NIST · Shared reference library

NIST SP 800-53 Rev. 5 Common Control Library

Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.

A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.

Sources and crosswalk scope

NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.

Official pinned NIST source

SHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763

Reset

6 matching controls · Page 1 of 1

System and Communications Protection · Base control

SC-23 · Session Authenticity

Control statement and discussion

NIST control statement

Protect the authenticity of communications sessions.

Discussion

Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of communications sessions in the ongoing identities of other parties and the validity of transmitted information. Authenticity protection includes protecting against "man-in-the-middle" attacks, session hijacking, and the insertion of false information into sessions.

GovRAMP crosswalk

System and Communications Protection · Enhancement

SC-23(1) · Invalidate Session Identifiers at Logout

View parent control
Control statement and discussion

NIST control statement

Invalidate session identifiers upon user logout or other session termination.

Discussion

Invalidating session identifiers at logout curtails the ability of adversaries to capture and continue to employ previously valid session IDs.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

System and Communications Protection · Enhancement · Withdrawn

SC-23(2) · User-initiated Logouts and Message Displays

View parent control
Control statement and discussion

NIST control statement

Withdrawn in this source release; review the official source for disposition.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

System and Communications Protection · Enhancement

SC-23(3) · Unique System-generated Session Identifiers

View parent control
Control statement and discussion

NIST control statement

Generate a unique session identifier for each session with [Assignment: randomness requirements] and recognize only session identifiers that are system-generated.

Discussion

Generating unique session identifiers curtails the ability of adversaries to reuse previously valid session IDs. Employing the concept of randomness in the generation of unique session identifiers protects against brute-force attacks to determine future session identifiers.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

System and Communications Protection · Enhancement · Withdrawn

SC-23(4) · Unique Session Identifiers with Randomization

View parent control
Control statement and discussion

NIST control statement

Withdrawn in this source release; review the official source for disposition.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.

System and Communications Protection · Enhancement

SC-23(5) · Allowed Certificate Authorities

View parent control
Control statement and discussion

NIST control statement

Only allow the use of [Assignment: certificated authorities] for verification of the establishment of protected sessions.

Discussion

Reliance on certificate authorities for the establishment of secure sessions includes the use of Transport Layer Security (TLS) certificates. These certificates, after verification by their respective certificate authorities, facilitate the establishment of protected sessions between web clients and web servers.

GovRAMP crosswalk

Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.