3)Continuity of OperationsIRIncident ResponseDE.AE-02, DE.AE-04, DE.AE-06, DE.AE-08, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.AN-08, RS.MA-03, RS.MA-05
    IR-4(4)Information CorrelationIRIncident ResponseDE.AE-03, DE.AE-06
    IR-4(8)Correlation with External OrganizationsIRIncident ResponseDE.AE-03, GV.SC-08, RS.MA-01
    IR-4(10)Supply Chain CoordinationIRIncident ResponseGV.SC-08, RS.CO-02, RS.CO-03
    IR-4(11)Integrated Incident Response TeamIRIncident ResponseDE.AE-06, RS.MA-01, RS.MA-04
    IR-4(12)Malicious Code and Forensic AnalysisIRIncident ResponseID.IM-02, ID.IM-03, RS.AN-03, RS.AN-06, RS.AN-07
    IR-4(13)Behavior AnalysisIRIncident ResponseDE.CM-03
    IR-4(15)Public Relations and Reputation RepairIRIncident ResponseRC.CO-04
    IR-5Incident MonitoringIRIncident ResponseDE.AE-06, RC.RP-06, RS.AN-06
    IR-6Incident ReportingIRIncident ResponseDE.AE-06, RC.CO-03, RS.CO-02, RS.CO-03, RS.MA-01
    IR-6(2)Vulnerabilities Related to IncidentsIRIncident ResponseID.IM-02, ID.IM-03, RS.AN-03
    IR-6(3)Supply Chain CoordinationIRIncident ResponseRS.CO-02, RS.CO-03
    IR-8Incident Response PlanIRIncident ResponseDE.AE-06, ID.IM-04, RS.MA-01, RS.MA-02, RS.MA-04
    MA-1Policy and ProceduresMAMaintenanceGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-02, PR.PS-03
    MA-2Controlled MaintenanceMAMaintenancePR.PS-02, PR.PS-03
    MA-6Timely MaintenanceMAMaintenancePR.PS-02, PR.PS-03
    MA-6(1)Preventive MaintenanceMAMaintenancePR.PS-02, PR.PS-03
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionDE.CM-02, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-06, PR.IR-02
    PE-2Physical Access AuthorizationsPEPhysical and Environmental ProtectionPR.AA-06
    PE-2(1)Access by Position or RolePEPhysical and Environmental ProtectionPR.AA-06
    PE-3Physical Access ControlPEPhysical and Environmental ProtectionDE.CM-02, PR.AA-06
    PE-3(2)Facility and SystemsPEPhysical and Environmental ProtectionDE.CM-02, PR.AA-06
    PE-3(3)Continuous GuardsPEPhysical and Environmental ProtectionDE.CM-02, PR.AA-06
    PE-6Monitoring Physical AccessPEPhysical and Environmental ProtectionDE.CM-02
    PE-8Visitor Access RecordsPEPhysical and Environmental ProtectionDE.CM-02
    PE-9Power Equipment and CablingPEPhysical and Environmental ProtectionPR.IR-02
    PE-13Fire ProtectionPEPhysical and Environmental ProtectionPR.IR-02
    PE-14Environmental ControlsPEPhysical and Environmental ProtectionPR.IR-02
    PE-15Water Damage ProtectionPEPhysical and Environmental ProtectionPR.IR-02
    PE-22Component MarkingPEPhysical and Environmental ProtectionID.AM-05
    PE-23Facility LocationPEPhysical and Environmental ProtectionDE.CM-02, GV.SC-06, PR.AA-06, PR.IR-02
    PL-1Policy and ProceduresPLPlanningGV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-03, GV.SC-01, GV.SC-03, GV.SC-05, ID.RA-09, PR.PS-06
    PL-2System Security and Privacy PlansPLPlanningID.AM-03
    PL-8Security and Privacy ArchitecturesPLPlanningPR.IR-01, PR.IR-03
    PL-9Central ManagementPLPlanningGV.RM-05, GV.RR-01, GV.RR-02
    PL-10Baseline SelectionPLPlanningPR.DS-10, PR.PS-05
    RA-1Policy and ProceduresRARisk AssessmentGV.OV-01, GV.OV-02, GV.OV-03, GV.PO-01, GV.PO-02, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09
    RA-2Security CategorizationRARisk AssessmentID.RA-04
    RA-2(1)Impact-level PrioritizationRARisk AssessmentID.RA-05, ID.RA-06
    RA-3Risk AssessmentRARisk AssessmentGV.RM-06, ID.IM-01, ID.IM-02, ID.RA-01, ID.RA-04, ID.RA-05
    RA-3(1)Supply Chain Risk AssessmentRARisk AssessmentGV.SC-09
    RA-5Vulnerability Monitoring and ScanningRARisk AssessmentID.RA-01
    RA-7Risk ResponseRARisk AssessmentGV.RM-04, ID.RA-05, ID.RA-06
    RA-8Privacy Impact AssessmentsRARisk AssessmentID.RA-04
    RA-9Criticality AnalysisRARisk AssessmentGV.OC-04, GV.OC-05, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, ID.AM-05, ID.RA-04, ID.RA-10, PR.PS-06
    RA-10Threat HuntingRARisk AssessmentID.RA-03
    SA-1Policy and ProceduresSASystem and Services AcquisitionGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.RA-09, PR.PS-06
    SA-2Allocation of ResourcesSASystem and Services AcquisitionGV.RR-03
    SA-3System Development Life CycleSASystem and Services AcquisitionGV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-3(1)Manage Preproduction EnvironmentSASystem and Services AcquisitionGV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-3(3)Technology RefreshSASystem and Services AcquisitionGV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-4Acquisition ProcessSASystem and Services AcquisitionGV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10, ID.RA-09, PR.PS-06
    SA-4(1)Functional Properties of ControlsSASystem and Services AcquisitionID.AM-03
    SA-4(2)Design and Implementation Information for ControlsSASystem and Services AcquisitionID.AM-03
    SA-4(3)Development Methods, Techniques, and PracticesSASystem and Services AcquisitionPR.PS-06
    SA-4(8)Continuous Monitoring Plan for ControlsSASystem and Services AcquisitionID.IM-01, ID.IM-02
    SA-4(12)Data OwnershipSASystem and Services AcquisitionID.AM-08
    SA-5System DocumentationSASystem and Services AcquisitionID.AM-05
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services AcquisitionPR.DS-10, PR.IR-01, PR.IR-03, PR.PS-05
    SA-8(14)Least PrivilegeSASystem and Services AcquisitionPR.AA-05, PR.DS-10
    SA-8(30)Procedural RigorSASystem and Services AcquisitionGV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-8(31)Secure System ModificationSASystem and Services AcquisitionID.RA-07
    SA-9External System ServicesSASystem and Services AcquisitionGV.SC-06, GV.SC-07, ID.AM-04
    SA-9(1)Risk Assessments and Organizational ApprovalsSASystem and Services AcquisitionGV.SC-06, GV.SC-07, ID.IM-01, ID.IM-02, ID.RA-10
    SA-9(3)Establish and Maintain Trust Relationship with ProvidersSASystem and Services AcquisitionGV.OC-02, GV.OC-04, GV.OC-05, GV.RM-05, GV.RR-02, GV.SC-01, GV.SC-02, GV.SC-03, GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-09, GV.SC-10, ID.AM-05, ID.RA-10
    SA-9(4)Consistent Interests of Consumers and ProvidersSASystem and Services AcquisitionGV.SC-06
    SA-9(5)Processing, Storage, and Service LocationSASystem and Services AcquisitionGV.SC-06, ID.AM-03
    SA-9(8)Processing and Storage Location — U.S. JurisdictionSASystem and Services AcquisitionID.AM-03
    SA-10Developer Configuration ManagementSASystem and Services AcquisitionID.RA-09
    SA-10(1)Software and Firmware Integrity VerificationSASystem and Services AcquisitionID.RA-09
    SA-10(3)Hardware Integrity VerificationSASystem and Services AcquisitionID.RA-09
    SA-11Developer Testing and EvaluationSASystem and Services AcquisitionID.IM-01, ID.IM-02, ID.RA-01, PR.PS-06
    SA-11(2)Threat Modeling and Vulnerability AnalysesSASystem and Services AcquisitionGV.OC-01, PR.PS-06
    SA-11(5)Penetration TestingSASystem and Services AcquisitionID.IM-01, ID.IM-02, ID.RA-01, PR.PS-06
    SA-11(6)Attack Surface ReviewsSASystem and Services AcquisitionID.IM-01, ID.IM-02, ID.RA-01, PR.PS-02, PR.PS-06
    SA-11(7)Verify Scope of Testing and EvaluationSASystem and Services AcquisitionID.IM-01, ID.IM-02, ID.RA-01, PR.PS-02, PR.PS-06
    SA-15Development Process, Standards, and ToolsSASystem and Services AcquisitionPR.PS-06
    SA-15(2)Security and Privacy Tracking ToolsSASystem and Services AcquisitionID.IM-01, ID.IM-02, ID.RA-01
    SA-15(3)Criticality AnalysisSASystem and Services AcquisitionPR.PS-06
    SA-15(5)Attack Surface ReductionSASystem and Services AcquisitionPR.DS-10, PR.IR-01, PR.IR-03, PR.PS-05
    SA-15(8)Reuse of Threat and Vulnerability InformationSASystem and Services AcquisitionGV.OC-01, PR.PS-06
    SA-22Unsupported System ComponentsSASystem and Services AcquisitionPR.PS-02, PR.PS-03
    SA-23SpecializationSASystem and Services AcquisitionGV.SC-09, ID.RA-09, PR.PS-06
    SC-1Policy and ProceduresSCSystem and Communications ProtectionGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SC-5Denial-of-service ProtectionSCSystem and Communications ProtectionPR.IR-04
    SC-5(1)Restrict Ability to Attack Other SystemsSCSystem and Communications ProtectionPR.IR-04
    SC-5(2)Capacity, Bandwidth, and RedundancySCSystem and Communications ProtectionPR.IR-04
    SC-5(3)Detection and MonitoringSCSystem and Communications ProtectionPR.IR-04
    SC-6Resource AvailabilitySCSystem and Communications ProtectionPR.IR-04
    SC-7(8)Route Traffic to Authenticated Proxy ServersSCSystem and Communications ProtectionDE.CM-03
    SC-7(18)Fail SecureSCSystem and Communications ProtectionPR.IR-01, PR.IR-03
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications ProtectionPR.DS-02
    SC-8(1)Cryptographic ProtectionSCSystem and Communications ProtectionPR.DS-01, PR.DS-02, PR.DS-10
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications ProtectionPR.DS-01, PR.DS-02, PR.DS-10
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionPR.DS-01, PR.DS-02, PR.DS-10
    SC-16(1)Integrity VerificationSCSystem and Communications ProtectionPR.DS-02
    SC-18(1)Identify Unacceptable Code and Take Corrective ActionsSCSystem and Communications ProtectionID.RA-08, PR.PS-02
    SC-18(3)Prevent Downloading and ExecutionSCSystem and Communications ProtectionDE.CM-03
    SC-28Protection of Information at RestSCSystem and Communications ProtectionPR.DS-01
    SC-28(1)Cryptographic ProtectionSCSystem and Communications ProtectionPR.DS-01, PR.DS-02
    SC-28(2)Offline StorageSCSystem and Communications ProtectionPR.DS-11
    SC-48Sensor RelocationSCSystem and Communications ProtectionID.RA-03
    SI-1Policy and ProceduresSISystem and Information IntegrityGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SI-2Flaw RemediationSISystem and Information IntegrityID.RA-01, ID.RA-08, PR.PS-02
    SI-2(4)Automated Patch Management ToolsSISystem and Information IntegrityPR.PS-02
    SI-3Malicious Code ProtectionSISystem and Information IntegrityDE.CM-09, ID.RA-01, ID.RA-08, PR.PS-02
    SI-4System MonitoringSISystem and Information IntegrityDE.AE-03, DE.AE-06, DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-04
    SI-4(1)System-wide Intrusion Detection SystemSISystem and Information IntegrityDE.CM-01
    SI-4(4)Inbound and Outbound Communications TrafficSISystem and Information IntegrityDE.CM-01
    SI-4(5)System-generated AlertsSISystem and Information IntegrityDE.CM-01, PR.PS-04
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information IntegrityDE.CM-03
    SI-4(12)Automated Organization-generated AlertsSISystem and Information IntegrityDE.AE-06
    SI-4(16)Correlate Monitoring InformationSISystem and Information IntegrityDE.AE-03, DE.AE-06
    SI-4(24)Indicators of CompromiseSISystem and Information IntegrityDE.CM-09
    SI-4(25)Optimize Network Traffic AnalysisSISystem and Information IntegrityDE.CM-01
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information IntegrityDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    SI-5(1)Automated Alerts and AdvisoriesSISystem and Information IntegrityDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    SI-7Software, Firmware, and Information IntegritySISystem and Information IntegrityDE.CM-09
    SI-7(6)Cryptographic ProtectionSISystem and Information IntegrityPR.DS-01, PR.DS-02, PR.DS-10
    SI-12Information Management and RetentionSISystem and Information IntegrityID.AM-07
    SI-12(3)Information DisposalSISystem and Information IntegrityID.AM-07
    SI-13Predictable Failure PreventionSISystem and Information IntegrityID.AM-08
    MP-1Policy and ProceduresMPMedia ProtectionGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.AM-08, PR.DS-01, PR.DS-02, PR.DS-10
    MP-2Media AccessMPMedia ProtectionDE.CM-09
    MP-4Media StorageMPMedia ProtectionID.AM-07
    PS-1Policy and ProceduresPSPersonnel SecurityGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-04, GV.SC-01, GV.SC-03
    PS-2Position Risk DesignationPSPersonnel SecurityGV.RR-02, PR.AA-05
    PS-8Personnel SanctionsPSPersonnel SecurityGV.PO-01, GV.PO-02
    PS-9Position DescriptionsPSPersonnel SecurityGV.RM-05, GV.RR-02
    PM-1Information Security Program PlanPMProgram ManagementGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RM-01, GV.RM-03, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-09
    PM-2Information Security Program Leadership RolePMProgram ManagementGV.RM-05, GV.RR-01, GV.RR-02
    PM-3Information Security and Privacy ResourcesPMProgram ManagementGV.RR-03
    PM-4Plan of Action and Milestones ProcessPMProgram ManagementID.IM-01, ID.IM-02, ID.RA-01, ID.RA-08, PR.PS-02
    PM-5System InventoryPMProgram ManagementGV.SC-04, ID.AM-01, ID.AM-02, ID.AM-08
    PM-5(1)Inventory of Personally Identifiable InformationPMProgram ManagementID.AM-07
    PM-6Measures of PerformancePMProgram ManagementGV.OV-01, GV.OV-03, GV.RM-05, GV.RR-01, GV.RR-02, GV.SC-09, ID.IM-03
    PM-7Enterprise ArchitecturePMProgram ManagementPR.IR-01, PR.IR-03
    PM-8Critical Infrastructure PlanPMProgram ManagementGV.OC-03, GV.SC-05, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05
    PM-9Risk Management StrategyPMProgram ManagementGV.OV-02, GV.OV-03, GV.RM-01, GV.RM-02, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, ID.RA-04
    PM-10Authorization ProcessPMProgram ManagementID.RA-01
    PM-11Mission and Business Process DefinitionPMProgram ManagementID.RA-04
    PM-12Insider Threat ProgramPMProgram ManagementID.RA-03
    PM-13Security and Privacy WorkforcePMProgram ManagementGV.RM-05, GV.RR-02
    PM-14Testing, Training, and MonitoringPMProgram ManagementGV.OC-03
    PM-15Security and Privacy Groups and AssociationsPMProgram ManagementDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    PM-16Threat Awareness ProgramPMProgram ManagementDE.AE-07, ID.RA-03, ID.RA-08
    PM-16(1)Automated Means for Sharing Threat IntelligencePMProgram ManagementDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    PM-18Privacy Program PlanPMProgram ManagementGV.OC-03
    PM-28Risk FramingPMProgram ManagementGV.OC-01, GV.RM-04, GV.RM-06, GV.RM-07, ID.RA-05, ID.RA-06
    PM-29Risk Management Program Leadership RolesPMProgram ManagementGV.OV-02, GV.OV-03, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-05, GV.RM-06, GV.RR-01, GV.RR-02, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10
    PM-30Supply Chain Risk Management StrategyPMProgram ManagementGV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10
    PM-30(1)Suppliers of Critical or Mission-essential ItemsPMProgram ManagementGV.OC-04, GV.OC-05, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, ID.AM-05, ID.RA-10, PR.PS-06
    PM-31Continuous Monitoring StrategyPMProgram ManagementDE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-04
    PT-1Policy and ProceduresPTPII Processing and TransparencyGV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10
    SR-2Supply Chain Risk Management PlanSRSupply Chain Risk ManagementGV.SC-01, GV.SC-03, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-09, GV.SC-10, ID.AM-04
    SR-2(1)Establish SCRM TeamSRSupply Chain Risk ManagementGV.SC-06, GV.SC-07
    SR-3Supply Chain Controls and ProcessesSRSupply Chain Risk ManagementGV.SC-06, GV.SC-07
    SR-3(2)Limitation of HarmSRSupply Chain Risk ManagementGV.SC-06, GV.SC-07
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk ManagementGV.OC-02, GV.OC-03, GV.SC-02, GV.SC-05, GV.SC-06, GV.SC-10
    SR-6Supplier Assessments and ReviewsSRSupply Chain Risk ManagementGV.SC-07, ID.IM-01, ID.IM-02
    SR-6(1)Testing and AnalysisSRSupply Chain Risk ManagementGV.SC-07, ID.IM-01, ID.IM-02
    SR-7Supply Chain Operations SecuritySRSupply Chain Risk ManagementGV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10
    SR-8Notification AgreementsSRSupply Chain Risk ManagementRC.CO-03
    SR-9Tamper Resistance and DetectionSRSupply Chain Risk ManagementID.RA-09
    SR-9(1)Multiple Stages of System Development Life CycleSRSupply Chain Risk ManagementID.RA-09

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.