Security and Privacy Controls for Information Systems and Organizations
The federal control catalog, and the identifier scheme every federal security program is already expressed in. Twenty families, and a great many more controls and enhancements than any one framework draws on.
What This Framework Contributes.
Lineage, not compliance. Each control here names the 800-53 controls it derives from so a reviewer can see what is genuinely new and what is a re-framing — and so nobody mistakes the second for the first.
- For any cited 800-53 identifier, the framework controls that derive from it, with what each one adds beyond the original: position, tempo, or an accountable owner.
- A reason to look at Program Management and Contingency Planning, which a control catalog is rarely read for and which this framework draws on heavily.
- An assessment procedure and a named evidence artifact against every derived control, which is the part an assessor is actually handed.
What it does not do for SP 800-53 Rev. 5.
Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of SP 800-53 Rev. 5 will be wrong in a way that is expensive to discover later.
- Baselines and tailoring.No low, moderate or high baseline is published here, and the framework does not tell an agency which of its controls apply. Categorization is the agency’s, made under its own authority.
- Implementation of anything cited.Deriving from AC-4 is not implementing AC-4. The derived control asks a different question — whether the flow is on the map and whether crossing it is observed — and answering it well leaves the original obligation exactly where it was.
- Coverage of the catalog.The identifiers cited below are a small fraction of Rev. 5. ASOM-Fed is not a restatement of 800-53, is not a substitute for it, and implementing it does not satisfy it.
- Enhancement-level rigour beyond what is cited.Where an enhancement is named it is because the base control alone would not carry the requirement. Where one is not named, no claim is made about it — absence here is silence, not a negative finding.
Which Families This Framework Actually Inherits From.
Computed from the catalog’s inherits arrays, so this is the real shape of the inheritance rather than a claim about it. The skew is the interesting part and is not smoothed: a framework about command, terrain and continuity draws hardest on Program Management, which a control catalog is rarely read for.
| SP 800-53 family | Identifiers cited | Citations | Framework families drawing on it |
|---|---|---|---|
| Program ManagementPM | 14 | 34 | CE, CG, DV, EN, FC, FO, ID, KT, LC, RC, SM, TA, TM, WF |
| Contingency PlanningCP | 10 | 16 | CG, EN, FC, FO, KT, LC, RC, SM, TA |
| Access ControlAC | 9 | 14 | CG, DV, FO, ID, KT, LC, TA, TM, WF |
| System and Communications ProtectionSC | 9 | 14 | FC, FO, ID, KT, RC, SM, TM |
| Incident ResponseIR | 8 | 23 | CG, EN, LC, RC, SM, TA |
| Risk AssessmentRA | 8 | 16 | CE, CG, FO, KT, SM, TA, TM |
| Configuration ManagementCM | 8 | 13 | DV, KT, LC, RC, TM |
| Identification and AuthenticationIA | 8 | 10 | DV, ID, WF |
| Supply Chain Risk ManagementSR | 8 | 8 | FO, LC |
| System and Information IntegritySI | 7 | 12 | CE, DV, EN, FO, KT, LC, RC, SM, TA |
| Assessment, Authorization, and MonitoringCA | 6 | 16 | CE, CG, KT, SM, TM |
| Audit and AccountabilityAU | 6 | 10 | CE, DV, EN, ID, RC, TA, WF |
| Personnel SecurityPS | 6 | 7 | TA, WF |
| Physical and Environmental ProtectionPE | 6 | 6 | FC |
| System and Services AcquisitionSA | 4 | 6 | CG, FO, LC |
| MaintenanceMA | 4 | 4 | DV, FC |
| Awareness and TrainingAT | 3 | 3 | WF |
| PlanningPL | 2 | 5 | CE, CG, FO, SM |
| Media ProtectionMP | 2 | 2 | DV, FO |
| Personally Identifiable Information Processing and TransparencyPT | 2 | 2 | FO |
Program Management
PM
- Identifiers cited
- 14
- Citations
- 34
- Framework families drawing on it
- CE, CG, DV, EN, FC, FO, ID, KT, LC, RC, SM, TA, TM, WF
Contingency Planning
CP
- Identifiers cited
- 10
- Citations
- 16
- Framework families drawing on it
- CG, EN, FC, FO, KT, LC, RC, SM, TA
Access Control
AC
- Identifiers cited
- 9
- Citations
- 14
- Framework families drawing on it
- CG, DV, FO, ID, KT, LC, TA, TM, WF
System and Communications Protection
SC
- Identifiers cited
- 9
- Citations
- 14
- Framework families drawing on it
- FC, FO, ID, KT, RC, SM, TM
Incident Response
IR
- Identifiers cited
- 8
- Citations
- 23
- Framework families drawing on it
- CG, EN, LC, RC, SM, TA
Risk Assessment
RA
- Identifiers cited
- 8
- Citations
- 16
- Framework families drawing on it
- CE, CG, FO, KT, SM, TA, TM
Configuration Management
CM
- Identifiers cited
- 8
- Citations
- 13
- Framework families drawing on it
- DV, KT, LC, RC, TM
Identification and Authentication
IA
- Identifiers cited
- 8
- Citations
- 10
- Framework families drawing on it
- DV, ID, WF
Supply Chain Risk Management
SR
- Identifiers cited
- 8
- Citations
- 8
- Framework families drawing on it
- FO, LC
System and Information Integrity
SI
- Identifiers cited
- 7
- Citations
- 12
- Framework families drawing on it
- CE, DV, EN, FO, KT, LC, RC, SM, TA
Assessment, Authorization, and Monitoring
CA
- Identifiers cited
- 6
- Citations
- 16
- Framework families drawing on it
- CE, CG, KT, SM, TM
Audit and Accountability
AU
- Identifiers cited
- 6
- Citations
- 10
- Framework families drawing on it
- CE, DV, EN, ID, RC, TA, WF
Personnel Security
PS
- Identifiers cited
- 6
- Citations
- 7
- Framework families drawing on it
- TA, WF
Physical and Environmental Protection
PE
- Identifiers cited
- 6
- Citations
- 6
- Framework families drawing on it
- FC
System and Services Acquisition
SA
- Identifiers cited
- 4
- Citations
- 6
- Framework families drawing on it
- CG, FO, LC
Maintenance
MA
- Identifiers cited
- 4
- Citations
- 4
- Framework families drawing on it
- DV, FC
Awareness and Training
AT
- Identifiers cited
- 3
- Citations
- 3
- Framework families drawing on it
- WF
Planning
PL
- Identifiers cited
- 2
- Citations
- 5
- Framework families drawing on it
- CE, CG, FO, SM
Media Protection
MP
- Identifiers cited
- 2
- Citations
- 2
- Framework families drawing on it
- DV, FO
Personally Identifiable Information Processing and Transparency
PT
- Identifiers cited
- 2
- Citations
- 2
- Framework families drawing on it
- FO
130 distinct identifiers across 20 of the 20 Rev. 5 families, cited 221 times by 78 controls. 28 of the identifiers are control enhancements rather than base controls — named individually where the base control alone would not carry the requirement. The thinnest draw is PL (2), MP (2), PT (2).
Every Inherited Control, and What Derives from It.
This is the direction an assessor works in. They arrive holding IR-4 because somebody asked about it, and the useful answer is the 12 framework controls that stand on it — not a list of what each of those controls inherits.
Program Management
PM · 14 identifiers · 34 citations- PM-1
- PM-4
- PM-5
- PM-6
- PM-7
- PM-8
- PM-9
- PM-10
- PM-11
- PM-12
- PM-16
- PM-29
- PM-30
- PM-31
Contingency Planning
CP · 10 identifiers · 16 citations- CP-2
- CP-2(3)enhancement
- CP-2(7)enhancement
- CP-2(8)enhancement
- CP-4
- CP-4(1)enhancement
- CP-6
- CP-9(1)enhancement
- CP-9(3)enhancement
- CP-10
Access Control
AC · 9 identifiers · 14 citations- AC-2
- AC-2(3)enhancement
- AC-2(7)enhancement
- AC-2(13)enhancement
- AC-3
- AC-4
- AC-6
- AC-20
- AC-21
System and Communications Protection
SC · 9 identifiers · 14 citations- SC-5
- SC-7
- SC-7(5)enhancement
- SC-7(21)enhancement
- SC-8
- SC-23
- SC-26
- SC-28
- SC-30
Incident Response
IR · 8 identifiers · 23 citations- IR-3
- IR-4SM-5 Branches and Sequels, TA-1 Decision Loop Measurement, TA-3 Temporal Advantage Threshold, TA-5 Tempo Degradation Trigger, CG-2 Phase Declaration, CG-3 Rules of Engagement, LC-5 Supplier Severance Capability, EN-1 Event Declaration and Triage, EN-2 Engagement Reconstruction, EN-3 Evidence Preservation, EN-4 Escalation and Engagement Authority, EN-5 Eradication and Transition to Recovery
- IR-4(2)enhancement
- IR-4(4)enhancement
- IR-5
- IR-6
- IR-7
- IR-9
Risk Assessment
RA · 8 identifiers · 16 citations- RA-2
- RA-3
- RA-3(4)enhancement
- RA-5
- RA-7
- RA-8
- RA-9
- RA-10
Configuration Management
CM · 8 identifiers · 13 citations- CM-2
- CM-3
- CM-6
- CM-7
- CM-7(5)enhancement
- CM-8
- CM-8(1)enhancement
- CM-8(4)enhancement
Identification and Authentication
IA · 8 identifiers · 10 citations- IA-2
- IA-2(1)enhancement
- IA-3
- IA-5
- IA-5(2)enhancement
- IA-8
- IA-9
- IA-12
Supply Chain Risk Management
SR · 8 identifiers · 8 citations- SR-2
- SR-3
- SR-4
- SR-5
- SR-6
- SR-8
- SR-11
- SR-11(1)enhancement
System and Information Integrity
SI · 7 identifiers · 12 citations- SI-2
- SI-4
- SI-4(16)enhancement
- SI-4(20)enhancement
- SI-5
- SI-7
- SI-7(1)enhancement
Assessment, Authorization, and Monitoring
CA · 6 identifiers · 16 citations- CA-2
- CA-3
- CA-5
- CA-7
- CA-7(3)enhancement
- CA-8
Audit and Accountability
AU · 6 identifiers · 10 citations- AU-2
- AU-6
- AU-6(9)enhancement
- AU-9
- AU-11
- AU-12
Personnel Security
PS · 6 identifiers · 7 citations- PS-2
- PS-3
- PS-4
- PS-5
- PS-7
- PS-8
Physical and Environmental Protection
PE · 6 identifiers · 6 citations- PE-2
- PE-3
- PE-3(1)enhancement
- PE-5
- PE-11
- PE-13
System and Services Acquisition
SA · 4 identifiers · 6 citations- SA-4
- SA-9
- SA-9(2)enhancement
- SA-10
Maintenance
MA · 4 identifiers · 4 citations- MA-2
- MA-3
- MA-4
- MA-5
Awareness and Training
AT · 3 identifiers · 3 citations- AT-2
- AT-2(1)enhancement
- AT-3
Planning
PL · 2 identifiers · 5 citations- PL-1
- PL-2
Media Protection
MP · 2 identifiers · 2 citations- MP-4
- MP-6
Personally Identifiable Information Processing and Transparency
PT · 2 identifiers · 2 citations- PT-2
- PT-3
Derived. Every edge is the inverse of an `inherits` array in the published catalog. Family names come from the provenance register, which the same catalog is checked against. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.