STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.

NIST 800-53 Controls

Rev 5Rev 4

Browse 862 security and privacy controls across 26 families. (filtered to Moderate, Privacy, No Baseline baselines)

Each control is linked to DISA CCI identifiers and STIG checks. Search for fast lookup by control ID or CCI. Switch to Rev 5 for the latest controls.

Control FamiliesAll Controls862
AC Access Control112AP Authority and Purpose2AR Accountability, Audit, and Risk Management8AT Awareness and Training10AU Audit and Accountability58CA Assessment, Authorization, and Monitoring22CM Configuration Management50CP Contingency Planning48DI Data Quality and Integrity5DM Data Minimization and Retention6IA Identification and Authentication56IP Individual Participation and Redress6IR Incident Response34MA Maintenance26MP Media Protection22PE Physical and Environmental Protection50PL Planning10PM Program Management16PS Personnel Security15RA Risk Assessment13SA System and Services Acquisition86SC System and Communications Protection116SE Security2SI System and Information Integrity82TR Transparency5UL Use Limitation2

PM — Program Management

16 base controls

PM-1Information Security Program Plan
17 CCIs
PM-2Senior Information Security Officer
1 CCIs
PM-3Information Security Resources
8 CCIs
PM-4Plan of Action and Milestones Process
14 CCIs
PM-5System Inventory
4 CCIs
PM-6Information Security Measures of Performance
6 CCIs
PM-7Enterprise Architecture
4 CCIs
PM-8Critical Infrastructure Plan
4 CCIs
PM-9Risk Management Strategy
5 CCIs
PM-10Authorization Process
7 CCIs
PM-11Mission/business Process Definition
6 CCIs
PM-12Insider Threat Program
1 CCIs
PM-13Information Security Workforce
2 CCIs
PM-14Testing, Training, and Monitoring
21 CCIs
PM-15Contacts with Security Groups and Associations
6 CCIs
PM-16Threat Awareness Program
1 CCIs