Don’t do SECURITY. Do business SECURELY.

NIST releases SP 800-53 Revision 4

NIST publishes SP 800-53 Revision 4, a major update to the US federal security control catalogue that adds privacy controls.

The US National Institute of Standards and Technology (NIST) has published Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, the most significant update to the catalogue since it was first published.

Key points

  • Adds controls addressing advanced persistent threats, insider threat, supply chain risk and mobile and cloud computing.
  • Introduces a new appendix of privacy controls based on fair information practice principles.
  • Adds guidance on tailoring baselines through overlays.
  • Strengthens emphasis on trustworthiness and security assurance.
  • Underpins FedRAMP and other US government security programmes.

SP 800-53 is widely used beyond US government, including by suppliers to US clients. UK organisations serving US public sector or regulated clients may be asked to map their controls to it.

Source: NIST SP 800-53 Rev. 4 (April 2013) (NIST CSRC)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights