STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.

NIST 800-53 Controls

Rev 5Rev 4
Baselines:AllLowModerateHighPrivacyNo Baseline

Browse 372 security and privacy controls across 18 families. (filtered to High baseline)

Each control is linked to DISA CCI identifiers and STIG checks. Search for fast lookup by control ID or CCI.

Control FamiliesAll Controls372
AC Access Control46AT Awareness and Training6AU Audit and Accountability25CA Assessment, Authorization, and Monitoring14CM Configuration Management32CP Contingency Planning35IA Identification and Authentication26IR Incident Response18MA Maintenance12MP Media Protection10PE Physical and Environmental Protection25PL Planning7PS Personnel Security10RA Risk Assessment11SA System and Services Acquisition21SC System and Communications Protection32SI System and Information Integrity28SR Supply Chain Risk Management14

SA — System and Services Acquisition

14 base controls

SA-1Policy and Procedures
21 CCIs
SA-2Allocation of Resources
11 CCIs
SA-3System Development Life Cycle
16 CCIs
SA-4Acquisition Process
21 CCIs
SA-5System Documentation
24 CCIs
SA-8Security and Privacy Engineering Principles
10 CCIs
SA-9External System Services
15 CCIs
SA-10Developer Configuration Management
33 CCIs
SA-11Developer Testing and Evaluation
21 CCIs
SA-15Development Process, Standards, and Tools
21 CCIs
SA-16Developer-Provided Training
4 CCIs
SA-17Developer Security and Privacy Architecture and Design
10 CCIs
SA-21Developer Screening
5 CCIs
SA-22Unsupported System Components
5 CCIs