NIST · Shared reference library

NIST SP 800-53 Rev. 5 Common Control Library

Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.

A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.

Sources and crosswalk scope

NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.

Official pinned NIST source

SHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763

Reset

1011 matching controls · Page 8 of 41

Audit and Accountability · Enhancement

AU-9(4) · Access by Subset of Privileged Users

View parent control
Control statement and discussion

NIST control statement

Authorize access to management of audit logging functionality to only [Assignment: subset of privileged users or roles].

Discussion

Individuals or roles with privileged access to a system and who are also the subject of an audit by that system may affect the reliability of the audit information by inhibiting audit activities or modifying audit records. Requiring privileged access to be further defined between audit-related privileges and other privileges limits the number of users or roles with audit-related privileges.

GovRAMP crosswalk

Audit and Accountability · Enhancement

AU-9(5) · Dual Authorization

View parent control
Control statement and discussion

NIST control statement

Enforce dual authorization for [Selection (one-or-more): movement; deletion] of [Assignment: audit information].

Discussion

Organizations may choose different selection options for different types of audit information. Dual authorization mechanisms (also known as two-person control) require the approval of two authorized individuals to execute audit functions. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals. Organizations do not require dual authorization mechanisms when immediate responses are necessary to ensure public and environmental safety.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-9(6) · Read-only Access

View parent control
Control statement and discussion

NIST control statement

Authorize read-only access to audit information to [Assignment: subset of privileged users or roles].

Discussion

Restricting privileged user or role authorizations to read-only helps to limit the potential damage to organizations that could be initiated by such users or roles, such as deleting audit records to cover up malicious activity.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-9(7) · Store on Component with Different Operating System

View parent control
Control statement and discussion

NIST control statement

Store audit information on a component running a different operating system than the system or component being audited.

Discussion

Storing auditing information on a system component running a different operating system reduces the risk of a vulnerability specific to the system, resulting in a compromise of the audit records.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Base control

AU-10 · Non-repudiation

Control statement and discussion

NIST control statement

Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [Assignment: actions].

Discussion

Types of individual actions covered by non-repudiation include creating information, sending and receiving messages, and approving information. Non-repudiation protects against claims by authors of not having authored certain documents, senders of not having transmitted messages, receivers of not having received messages, and signatories of not having signed documents. Non-repudiation services can be used to determine if information originated from an individual or if an individual took specific actions (e.g., sending an email, signing a contract, approving a procurement request, or receiving specific information). Organizations obtain non-repudiation services by employing various techniques or mechanisms, including digital signatures and digital message receipts.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-10(1) · Association of Identities

View parent control
Control statement and discussion

NIST control statement

(a) Bind the identity of the information producer with the information to [Assignment: strength of binding] ; and (b) Provide the means for authorized individuals to determine the identity of the producer of the information.

Discussion

Binding identities to the information supports audit requirements that provide organizational personnel with the means to identify who produced specific information in the event of an information transfer. Organizations determine and approve the strength of attribute binding between the information producer and the information based on the security category of the information and other relevant risk factors.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-10(2) · Validate Binding of Information Producer Identity

View parent control
Control statement and discussion

NIST control statement

(a) Validate the binding of the information producer identity to the information at [Assignment: frequency] ; and (b) Perform [Assignment: actions] in the event of a validation error.

Discussion

Validating the binding of the information producer identity to the information prevents the modification of information between production and review. The validation of bindings can be achieved by, for example, using cryptographic checksums. Organizations determine if validations are in response to user requests or generated automatically.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-10(3) · Chain of Custody

View parent control
Control statement and discussion

NIST control statement

Maintain reviewer or releaser credentials within the established chain of custody for information reviewed or released.

Discussion

Chain of custody is a process that tracks the movement of evidence through its collection, safeguarding, and analysis life cycle by documenting each individual who handled the evidence, the date and time the evidence was collected or transferred, and the purpose for the transfer. If the reviewer is a human or if the review function is automated but separate from the release or transfer function, the system associates the identity of the reviewer of the information to be released with the information and the information label. In the case of human reviews, maintaining the credentials of reviewers or releasers provides the organization with the means to identify who reviewed and released the information. In the case of automated reviews, it ensures that only approved review functions are used.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-10(4) · Validate Binding of Information Reviewer Identity

View parent control
Control statement and discussion

NIST control statement

(a) Validate the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between [Assignment: security domains] ; and (b) Perform [Assignment: actions] in the event of a validation error.

Discussion

Validating the binding of the information reviewer identity to the information at transfer or release points prevents the unauthorized modification of information between review and the transfer or release. The validation of bindings can be achieved by using cryptographic checksums. Organizations determine if validations are in response to user requests or generated automatically.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Base control

AU-11 · Audit Record Retention

Control statement and discussion

NIST control statement

Retain audit records for [Assignment: time period] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.

Discussion

Organizations retain audit records until it is determined that the records are no longer needed for administrative, legal, audit, or other operational purposes. This includes the retention and availability of audit records relative to Freedom of Information Act (FOIA) requests, subpoenas, and law enforcement actions. Organizations develop standard categories of audit records relative to such types of actions and standard response processes for each type of action. The National Archives and Records Administration (NARA) General Records Schedules provide federal policy on records retention.

GovRAMP crosswalk

Audit and Accountability · Enhancement

AU-11(1) · Long-term Retrieval Capability

View parent control
Control statement and discussion

NIST control statement

Employ [Assignment: measures] to ensure that long-term audit records generated by the system can be retrieved.

Discussion

Organizations need to access and read audit records requiring long-term storage (on the order of years). Measures employed to help facilitate the retrieval of audit records include converting records to newer formats, retaining equipment capable of reading the records, and retaining the necessary documentation to help personnel understand how to interpret the records.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Base control

AU-12 · Audit Record Generation

Control statement and discussion

NIST control statement

a. Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [Assignment: system components]; b. Allow [Assignment: personnel or roles] to select the event types that are to be logged by specific components of the system; and c. Generate audit records for the event types defined in [AU-2c](#au-2_smt.c) that include the audit record content defined in [AU-3](#au-3).

Discussion

Audit records can be generated from many different system components. The event types specified in [AU-2d](#au-2_smt.d) are the event types for which audit logs are to be generated and are a subset of all event types for which the system can generate audit records.

GovRAMP crosswalk

Audit and Accountability · Enhancement

AU-12(1) · System-wide and Time-correlated Audit Trail

View parent control
Control statement and discussion

NIST control statement

Compile audit records from [Assignment: system components] into a system-wide (logical or physical) audit trail that is time-correlated to within [Assignment: level of tolerance].

Discussion

Audit trails are time-correlated if the time stamps in the individual audit records can be reliably related to the time stamps in other audit records to achieve a time ordering of the records within organizational tolerances.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-12(2) · Standardized Formats

View parent control
Control statement and discussion

NIST control statement

Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format.

Discussion

Audit records that follow common standards promote interoperability and information exchange between devices and systems. Promoting interoperability and information exchange facilitates the production of event information that can be readily analyzed and correlated. If logging mechanisms do not conform to standardized formats, systems may convert individual audit records into standardized formats when compiling system-wide audit trails.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-12(3) · Changes by Authorized Individuals

View parent control
Control statement and discussion

NIST control statement

Provide and implement the capability for [Assignment: individuals or roles] to change the logging to be performed on [Assignment: system components] based on [Assignment: selectable event criteria] within [Assignment: time thresholds].

Discussion

Permitting authorized individuals to make changes to system logging enables organizations to extend or limit logging as necessary to meet organizational requirements. Logging that is limited to conserve system resources may be extended (either temporarily or permanently) to address certain threat situations. In addition, logging may be limited to a specific set of event types to facilitate audit reduction, analysis, and reporting. Organizations can establish time thresholds in which logging actions are changed (e.g., near real-time, within minutes, or within hours).

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-12(4) · Query Parameter Audits of Personally Identifiable Information

View parent control
Control statement and discussion

NIST control statement

Provide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.

Discussion

Query parameters are explicit criteria that an individual or automated system submits to a system to retrieve data. Auditing of query parameters for datasets that contain personally identifiable information augments the capability of an organization to track and understand the access, usage, or sharing of personally identifiable information by authorized personnel.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Base control

AU-13 · Monitoring for Information Disclosure

Control statement and discussion

NIST control statement

a. Monitor [Assignment: open-source information and/or information sites] [Assignment: frequency] for evidence of unauthorized disclosure of organizational information; and b. If an information disclosure is discovered: 1. Notify [Assignment: personnel or roles] ; and 2. Take the following additional actions: [Assignment: additional actions].

Discussion

Unauthorized disclosure of information is a form of data leakage. Open-source information includes social networking sites and code-sharing platforms and repositories. Examples of organizational information include personally identifiable information retained by the organization or proprietary information generated by the organization.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-13(1) · Use of Automated Tools

View parent control
Control statement and discussion

NIST control statement

Monitor open-source information and information sites using [Assignment: automated mechanisms].

Discussion

Automated mechanisms include commercial services that provide notifications and alerts to organizations and automated scripts to monitor new posts on websites.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-13(2) · Review of Monitored Sites

View parent control
Control statement and discussion

NIST control statement

Review the list of open-source information sites being monitored [Assignment: frequency].

Discussion

Reviewing the current list of open-source information sites being monitored on a regular basis helps to ensure that the selected sites remain relevant. The review also provides the opportunity to add new open-source information sites with the potential to provide evidence of unauthorized disclosure of organizational information. The list of sites monitored can be guided and informed by threat intelligence of other credible sources of information.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-13(3) · Unauthorized Replication of Information

View parent control
Control statement and discussion

NIST control statement

Employ discovery techniques, processes, and tools to determine if external entities are replicating organizational information in an unauthorized manner.

Discussion

The unauthorized use or replication of organizational information by external entities can cause adverse impacts on organizational operations and assets, including damage to reputation. Such activity can include the replication of an organizational website by an adversary or hostile threat actor who attempts to impersonate the web-hosting organization. Discovery tools, techniques, and processes used to determine if external entities are replicating organizational information in an unauthorized manner include scanning external websites, monitoring social media, and training staff to recognize the unauthorized use of organizational information.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Base control

AU-14 · Session Audit

Control statement and discussion

NIST control statement

a. Provide and implement the capability for [Assignment: users or roles] to [Selection (one-or-more): record; view; hear; log] the content of a user session under [Assignment: circumstances] ; and b. Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Discussion

Session audits can include monitoring keystrokes, tracking websites visited, and recording information and/or file transfers. Session audit capability is implemented in addition to event logging and may involve implementation of specialized session capture technology. Organizations consider how session auditing can reveal information about individuals that may give rise to privacy risk as well as how to mitigate those risks. Because session auditing can impact system and network performance, organizations activate the capability under well-defined situations (e.g., the organization is suspicious of a specific individual). Organizations consult with legal counsel, civil liberties officials, and privacy officials to ensure that any legal, privacy, civil rights, or civil liberties issues, including the use of personally identifiable information, are appropriately addressed.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-14(1) · System Start-up

View parent control
Control statement and discussion

NIST control statement

Initiate session audits automatically at system start-up.

Discussion

The automatic initiation of session audits at startup helps to ensure that the information being captured on selected individuals is complete and not subject to compromise through tampering by malicious threat actors.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-14(3) · Remote Viewing and Listening

View parent control
Control statement and discussion

NIST control statement

Provide and implement the capability for authorized users to remotely view and hear content related to an established user session in real time.

Discussion

None.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Base control

AU-16 · Cross-organizational Audit Logging

Control statement and discussion

NIST control statement

Employ [Assignment: methods] for coordinating [Assignment: audit information] among external organizations when audit information is transmitted across organizational boundaries.

Discussion

When organizations use systems or services of external organizations, the audit logging capability necessitates a coordinated, cross-organization approach. For example, maintaining the identity of individuals who request specific services across organizational boundaries may often be difficult, and doing so may prove to have significant performance and privacy ramifications. Therefore, it is often the case that cross-organizational audit logging simply captures the identity of individuals who issue requests at the initial system, and subsequent systems record that the requests originated from authorized individuals. Organizations consider including processes for coordinating audit information requirements and protection of audit information in information exchange agreements.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

Audit and Accountability · Enhancement

AU-16(1) · Identity Preservation

View parent control
Control statement and discussion

NIST control statement

Preserve the identity of individuals in cross-organizational audit trails.

Discussion

Identity preservation is applied when there is a need to be able to trace actions that are performed across organizational boundaries to a specific individual.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.