The US National Institute of Standards and Technology (NIST) has published Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, the most significant update to the catalogue since it was first published.
Key points
- Adds controls addressing advanced persistent threats, insider threat, supply chain risk and mobile and cloud computing.
- Introduces a new appendix of privacy controls based on fair information practice principles.
- Adds guidance on tailoring baselines through overlays.
- Strengthens emphasis on trustworthiness and security assurance.
- Underpins FedRAMP and other US government security programmes.
SP 800-53 is widely used beyond US government, including by suppliers to US clients. UK organisations serving US public sector or regulated clients may be asked to map their controls to it.
Source: NIST SP 800-53 Rev. 4 (April 2013) (NIST CSRC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.