Security and Privacy Controls for Information Systems and Organizations
This publication provides a catalog of security and privacy controls for federal information
systems and organizations and a process for selecting controls to protect organizational operations
(including mission, functions, image, and reputation), organizational assets, individuals, other
organizations, and the Nation from a diverse set of threats including hostile cyber attacks, natural
disasters, structural failures, and human errors. The controls are customizable and implemented as
part of an organization-wide process that manages information security and privacy risk.
Link to SP800-53 Rev 4 (Published)
Link to SP 800-53 Rev. 5 (DRAFT)