Home/Compliance
nist-800-53

NIST 800-53. Security Controls

11 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
1246
Total controls
0%
Detection coverage
0
Covered controls
1246
Coverage gaps
▤ Export audit (CSV) Coverage report Self-assessment Show gaps only
▶ Check your own detection coverage

Paste the ATT&CK technique IDs you have Sigma/YARA rules for (one per line, e.g. T1059, T1190). The controls below will update to show YOUR coverage instead of ours.

Red team insight A nist-800-53 compliant org should have detection for the green-tagged techniques below. Controls showing no technique coverage are likely blind spots. Use gaps view to enumerate unmonitored attack paths.

Controls

11 shown of 11
family CM framework nist-800-53
ATT&CK techniques this control defends against   ✓ covered by Sigma/YARA in our corpus  × = detection gap
T1003 · OS Credential Dumping T1003.001 · LSASS Memory T1003.002 · Security Account Manager T1003.005 · Cached Domain Credentials T1008 · Fallback Channels× T1011 · Exfiltration Over Other Network Medium× T1011.001 · Exfiltration Over Bluetooth× T1020.001 · Traffic Duplication T1021 · Remote Services T1021.001 · Remote Desktop Protocol T1021.002 · SMB/Windows Admin Shares T1021.003 · Distributed Component Object Model T1021.005 · VNC T1021.006 · Windows Remote Management× T1021.008 · Direct Cloud VM Connections T1027 · Obfuscated Files or Information T1036 · Masquerading T1036.005 · Match Legitimate Resource Name or Location T1036.007 · Double File Extension× T1036.008 · Masquerade File Type T1037 · Boot or Logon Initialization Scripts T1037.001 · Logon Script (Windows) T1040 · Network Sniffing T1046 · Network Service Discovery T1047 · Windows Management Instrumentation T1048 · Exfiltration Over Alternative Protocol T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol× T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol× T1052 · Exfiltration Over Physical Medium× T1052.001 · Exfiltration over USB T1053 · Scheduled Task/Job T1053.002 · At T1053.005 · Scheduled Task T1059 · Command and Scripting Interpreter T1059.005 · Visual Basic T1059.007 · JavaScript T1059.009 · Cloud API× T1059.010 · AutoHotKey & AutoIT T1068 · Exploitation for Privilege Escalation
Configure the system to provide only {{ insert: param, cm-07_odp.01 }} ; and Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: {{ insert: param, cm-7_prm_2 }}.
family CM framework nist-800-53
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
Review the system {{ insert: param, cm-07.01_odp.01 }} to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services; and Disable or remove {{ insert: param, cm-7.1_prm_2 }}.
family CM framework nist-800-53
Prevent program execution in accordance with {{ insert: param, cm-07.02_odp.01 }}.
family CM framework nist-800-53
Ensure compliance with {{ insert: param, cm-07.03_odp }}.
family CM framework nist-800-53
Identify {{ insert: param, cm-07.04_odp.01 }}; Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system; and Review and update the list of unauthorized software programs {{ insert: param, cm-07.04_odp.02 }}.
family CM framework nist-800-53
Identify {{ insert: param, cm-07.05_odp.01 }}; Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and Review and update the list of authorized software programs {{ insert: param, cm-07.05_odp.02 }}.
family CM framework nist-800-53
Require that the following user-installed software execute in a confined physical or virtual machine environment with limited privileges: {{ insert: param, cm-07.06_odp }}.
family CM framework nist-800-53
Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of {{ insert: param, cm-07.07_odp }} when such code is: Obtained from sources with limited or no warranty; and/or Without the provision of source code.
family CM framework nist-800-53
Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code; and Allow exceptions only for compelling mission or operational requirements and with the approval of the authorizing official.
family CM framework nist-800-53
Identify {{ insert: param, cm-07.09_odp.01 }}; Prohibit the use or connection of unauthorized hardware components; Review and update the list of authorized hardware components {{ insert: param, cm-07.09_odp.02 }}.
family CM framework nist-800-53
Showing 1-11 of 11
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin