NIST SP 800-53 Moderate Baseline and the AIC Kits

Analog Informatics Corporation (AIC) kits are designed to the National Institute of Standards and Technology (NIST) Special Publication 800-53 Revision 5 moderate baseline. This page lists all 287 controls and enhancements in that baseline and states what the kit does for each one. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit.

A broad architectural grid of many organized control modules linked to a central technical evidence binder
NIST SP 800-53 Moderate Baseline and the AIC Kits

Capability Availability and Organizational Responsibilities

The 287 control and enhancement mappings below are grouped by the availability and scope of the named AIC capability:

  • Available Now - 71 mappings: The named AIC module is available for the systems and access paths the kit manages.
  • Available Now, Wider Scope Planned - 60 mappings: The named module is available within its current scope. Coverage beyond that scope is planned or remains with the organization, as described in the mapping.
  • Planned - 9 mappings: The named product capability is not yet available.
  • Organization - 147 mappings: The control is addressed through the organization's people, facilities, policies, or tools. The Assessment Binder can store the supporting records.

These labels describe product availability and responsibility, not whether a control has been satisfied. Control titles are taken from the public NIST catalog.

Moderate Baseline Catalog

ControlTitleKit Module
AC-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
AC-2Account ManagementIdentity Governance and Administration and Privileged Identity Management
AC-2(1)Account Management: Automated System Account ManagementIdentity Governance and Administration and Privileged Identity Management
AC-2(2)Account Management: Automated Temporary and Emergency Account ManagementJust-in-time elevation
AC-2(3)Account Management: Disable AccountsIdentity Governance and Administration and Privileged Identity Management
AC-2(4)Account Management: Automated Audit ActionsAudit
AC-2(5)Account Management: Inactivity LogoutKit sessions
AC-2(13)Account Management: Disable Accounts for High-risk IndividualsIdentity Governance and Administration and Privileged Identity Management
AC-3Access EnforcementPrivileged Identity Management, Privileged Access Management, and Privileged User Management
AC-4Information Flow EnforcementDocument sharing vault and classification
AC-5Separation of DutiesApprovals in Privileged Access Management
AC-6Least PrivilegePrivileged User Management
AC-6(1)Least Privilege: Authorize Access to Security FunctionsPrivileged User Management
AC-6(2)Least Privilege: Non-privileged Access for Nonsecurity FunctionsPrivileged User Management
AC-6(5)Least Privilege: Privileged AccountsPrivileged User Management
AC-6(7)Least Privilege: Review of User PrivilegesAccess review
AC-6(9)Least Privilege: Log Use of Privileged FunctionsAudit
AC-6(10)Least Privilege: Prohibit Non-privileged Users from Executing Privileged FunctionsPrivileged User Management
AC-7Unsuccessful Logon AttemptsKit sign-in
AC-8System Use NotificationUniversal host logon banner
AC-11Device LockKit session lock. Operating system lock stays with the organization
AC-11(1)Device Lock: Pattern-hiding DisplaysKit session lock. Operating system lock stays with the organization
AC-12Session TerminationKit sessions
AC-14Permitted Actions Without Identification or AuthenticationKit sign-in
AC-17Remote AccessJump and Privileged Access Management
AC-17(1)Remote Access: Monitoring and ControlJump and Privileged Access Management
AC-17(2)Remote Access: Protection of Confidentiality and Integrity Using EncryptionJump and Privileged Access Management
AC-17(3)Remote Access: Managed Access Control PointsJump
AC-17(4)Remote Access: Privileged Commands and AccessCommand restriction
AC-18Wireless AccessAssessment Binder stores the record
AC-18(1)Wireless Access: Authentication and EncryptionAssessment Binder stores the record
AC-18(3)Wireless Access: Disable Wireless NetworkingAssessment Binder stores the record
AC-19Access Control for Mobile DevicesAssessment Binder stores the record
AC-19(5)Access Control for Mobile Devices: Full Device or Container-based EncryptionAssessment Binder stores the record
AC-20Use of External SystemsConfiguration compliance for external systems that connect
AC-20(1)Use of External Systems: Limits on Authorized UseConfiguration compliance for external systems that connect
AC-20(2)Use of External Systems: Portable Storage Devices - Restricted UseAssessment Binder stores the record
AC-21Information SharingDocument sharing vault
AC-22Publicly Accessible ContentAssessment Binder stores the record
AT-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
AT-2Literacy Training and AwarenessTraining and attestation
AT-2(2)Literacy Training and Awareness: Insider ThreatTraining and attestation
AT-2(3)Literacy Training and Awareness: Social Engineering and MiningTraining and attestation
AT-3Role-based TrainingTraining and attestation
AT-4Training RecordsTraining and attestation records
AU-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
AU-2Event LoggingAudit
AU-3Content of Audit RecordsAudit
AU-3(1)Content of Audit Records: Additional Audit InformationAudit
AU-4Audit Log Storage CapacityAudit
AU-5Response to Audit Logging Process FailuresAudit
AU-6Audit Record Review, Analysis, and ReportingAudit, Windows Event Log, and syslog
AU-6(1)Audit Record Review, Analysis, and Reporting: Automated Process IntegrationAudit
AU-6(3)Audit Record Review, Analysis, and Reporting: Correlate Audit Record RepositoriesAudit, Windows Event Log, and syslog
AU-7Audit Record Reduction and Report GenerationAudit reports
AU-7(1)Audit Record Reduction and Report Generation: Automatic ProcessingAudit reports
AU-8Time StampsAudit
AU-9Protection of Audit InformationAudit
AU-9(4)Protection of Audit Information: Access by Subset of Privileged UsersAudit
AU-11Audit Record RetentionAudit
AU-12Audit Record GenerationAudit
CA-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
CA-2Control AssessmentsAssessment Binder and Current State Compliance
CA-2(1)Control Assessments: Independent AssessorsAssessment Binder stores the record
CA-3Information ExchangeAssessment Binder stores the record
CA-5Plan of Action and MilestonesAssessment Binder plan of action support
CA-6AuthorizationAssessment Binder stores the record
CA-7Continuous MonitoringCurrent State Compliance and continuous configuration compliance monitoring
CA-7(1)Continuous Monitoring: Independent AssessmentCurrent State Compliance
CA-7(4)Continuous Monitoring: Risk MonitoringCurrent State Compliance and continuous configuration compliance monitoring
CA-9Internal System ConnectionsConfiguration compliance
CM-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
CM-2Baseline ConfigurationConfiguration compliance
CM-2(2)Baseline Configuration: Automation Support for Accuracy and CurrencyConfiguration compliance
CM-2(3)Baseline Configuration: Retention of Previous ConfigurationsConfiguration compliance
CM-2(7)Baseline Configuration: Configure Systems and Components for High-risk AreasAssessment Binder stores the record
CM-3Configuration Change ControlConfiguration compliance and Current State Compliance
CM-3(2)Configuration Change Control: Testing, Validation, and Documentation of ChangesAssessment Binder stores the record
CM-3(4)Configuration Change Control: Security and Privacy RepresentativesAssessment Binder stores the record
CM-4Impact AnalysesAssessment Binder stores the record
CM-4(2)Impact Analyses: Verification of ControlsAssessment Binder stores the record
CM-5Access Restrictions for ChangePrivileged Access Management
CM-6Configuration SettingsConfiguration compliance
CM-7Least FunctionalityPrivileged User Management application control
CM-7(1)Least Functionality: Periodic ReviewPrivileged User Management application control
CM-7(2)Least Functionality: Prevent Program ExecutionPrivileged User Management application control
CM-7(5)Least Functionality: Authorized Software - Allow-by-exceptionPrivileged User Management application control
CM-8System Component InventoryInventory of enrolled systems
CM-8(1)System Component Inventory: Updates During Installation and RemovalInventory of enrolled systems
CM-8(3)System Component Inventory: Automated Unauthorized Component DetectionInventory of enrolled systems
CM-9Configuration Management PlanAssessment Binder stores the record
CM-10Software Usage RestrictionsAssessment Binder stores the record
CM-11User-installed SoftwarePrivileged User Management application control
CM-12Information LocationAssessment Binder stores the record
CM-12(1)Information Location: Automated Tools to Support Information LocationAssessment Binder stores the record
CP-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
CP-2Contingency PlanAssessment Binder stores the record
CP-2(1)Contingency Plan: Coordinate with Related PlansAssessment Binder stores the record
CP-2(3)Contingency Plan: Resume Mission and Business FunctionsAssessment Binder stores the record
CP-2(8)Contingency Plan: Identify Critical AssetsAssessment Binder stores the record
CP-3Contingency TrainingAssessment Binder stores the record
CP-4Contingency Plan TestingAssessment Binder stores the record
CP-4(1)Contingency Plan Testing: Coordinate with Related PlansAssessment Binder stores the record
CP-6Alternate Storage SiteAssessment Binder stores the record
CP-6(1)Alternate Storage Site: Separation from Primary SiteAssessment Binder stores the record
CP-6(3)Alternate Storage Site: AccessibilityAssessment Binder stores the record
CP-7Alternate Processing SiteAssessment Binder stores the record
CP-7(1)Alternate Processing Site: Separation from Primary SiteAssessment Binder stores the record
CP-7(2)Alternate Processing Site: AccessibilityAssessment Binder stores the record
CP-7(3)Alternate Processing Site: Priority of ServiceAssessment Binder stores the record
CP-8Telecommunications ServicesAssessment Binder stores the record
CP-8(1)Telecommunications Services: Priority of Service ProvisionsAssessment Binder stores the record
CP-8(2)Telecommunications Services: Single Points of FailureAssessment Binder stores the record
CP-9System BackupAssessment Binder stores the record
CP-9(1)System Backup: Testing for Reliability and IntegrityAssessment Binder stores the record
CP-9(8)System Backup: Cryptographic ProtectionAssessment Binder stores the record
CP-10System Recovery and ReconstitutionAssessment Binder stores the record
CP-10(2)System Recovery and Reconstitution: Transaction RecoveryAssessment Binder stores the record
IA-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
IA-2Identification and Authentication (Organizational Users)Kit sign-in with another step beyond a password
IA-2(1)Identification and Authentication (Organizational Users): Multi-factor Authentication to Privileged AccountsKit sign-in with another step beyond a password
IA-2(2)Identification and Authentication (Organizational Users): Multi-factor Authentication to Non-privileged AccountsKit sign-in with another step beyond a password
IA-2(8)Identification and Authentication (Organizational Users): Access to Accounts - Replay ResistantKit sign-in with another step beyond a password
IA-2(12)Identification and Authentication (Organizational Users): Acceptance of PIV CredentialsPersonal identity verification card sign-in
IA-3Device Identification and AuthenticationEnrolled agent identity
IA-4Identifier ManagementPrivileged Identity Management
IA-4(4)Identifier Management: Identify User StatusPrivileged Identity Management
IA-5Authenticator ManagementPrivileged Identity Management
IA-5(1)Authenticator Management: Password-based AuthenticationPrivileged Identity Management
IA-5(2)Authenticator Management: Public Key-based AuthenticationPrivileged Identity Management
IA-5(6)Authenticator Management: Protection of AuthenticatorsPrivileged Identity Management
IA-6Authentication FeedbackKit sign-in
IA-7Cryptographic Module AuthenticationValidated cryptographic module
IA-8Identification and Authentication (Non-organizational Users)Kit sign-in
IA-8(1)Identification and Authentication (Non-organizational Users): Acceptance of PIV Credentials from Other AgenciesKit sign-in
IA-8(2)Identification and Authentication (Non-organizational Users): Acceptance of External AuthenticatorsKit sign-in
IA-8(4)Identification and Authentication (Non-organizational Users): Use of Defined ProfilesKit sign-in
IA-11Re-authenticationKit sessions
IA-12Identity ProofingAssessment Binder stores the record
IA-12(2)Identity Proofing: Identity EvidenceAssessment Binder stores the record
IA-12(3)Identity Proofing: Identity Evidence Validation and VerificationAssessment Binder stores the record
IA-12(5)Identity Proofing: Address ConfirmationAssessment Binder stores the record
IR-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
IR-2Incident Response TrainingAssessment Binder stores the record
IR-3Incident Response TestingAssessment Binder stores the record
IR-3(2)Incident Response Testing: Coordination with Related PlansAssessment Binder stores the record
IR-4Incident HandlingIncident Response
IR-4(1)Incident Handling: Automated Incident Handling ProcessesIncident Response
IR-5Incident MonitoringIncident Response
IR-6Incident ReportingIncident Response
IR-6(1)Incident Reporting: Automated ReportingIncident Response
IR-6(3)Incident Reporting: Supply Chain CoordinationAssessment Binder stores the record
IR-7Incident Response AssistanceIncident Response
IR-7(1)Incident Response Assistance: Automation Support for Availability of Information and SupportIncident Response
IR-8Incident Response PlanAssessment Binder stores the record
MA-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
MA-2Controlled MaintenanceAssessment Binder stores the record
MA-3Maintenance ToolsPrivileged Access Management
MA-3(1)Maintenance Tools: Inspect ToolsAssessment Binder stores the record
MA-3(2)Maintenance Tools: Inspect MediaAssessment Binder stores the record
MA-3(3)Maintenance Tools: Prevent Unauthorized RemovalAssessment Binder stores the record
MA-4Nonlocal MaintenancePrivileged Access Management
MA-5Maintenance PersonnelPrivileged Access Management
MA-6Timely MaintenanceAssessment Binder stores the record
MP-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
MP-2Media AccessDocument sharing vault
MP-3Media MarkingDocument sharing vault classification
MP-4Media StorageDocument sharing vault
MP-5Media TransportAssessment Binder stores the record
MP-6Media SanitizationAssessment Binder stores the record

Moderate Baseline Catalog (Continued)

ControlTitleKit Module
MP-7Media UseAssessment Binder stores the record
PE-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
PE-2Physical Access AuthorizationsAssessment Binder stores the record
PE-3Physical Access ControlAssessment Binder stores the record
PE-4Access Control for TransmissionAssessment Binder stores the record
PE-5Access Control for Output DevicesAssessment Binder stores the record
PE-6Monitoring Physical AccessAssessment Binder stores the record
PE-6(1)Monitoring Physical Access: Intrusion Alarms and Surveillance EquipmentAssessment Binder stores the record
PE-8Visitor Access RecordsAssessment Binder stores the record
PE-9Power Equipment and CablingAssessment Binder stores the record
PE-10Emergency ShutoffAssessment Binder stores the record
PE-11Emergency PowerAssessment Binder stores the record
PE-12Emergency LightingAssessment Binder stores the record
PE-13Fire ProtectionAssessment Binder stores the record
PE-13(1)Fire Protection: Detection Systems - Automatic Activation and NotificationAssessment Binder stores the record
PE-14Environmental ControlsAssessment Binder stores the record
PE-15Water Damage ProtectionAssessment Binder stores the record
PE-16Delivery and RemovalAssessment Binder stores the record
PE-17Alternate Work SiteAssessment Binder stores the record
PL-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
PL-2System Security and Privacy PlansAssessment Binder stores the record
PL-4Rules of BehaviorAssessment Binder stores the record
PL-4(1)Rules of Behavior: Social Media and External Site/Application Usage RestrictionsAssessment Binder stores the record
PL-8Security and Privacy ArchitecturesAssessment Binder stores the record
PL-10Baseline SelectionAssessment Binder stores the record
PL-11Baseline TailoringAssessment Binder stores the record
PS-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
PS-2Position Risk DesignationAssessment Binder stores the record
PS-3Personnel ScreeningAssessment Binder stores the record
PS-4Personnel TerminationAccount removal in the kit
PS-5Personnel TransferAccount change in the kit
PS-6Access AgreementsAssessment Binder stores the record
PS-7External Personnel SecurityAssessment Binder stores the record
PS-8Personnel SanctionsAssessment Binder stores the record
PS-9Position DescriptionsAssessment Binder stores the record
RA-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
RA-2Security CategorizationAssessment Binder stores the record
RA-3Risk AssessmentCurrent State Compliance findings
RA-3(1)Risk Assessment: Supply Chain Risk AssessmentCurrent State Compliance findings
RA-5Vulnerability Monitoring and ScanningVulnerability analysis (add-on module)
RA-5(2)Vulnerability Monitoring and Scanning: Update Vulnerabilities to Be ScannedVulnerability analysis (add-on module)
RA-5(5)Vulnerability Monitoring and Scanning: Privileged AccessPrivileged Identity Management supplies scan credentials
RA-5(11)Vulnerability Monitoring and Scanning: Public Disclosure ProgramVulnerability analysis (add-on module)
RA-7Risk ResponseAssessment Binder stores the record
RA-9Criticality AnalysisAssessment Binder stores the record
SA-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
SA-2Allocation of ResourcesAssessment Binder stores the record
SA-3System Development Life CycleAssessment Binder stores the record
SA-4Acquisition ProcessAssessment Binder stores the record
SA-4(1)Acquisition Process: Functional Properties of ControlsAssessment Binder stores the record
SA-4(2)Acquisition Process: Design and Implementation Information for ControlsAssessment Binder stores the record
SA-4(9)Acquisition Process: Functions, Ports, Protocols, and Services in UseAssessment Binder stores the record
SA-4(10)Acquisition Process: Use of Approved PIV ProductsAssessment Binder stores the record
SA-5System DocumentationAssessment Binder stores the record
SA-8Security and Privacy Engineering PrinciplesAssessment Binder stores the record
SA-9External System ServicesAssessment Binder stores the record
SA-9(2)External System Services: Identification of Functions, Ports, Protocols, and ServicesAssessment Binder stores the record
SA-10Developer Configuration ManagementAssessment Binder stores the record
SA-11Developer Testing and EvaluationAssessment Binder stores the record
SA-15Development Process, Standards, and ToolsAssessment Binder stores the record
SA-15(3)Development Process, Standards, and Tools: Criticality AnalysisAssessment Binder stores the record
SA-22Unsupported System ComponentsAssessment Binder stores the record
SC-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
SC-2Separation of System and User FunctionalityKit design
SC-4Information in Shared System ResourcesKit design
SC-5Denial-of-service ProtectionAssessment Binder stores the record
SC-7Boundary ProtectionJump
SC-7(3)Boundary Protection: Access PointsJump
SC-7(4)Boundary Protection: External Telecommunications ServicesJump
SC-7(5)Boundary Protection: Deny by Default - Allow by ExceptionJump
SC-7(7)Boundary Protection: Split Tunneling for Remote DevicesJump
SC-7(8)Boundary Protection: Route Traffic to Authenticated Proxy ServersJump
SC-8Transmission Confidentiality and IntegrityValidated cryptography on kit paths
SC-8(1)Transmission Confidentiality and Integrity: Cryptographic ProtectionValidated cryptography on kit paths
SC-10Network DisconnectKit sessions
SC-12Cryptographic Key Establishment and ManagementKey management with hardware security module support
SC-13Cryptographic ProtectionValidated cryptography on kit paths
SC-15Collaborative Computing Devices and ApplicationsAssessment Binder stores the record
SC-17Public Key Infrastructure CertificatesCertificate lifecycle management
SC-18Mobile CodeAssessment Binder stores the record
SC-20Secure Name/Address Resolution Service (Authoritative Source)Assessment Binder stores the record
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)Assessment Binder stores the record
SC-22Architecture and Provisioning for Name/Address Resolution ServiceAssessment Binder stores the record
SC-23Session AuthenticityKit sessions
SC-28Protection of Information at RestEncryption at rest on kit paths
SC-28(1)Protection of Information at Rest: Cryptographic ProtectionEncryption at rest on kit paths
SC-39Process IsolationAssessment Binder stores the record
SI-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
SI-2Flaw RemediationCurrent State Compliance findings
SI-2(2)Flaw Remediation: Automated Flaw Remediation StatusCurrent State Compliance findings
SI-3Malicious Code ProtectionAssessment Binder stores the record
SI-4System MonitoringIncident Response and continuous monitoring
SI-4(2)System Monitoring: Automated Tools and Mechanisms for Real-time AnalysisIncident Response
SI-4(4)System Monitoring: Inbound and Outbound Communications TrafficIncident Response and continuous monitoring
SI-4(5)System Monitoring: System-generated AlertsIncident Response alerts
SI-5Security Alerts, Advisories, and DirectivesIncident Response
SI-7Software, Firmware, and Information IntegrityConfiguration compliance
SI-7(1)Software, Firmware, and Information Integrity: Integrity ChecksConfiguration compliance
SI-7(7)Software, Firmware, and Information Integrity: Integration of Detection and ResponseAssessment Binder stores the record
SI-8Spam ProtectionAssessment Binder stores the record
SI-8(2)Spam Protection: Automatic UpdatesAssessment Binder stores the record
SI-10Information Input ValidationKit design
SI-11Error HandlingKit design
SI-12Information Management and RetentionAudit retention
SI-16Memory ProtectionAssessment Binder stores the record
SR-1Policy and ProceduresPolicy and procedures. Assessment Binder stores the record
SR-2Supply Chain Risk Management PlanAssessment Binder stores the record
SR-2(1)Supply Chain Risk Management Plan: Establish SCRM TeamAssessment Binder stores the record
SR-3Supply Chain Controls and ProcessesAssessment Binder stores the record
SR-5Acquisition Strategies, Tools, and MethodsAssessment Binder stores the record
SR-6Supplier Assessments and ReviewsAssessment Binder stores the record
SR-8Notification AgreementsAssessment Binder stores the record
SR-10Inspection of Systems or ComponentsAssessment Binder stores the record
SR-11Component AuthenticityAssessment Binder stores the record
SR-11(1)Component Authenticity: Anti-counterfeit TrainingAssessment Binder stores the record
SR-11(2)Component Authenticity: Configuration Control for Component Service and RepairAssessment Binder stores the record
SR-12Component DisposalAssessment Binder stores the record

Screenshots

Control coverage shows which controls have live evidence and which still need work.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.