Home/Compliance
nist-800-53

NIST 800-53. Security Controls

17 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
1246
Total controls
0%
Detection coverage
0
Covered controls
1246
Coverage gaps
▤ Export audit (CSV) Coverage report Self-assessment Show gaps only
▶ Check your own detection coverage

Paste the ATT&CK technique IDs you have Sigma/YARA rules for (one per line, e.g. T1059, T1190). The controls below will update to show YOUR coverage instead of ours.

Red team insight A nist-800-53 compliant org should have detection for the green-tagged techniques below. Controls showing no technique coverage are likely blind spots. Use gaps view to enumerate unmonitored attack paths.

Controls

17 shown of 17
family AC framework nist-800-53
ATT&CK techniques this control defends against   ✓ covered by Sigma/YARA in our corpus  × = detection gap
T1003 · OS Credential Dumping T1003.001 · LSASS Memory T1003.002 · Security Account Manager T1003.003 · NTDS T1003.004 · LSA Secrets T1003.005 · Cached Domain Credentials T1003.006 · DCSync× T1003.007 · Proc Filesystem× T1003.008 · /etc/passwd and /etc/shadow T1005 · Data from Local System× T1020.001 · Traffic Duplication T1021 · Remote Services T1021.001 · Remote Desktop Protocol T1021.002 · SMB/Windows Admin Shares T1021.003 · Distributed Component Object Model T1021.004 · SSH T1021.005 · VNC T1021.006 · Windows Remote Management T1021.007 · Cloud Services× T1021.008 · Direct Cloud VM Connections× T1025 · Data from Removable Media T1027 · Obfuscated Files or Information T1036 · Masquerading T1036.003 · Rename Legitimate Utilities T1036.005 · Match Legitimate Resource Name or Location× T1036.010 · Masquerade Account Name T1037 · Boot or Logon Initialization Scripts× T1037.002 · Login Hook× T1037.003 · Network Logon Script× T1037.004 · RC Scripts T1037.005 · Startup Items T1041 · Exfiltration Over C2 Channel T1047 · Windows Management Instrumentation T1048 · Exfiltration Over Alternative Protocol T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol× T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol× T1052 · Exfiltration Over Physical Medium× T1052.001 · Exfiltration over USB T1053 · Scheduled Task/Job
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
family AC framework nist-800-53
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family AC framework nist-800-53
Employ an audited override of automated access control mechanisms under {{ insert: param, ac-03.10_odp.01 }} by {{ insert: param, ac-03.10_odp.02 }}.
family AC framework nist-800-53
Restrict access to data repositories containing {{ insert: param, ac-03.11_odp }}.
family AC framework nist-800-53
Require applications to assert, as part of the installation process, the access needed to the following system applications and functions: {{ insert: param, ac-03.12_odp }}; Provide an enforcement mechanism to prevent unauthorized access; and Approve access changes after initial installation of the application.
family AC framework nist-800-53
Enforce attribute-based access control policy over defined subjects and objects and control access based upon {{ insert: param, ac-03.13_odp }}.
family AC framework nist-800-53
Provide {{ insert: param, ac-03.14_odp.01 }} to enable individuals to have access to the following elements of their personally identifiable information: {{ insert: param, ac-03.14_odp.02 }}.
family AC framework nist-800-53
Enforce {{ insert: param, ac-3.15_prm_1 }} over the set of covered subjects and objects specified in the policy; and Enforce {{ insert: param, ac-3.15_prm_2 }} over the set of covered subjects and objects specified in the policy.
family AC framework nist-800-53
Enforce dual authorization for {{ insert: param, ac-03.02_odp }}.
family AC framework nist-800-53
Enforce {{ insert: param, ac-3.3_prm_1 }} over the set of covered subjects and objects specified in the policy, and where the policy: Is uniformly enforced across the covered subjects and objects within the system; Specifies that a subject that has been granted access to information is constrained from doing any of the following; Passing the information to unauthorized subjects or objects; Granting its privileges to other subjects; Changing one or more security attributes (specified by the policy) on subjects, objects, the system, or system components; Choosing the security attributes and attribute values (specified by the policy) to be associated with newly created or modified objects; and Changing the rules governing access control; and Specifies that {{ insert: param, ac-03.03_odp.03 }} may explicitly be granted {{ insert: param, ac-03.03_odp.04 }} such that they are not limited by any defined subset (or all) of the above constraints.
family AC framework nist-800-53
Enforce {{ insert: param, ac-3.4_prm_1 }} over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: Pass the information to any other subjects or objects; Grant its privileges to other subjects; Change security attributes on subjects, objects, the system, or the system’s components; Choose the security attributes to be associated with newly created or revised objects; or Change the rules governing access control.
family AC framework nist-800-53
Prevent access to {{ insert: param, ac-03.05_odp }} except during secure, non-operable system states.
family AC framework nist-800-53
family AC framework nist-800-53
Enforce a role-based access control policy over defined subjects and objects and control access based upon {{ insert: param, ac-3.7_prm_1 }}.
family AC framework nist-800-53
Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on {{ insert: param, ac-03.08_odp }}.
family AC framework nist-800-53
Release information outside of the system only if: The receiving {{ insert: param, ac-03.09_odp.01 }} provides {{ insert: param, ac-03.09_odp.02 }} ; and {{ insert: param, ac-03.09_odp.03 }} are used to validate the appropriateness of the information designated for release.
family AC framework nist-800-53
Showing 1-17 of 17
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin