Request Demo

What's New in NIST SP 800 53 Rev 5

down-arrow

NIST Special Publication (SP) 800-53 offers regulatory guidelines and controls for federal information systems, except those relating to national security. This catalog of security and privacy controls has been used and adopted by a range of organizations, both part of the federal government and beyond, due to the comprehensive nature of the control set.

Back in 2017, NIST released the first public draft of SP 800-53 Revision 5. In September 2020, NIST released the official version of Rev 5, following what NIST describes as “a multi-year effort to develop the next generation of security and privacy controls needed to strengthen and support the Federal Government and every sector of critical infrastructure” and with it has come a monumental sweep of changes for federal agencies and non-governmental organizations alike to use to protect the critical systems, components, and services that defend the United States.

Recent Changes in NIST Special Publication 800-53

Controls for information systems and security controls are integrated into a seamless catalog for information systems and organizations. Privacy elements are now included in the unified catalog and integrated throughout 86 controls.

  • New Supply Chain Risk Management (SCRM) control family, with integrations throughout NIST 800 53 Rev 5.
  • Security and Privacy controls have become more outcome-based.
  • Clarifications of language between requirements, as well as the relationship between security and privacy controls
  • Separation of control selection processes and actual controls, making them more accessible to other teams across an organization.
  • New state-of-the-art controls based on threat intelligence and industry data to support cyber resilience, secure system design, and governance models.

Promoting an integrated approach to cyber risk management and cybersecurity best practices (like the NIST CSF), allowing Rev 5 to be scalable and applicable to multiple avenues like large-scale IT, cloud-based infrastructure, mobile devices, and IoT devices.

NIST SP 800-53 Rev 5 is making great strides to usher in a new generation of cybersecurity best practices. Bridging the gap between cybersecurity teams and organizational objectives. Using a cyber risk management solution like CyberStrong can help harmonize an organization's cybersecurity efforts across multiple frameworks and compliance regulations using our cutting-edge AI technology to crosswalk and automate risk management processes to save organizations valuable time, energy, and resources, as well as present information in a unified, human way.

Learn more about the NIST 800-53 control families here. 

If you have questions about any NIST Special Publication, including 800-53 Rev 5, NIST 800-171, cyber risk management, or how CyberStrong is helping organizations meet their cybersecurity goals, meet with the CyberSaint team.

You may also like

CyberStrong February Product Update
on February 20, 2025

The team at CyberSaint is thrilled to announce the latest additions and updates to the CyberStrong solution. To start, we’re expanding Phase 1 of Asset Management with custom ...

Bridging the Gap Between Security ...
on February 17, 2025

Cybersecurity and risk management are often treated as separate disciplines within organizations. Security teams focus on identifying and mitigating technical threats, while risk ...

Prioritizing Cybersecurity ...
on January 28, 2025

There is an immediate need for organizations to quickly implement or mature their cyber risk practices, and even more so as the reality of a new era of remote work and other ...

Alison Furneaux
Beyond the CISO: Leveraging a ...
on January 27, 2025

The Strategic Importance of a Deputy CISO The role of a Chief Information Security Officer (CISO) is constantly evolving, often expanding to encompass responsibilities beyond the ...

Top Cybersecurity Predictions for ...
on January 21, 2025

Cybersecurity in 2025: Key Predictions As we approach 2025, the cybersecurity landscape is poised for significant shifts. Experts predict a move towards more practical AI ...

A Pocket Guide to Cyber Risk ...
on January 16, 2025

Cybersecurity is no longer just about firewalls and antivirus software. In today's data-driven world, effectively managing cybersecurity risk requires quantification: turning ...