ASOM-Fedv6.1Open the explorer
Control catalog · National Institute of Standards and Technology

Security and Privacy Controls for Information Systems and Organizations

The federal control catalog, and the identifier scheme every federal security program is already expressed in. Twenty families, and a great many more controls and enhancements than any one framework draws on.

130Identifiers inherited fromAcross 20 of the 20 families — a small fraction of Rev. 5, and lineage rather than implementation.
78Controls carrying itEach with an evidence artifact and an assessment procedure
4Stated boundariesWhat this framework does not do for this regime
The Claim

What This Framework Contributes.

Lineage, not compliance. Each control here names the 800-53 controls it derives from so a reviewer can see what is genuinely new and what is a re-framing — and so nobody mistakes the second for the first.

The Boundary

What it does not do for SP 800-53 Rev. 5.

Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of SP 800-53 Rev. 5 will be wrong in a way that is expensive to discover later.

The Draw

Which Families This Framework Actually Inherits From.

Computed from the catalog’s inherits arrays, so this is the real shape of the inheritance rather than a claim about it. The skew is the interesting part and is not smoothed: a framework about command, terrain and continuity draws hardest on Program Management, which a control catalog is rarely read for.

SP 800-53 familyIdentifiers citedCitationsFramework families drawing on it
Program ManagementPM1434CE, CG, DV, EN, FC, FO, ID, KT, LC, RC, SM, TA, TM, WF
Contingency PlanningCP1016CG, EN, FC, FO, KT, LC, RC, SM, TA
Access ControlAC914CG, DV, FO, ID, KT, LC, TA, TM, WF
System and Communications ProtectionSC914FC, FO, ID, KT, RC, SM, TM
Incident ResponseIR823CG, EN, LC, RC, SM, TA
Risk AssessmentRA816CE, CG, FO, KT, SM, TA, TM
Configuration ManagementCM813DV, KT, LC, RC, TM
Identification and AuthenticationIA810DV, ID, WF
Supply Chain Risk ManagementSR88FO, LC
System and Information IntegritySI712CE, DV, EN, FO, KT, LC, RC, SM, TA
Assessment, Authorization, and MonitoringCA616CE, CG, KT, SM, TM
Audit and AccountabilityAU610CE, DV, EN, ID, RC, TA, WF
Personnel SecurityPS67TA, WF
Physical and Environmental ProtectionPE66FC
System and Services AcquisitionSA46CG, FO, LC
MaintenanceMA44DV, FC
Awareness and TrainingAT33WF
PlanningPL25CE, CG, FO, SM
Media ProtectionMP22DV, FO
Personally Identifiable Information Processing and TransparencyPT22FO

Program Management

PM

Identifiers cited
14
Citations
34
Framework families drawing on it
CE, CG, DV, EN, FC, FO, ID, KT, LC, RC, SM, TA, TM, WF

Contingency Planning

CP

Identifiers cited
10
Citations
16
Framework families drawing on it
CG, EN, FC, FO, KT, LC, RC, SM, TA

Access Control

AC

Identifiers cited
9
Citations
14
Framework families drawing on it
CG, DV, FO, ID, KT, LC, TA, TM, WF

System and Communications Protection

SC

Identifiers cited
9
Citations
14
Framework families drawing on it
FC, FO, ID, KT, RC, SM, TM

Incident Response

IR

Identifiers cited
8
Citations
23
Framework families drawing on it
CG, EN, LC, RC, SM, TA

Risk Assessment

RA

Identifiers cited
8
Citations
16
Framework families drawing on it
CE, CG, FO, KT, SM, TA, TM

Configuration Management

CM

Identifiers cited
8
Citations
13
Framework families drawing on it
DV, KT, LC, RC, TM

Identification and Authentication

IA

Identifiers cited
8
Citations
10
Framework families drawing on it
DV, ID, WF

Supply Chain Risk Management

SR

Identifiers cited
8
Citations
8
Framework families drawing on it
FO, LC

System and Information Integrity

SI

Identifiers cited
7
Citations
12
Framework families drawing on it
CE, DV, EN, FO, KT, LC, RC, SM, TA

Assessment, Authorization, and Monitoring

CA

Identifiers cited
6
Citations
16
Framework families drawing on it
CE, CG, KT, SM, TM

Audit and Accountability

AU

Identifiers cited
6
Citations
10
Framework families drawing on it
CE, DV, EN, ID, RC, TA, WF

Personnel Security

PS

Identifiers cited
6
Citations
7
Framework families drawing on it
TA, WF

Physical and Environmental Protection

PE

Identifiers cited
6
Citations
6
Framework families drawing on it
FC

System and Services Acquisition

SA

Identifiers cited
4
Citations
6
Framework families drawing on it
CG, FO, LC

Maintenance

MA

Identifiers cited
4
Citations
4
Framework families drawing on it
DV, FC

Awareness and Training

AT

Identifiers cited
3
Citations
3
Framework families drawing on it
WF

Planning

PL

Identifiers cited
2
Citations
5
Framework families drawing on it
CE, CG, FO, SM

Media Protection

MP

Identifiers cited
2
Citations
2
Framework families drawing on it
DV, FO

Personally Identifiable Information Processing and Transparency

PT

Identifiers cited
2
Citations
2
Framework families drawing on it
FO

130 distinct identifiers across 20 of the 20 Rev. 5 families, cited 221 times by 78 controls. 28 of the identifiers are control enhancements rather than base controls — named individually where the base control alone would not carry the requirement. The thinnest draw is PL (2), MP (2), PT (2).

The Inversion

Every Inherited Control, and What Derives from It.

This is the direction an assessor works in. They arrive holding IR-4 because somebody asked about it, and the useful answer is the 12 framework controls that stand on it — not a list of what each of those controls inherits.

Awareness and Training

AT · 3 identifiers · 3 citations

Media Protection

MP · 2 identifiers · 2 citations

Personally Identifiable Information Processing and Transparency

PT · 2 identifiers · 2 citations

Derived. Every edge is the inverse of an `inherits` array in the published catalog. Family names come from the provenance register, which the same catalog is checked against. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.