nist-800-53

Guides NIST SP 800-53 Rev 5 control selection, tailoring, assessment, and RMF authorization workflows.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nist-800-53-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nist-800-53
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/nist-800-53
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nist-800-53-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Federal agencies, contractors, and cloud providers must navigate hundreds of NIST SP 800-53 Rev 5 controls across 20 families, select the right Low/Moderate/High baseline, write SSP narratives, and pass assessments — a process that is error-prone and time-consuming without structured guidance. ## Core Features & Use Cases - Baseline Selection & Categorization: Walks through FIPS 199 impact categorization and SP 800-53B Low/Moderate/High baseline selection with tailoring and overlay guidance. - Control-by-Control Reference: Covers all 20 families (AC through SR) with baseline assignments, enhancement details, and implementation tips via reference files. - Assessment & RMF Support: Provides SP 800-53A assessment procedures, POA&M management, RMF step-by-step guidance, OSCAL, and mapping to FedRAMP, FISMA, CMMC 2.0, ISO 27001, and CSF 2.0. - Use Case: A cloud service provider preparing for FedRAMP can ask for a gap assessment table of the Moderate baseline, then generate SSP narratives for AC and IA families with correct ODVs. ## Quick Start Ask the assistant to select and tailor a NIST SP 800-53 Moderate baseline for a system that processes PII, including control narratives for the AC family.

Frequently Asked Questions about nist-800-53

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I select a NIST SP 800-53 baseline for my system?

Baseline selection starts with FIPS 199 categorization: assess the impact of a breach on confidentiality, integrity, and availability, then take the high-water mark. Low impact maps to the Low baseline (~156 controls), Moderate to ~323, and High to ~422 controls per SP 800-53B.

What is the difference between SP 800-53 Low, Moderate, and High baselines?

The baselines differ in control count and rigor: Low covers fundamental protections, Moderate adds automation, least privilege, encryption at rest, and supply chain controls, while High adds penetration testing, threat hunting, non-repudiation, and tamper resistance. Baselines are defined in SP 800-53B.

How does NIST SP 800-53 map to FedRAMP and CMMC 2.0?

FedRAMP uses the SP 800-53 Moderate or High baseline with FedRAMP-specific overlay parameters and 3PAO assessment. CMMC 2.0 Level 2 is based on NIST SP 800-171, which derives from the SP 800-53 Moderate baseline, with mappings in SP 800-171 Appendix D.

What should a NIST SP 800-53 SSP control narrative include?

An SSP narrative includes the implementation status, a system-specific implementation description naming tools and processes, responsible roles, and evidence artifacts. Avoid generic statements and address all organization-defined values and enhancements.

When are privacy controls from the PT family required?

PT family controls are required for any system that processes PII, regardless of its FIPS 199 impact level. They address consent, privacy notices, SORN publication under the Privacy Act, and computer matching requirements.

What are the limitations of this NIST 800-53 guidance?

The skill provides general compliance information, not legal advice, and its content reflects SP 800-53 Rev 5 as of its last verification date. Users should verify current requirements against official NIST publications and consult accredited assessors for authorization decisions.