Home/Compliance
nist-800-53

NIST 800-53. Security Controls

13 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
1246
Total controls
0%
Detection coverage
0
Covered controls
1246
Coverage gaps
▤ Export audit (CSV) Coverage report Self-assessment Show gaps only
▶ Check your own detection coverage

Paste the ATT&CK technique IDs you have Sigma/YARA rules for (one per line, e.g. T1059, T1190). The controls below will update to show YOUR coverage instead of ours.

Red team insight A nist-800-53 compliant org should have detection for the green-tagged techniques below. Controls showing no technique coverage are likely blind spots. Use gaps view to enumerate unmonitored attack paths.

Controls

13 shown of 13
family RA framework nist-800-53
ATT&CK techniques this control defends against   ✓ covered by Sigma/YARA in our corpus  × = detection gap
× T1011.001 · Exfiltration Over Bluetooth T1021.001 · Remote Desktop Protocol T1021.003 · Distributed Component Object Model T1021.004 · SSH T1021.005 · VNC T1021.006 · Windows Remote Management T1046 · Network Service Discovery T1047 · Windows Management Instrumentation× T1052 · Exfiltration Over Physical Medium× T1052.001 · Exfiltration over USB T1053 · Scheduled Task/Job T1053.002 · At T1053.003 · Cron T1053.005 · Scheduled Task T1059 · Command and Scripting Interpreter T1059.001 · PowerShell T1059.005 · Visual Basic T1059.007 · JavaScript T1068 · Exploitation for Privilege Escalation T1078 · Valid Accounts T1091 · Replication Through Removable Media× T1092 · Communication Through Removable Media T1098.004 · SSH Authorized Keys T1127 · Trusted Developer Utilities Proxy Execution T1127.001 · MSBuild× T1127.002 · ClickOnce T1133 · External Remote Services T1137 · Office Application Startup× T1137.001 · Office Template Macros× T1176 · Software Extensions T1190 · Exploit Public-Facing Application T1195 · Supply Chain Compromise T1195.001 · Compromise Software Dependencies and Development Tools T1195.002 · Compromise Software Supply Chain× T1204.003 · Malicious Image T1210 · Exploitation of Remote Services T1211 · Exploitation for Stealth T1212 · Exploitation for Credential Access T1213 · Data from Information Repositories× T1213.001 · Confluence
Monitor and scan for vulnerabilities in the system and hosted applications {{ insert: param, ra-5_prm_1 }} and when new vulnerabilities potentially affecting the system are identified and reported; Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: Enumerating platforms, software flaws, and improper configurations; Formatting checklists and test procedures; and Measuring vulnerability impact; Analyze vulnerability scan reports and results from vulnerability monitoring; Remediate legitimate vulnerabilities {{ insert: param, ra-05_odp.03 }} in accordance with an organizational assessment of risk; Share information obtained from the vulnerability monitoring process and control assessments with {{ insert: param, ra-05_odp.04 }} to help eliminate similar vulnerabilities in other systems; and Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.
family RA framework nist-800-53
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family RA framework nist-800-53
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
family RA framework nist-800-53
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
family RA framework nist-800-53
Update the system vulnerabilities to be scanned {{ insert: param, ra-05.02_odp.01 }}.
family RA framework nist-800-53
Define the breadth and depth of vulnerability scanning coverage.
family RA framework nist-800-53
Determine information about the system that is discoverable and take {{ insert: param, ra-05.04_odp }}.
family RA framework nist-800-53
Implement privileged access authorization to {{ insert: param, ra-05.05_odp.01 }} for {{ insert: param, ra-05.05_odp.02 }}.
family RA framework nist-800-53
Compare the results of multiple vulnerability scans using {{ insert: param, ra-05.06_odp }}.
family RA framework nist-800-53
Review historic audit logs to determine if a vulnerability identified in a {{ insert: param, ra-05.08_odp.01 }} has been previously exploited within an {{ insert: param, ra-05.08_odp.02 }}.
family RA framework nist-800-53
family RA framework nist-800-53
Showing 1-13 of 13
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin