Home/Compliance
nist-800-53

NIST 800-53. Security Controls

31 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
1246
Total controls
0%
Detection coverage
0
Covered controls
1246
Coverage gaps
▤ Export audit (CSV) Coverage report Self-assessment Show gaps only
▶ Check your own detection coverage

Paste the ATT&CK technique IDs you have Sigma/YARA rules for (one per line, e.g. T1059, T1190). The controls below will update to show YOUR coverage instead of ours.

Red team insight A nist-800-53 compliant org should have detection for the green-tagged techniques below. Controls showing no technique coverage are likely blind spots. Use gaps view to enumerate unmonitored attack paths.

Controls

31 shown of 31
family SC framework nist-800-53
ATT&CK techniques this control defends against   ✓ covered by Sigma/YARA in our corpus  × = detection gap
T1001 · Data Obfuscation× T1001.001 · Junk Data× T1001.002 · Steganography T1001.003 · Protocol or Service Impersonation T1008 · Fallback Channels× T1020.001 · Traffic Duplication T1021.001 · Remote Desktop Protocol T1021.002 · SMB/Windows Admin Shares T1021.003 · Distributed Component Object Model T1021.005 · VNC T1021.006 · Windows Remote Management T1029 · Scheduled Transfer T1030 · Data Transfer Size Limits× T1036.008 · Masquerade File Type T1041 · Exfiltration Over C2 Channel T1046 · Network Service Discovery T1048 · Exfiltration Over Alternative Protocol T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol× T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol T1055 · Process Injection T1055.001 · Dynamic-link Library Injection× T1055.002 · Portable Executable Injection T1055.003 · Thread Execution Hijacking× T1055.004 · Asynchronous Procedure Call× T1055.005 · Thread Local Storage T1055.008 · Ptrace System Calls T1055.009 · Proc Memory T1055.011 · Extra Window Memory Injection T1055.012 · Process Hollowing× T1055.013 · Process Doppelgänging× T1055.014 · VDSO Hijacking T1068 · Exploitation for Privilege Escalation T1071 · Application Layer Protocol T1071.001 · Web Protocols× T1071.002 · File Transfer Protocols× T1071.003 · Mail Protocols T1071.004 · DNS× T1071.005 · Publish/Subscribe Protocols T1072 · Software Deployment Tools
Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; Implement subnetworks for publicly accessible system components that are {{ insert: param, sc-07_odp }} separated from internal organizational networks; and Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
family SC framework nist-800-53
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
family SC framework nist-800-53
Prevent the exfiltration of information; and Conduct exfiltration tests {{ insert: param, sc-07.10_odp }}.
family SC framework nist-800-53
Only allow incoming communications from {{ insert: param, sc-07.11_odp.01 }} to be routed to {{ insert: param, sc-07.11_odp.02 }}.
family SC framework nist-800-53
Implement {{ insert: param, sc-07.12_odp.01 }} at {{ insert: param, sc-07.12_odp.02 }}.
family SC framework nist-800-53
Isolate {{ insert: param, sc-07.13_odp }} from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.
family SC framework nist-800-53
Protect against unauthorized physical connections at {{ insert: param, sc-07.14_odp }}.
family SC framework nist-800-53
Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.
family SC framework nist-800-53
Prevent the discovery of specific system components that represent a managed interface.
family SC framework nist-800-53
Enforce adherence to protocol formats.
family SC framework nist-800-53
Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.
family SC framework nist-800-53
Block inbound and outbound communications traffic between {{ insert: param, sc-07.19_odp }} that are independently configured by end users and external service providers.
family SC framework nist-800-53
family SC framework nist-800-53
Provide the capability to dynamically isolate {{ insert: param, sc-07.20_odp }} from other system components.
family SC framework nist-800-53
Employ boundary protection mechanisms to isolate {{ insert: param, sc-07.21_odp.01 }} supporting {{ insert: param, sc-07.21_odp.02 }}.
family SC framework nist-800-53
Implement separate network addresses to connect to systems in different security domains.
family SC framework nist-800-53
Disable feedback to senders on protocol format validation failure.
family SC framework nist-800-53
For systems that process personally identifiable information: Apply the following processing rules to data elements of personally identifiable information: {{ insert: param, sc-07.24_odp }}; Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system; Document each processing exception; and Review and remove exceptions that are no longer supported.
family SC framework nist-800-53
Prohibit the direct connection of {{ insert: param, sc-07.25_odp.01 }} to an external network without the use of {{ insert: param, sc-07.25_odp.02 }}.
family SC framework nist-800-53
Prohibit the direct connection of a classified national security system to an external network without the use of {{ insert: param, sc-07.26_odp }}.
family SC framework nist-800-53
Prohibit the direct connection of {{ insert: param, sc-07.27_odp.01 }} to an external network without the use of {{ insert: param, sc-07.27_odp.02 }}.
family SC framework nist-800-53
Prohibit the direct connection of {{ insert: param, sc-07.28_odp }} to a public network.
family SC framework nist-800-53
Implement {{ insert: param, sc-07.29_odp.01 }} separate subnetworks to isolate the following critical system components and functions: {{ insert: param, sc-07.29_odp.02 }}.
family SC framework nist-800-53
Limit the number of external network connections to the system.
family SC framework nist-800-53
Implement a managed interface for each external telecommunication service; Establish a traffic flow policy for each managed interface; Protect the confidentiality and integrity of the information being transmitted across each interface; Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need; Review exceptions to the traffic flow policy {{ insert: param, sc-07.04_odp }} and remove exceptions that are no longer supported by an explicit mission or business need; Prevent unauthorized exchange of control plane traffic with external networks; Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and Filter unauthorized control plane traffic from external networks.
family SC framework nist-800-53
Deny network communications traffic by default and allow network communications traffic by exception {{ insert: param, sc-07.05_odp.01 }}.
family SC framework nist-800-53
family SC framework nist-800-53
Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using {{ insert: param, sc-07.07_odp }}.
family SC framework nist-800-53
Route {{ insert: param, sc-07.08_odp.01 }} to {{ insert: param, sc-07.08_odp.02 }} through authenticated proxy servers at managed interfaces.
family SC framework nist-800-53
Detect and deny outgoing communications traffic posing a threat to external systems; and Audit the identity of internal users associated with denied communications.
family SC framework nist-800-53
Showing 1-31 of 31
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin