SP 800-53 Rev. 5NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
National Institute of Standards and Technology
The federal control catalog. Every control this framework publishes names the 800-53 controls it derives from, and the distribution of those references is computed below rather than described.
What this framework takes- Descent, recorded per control. Each entry publishes the 800-53 identifiers it grew out of, which is what allows the twelve genuinely new controls to be counted rather than asserted.
- The grammar of a control: a normative statement of what the organization shall do, separated from the discussion of why it exists.
- The family structure as the index against which lineage is expressed.
What it does not take- Baselines and tailoring.Nothing resembling a low, moderate or high baseline is taken from 800-53, and none is invented to replace it. Which controls apply is a categorization decision, and that decision belongs to the agency making it.
- Control enhancements and the overlay mechanism.Lineage is expressed at the control level. Claiming enhancement-level derivation would imply a rigour of mapping that has not been performed.
- Any claim of coverage.What is cited amounts to a small fraction of Rev. 5, and the direction of the debt runs one way: this framework borrows from 800-53 and returns nothing to it. Implementing one does not discharge the other.
SP 800-37 (RMF)NIST SP 800-37, Risk Management Framework for Information Systems and Organizations
National Institute of Standards and Technology
The lifecycle that carries a federal system from categorization through authorization and then holds it under continuous monitoring — seven steps, of which only the last turns more than once.
What this framework takes- The authorization boundary as the scope statement. Terrain is mapped inside a boundary that already exists, so the overlay can be reconciled against the system inventory rather than invented beside it.
- The Authorizing Official as the commander analog: the accountable person who owns the risk and therefore owns the intent.
- The outer ring of the RMF, which the operating cycle turns inside. What is taken is the obligation to keep watching; what is added is a cadence, a clock and a record for doing it.
What it does not take- The authorization decision.What the RMF requires as evidence — the system security plan, the assessment report, the plan of action and milestones, each in its prescribed form — is not among the artifacts this framework emits, and no route from one to the other is implied.
- The assessment cadence.The lifecycle is inherited; its cadence is not. A defense that re-examines itself on an anniversary is the exact tempo problem the operating cycle was built to answer.
- Categorization.Defensive weight is borrowed from nowhere in FIPS 199 and is not offered back to it. The two numbers answer different questions, and substituting one for the other would put an editorial figure where a statutory determination is required.
CSF 2.0The NIST Cybersecurity Framework 2.0
National Institute of Standards and Technology
The six-function outcome framework — govern, identify, protect, detect, respond, recover — whose subcategory identifiers have become the common index for describing security outcomes across agencies and vendors.
What this framework takes- Subcategory identifiers as an index. An agency already reporting in CSF terms can find the ASOM-Fed controls that bear on a subcategory without a translation exercise.
- The Govern function’s existence as first-class. Command and intent are governance outcomes here, not a preamble to the technical ones.
What it does not take- Tiers and Profiles.The five pillars are taken; the four-stage scale is left where it is. An estate graded on two scales at once yields two verdicts and no principled way to pick one, so capability is scored here on the framework’s own scale and reported under the pillar names an agency already files against.
- Even coverage of the six functions.The citation distribution below is lopsided and is published lopsided. Respond is cited through a single subcategory, because what this framework has to say about responding sits in the maneuver catalog and the phase model, neither of which is a control. An agency that needs CSF Respond coverage should not take it from here.
CISA ZTMMCISA Zero Trust Maturity Model
Cybersecurity and Infrastructure Security Agency
CISA’s maturity model for federal zero trust, and the vocabulary an agency is already reporting against: five pillars carrying three cross-cutting capabilities, graded traditional through optimal.
What this framework takes- The five pillars, verbatim and deliberately unrenamed, as terrain layers T1 through T5. An agency already reporting ZTMM maturity should not have to translate its own reporting to read this framework.
- The four stages, reused as the rungs a sub-tower is scored on and as the arithmetic behind the coverage percentage that rolls up into residual risk.
- The cross-cutting capabilities, which become the cross-cutting terrain — visibility, automation and governance are enablers of movement rather than ground to be held.
What it does not take- The pillar set as complete.Operational technology, workforce, facilities and supply chain are added, each covering ground a federal estate really holds and the five pillars leave unaddressed. The table below derives which layers are inherited and which are ours, rather than asserting it.
- Maturity read as progress.A layer’s stage says what the estate can currently do on that ground, not how well the program is performing. The framework scores coverage per sub-tower for that reason — an estate with excellent authentication and no privileged-access control averages to a respectable number and will still be lost.
- The assumption that Optimal is universally reachable.Several sub-towers on operational-technology ground cannot reach the top rung without a vendor change the agency does not control. That ceiling is recorded against the terrain rather than reported as a permanent failure.
SP 800-207NIST SP 800-207, Zero Trust Architecture
National Institute of Standards and Technology
The architectural definition of zero trust, and the policy decision point / policy enforcement point vocabulary that makes it concrete.
What this framework takes- The policy decision point and policy enforcement point as named elements on the terrain overlay, which is what allows a decisive point to be a specific thing rather than an important-sounding system.
- The principle that trust is evaluated per request, which is what makes identity the high ground rather than one control family among many.
What it does not take- The deployment variants.The document sets out several architectural approaches. Choosing between them is an agency engineering decision; the framework needs only that the decision points be locatable on the map.
TIC 3.0Trusted Internet Connections 3.0
Cybersecurity and Infrastructure Security Agency
The federal program that replaced a single physical internet gateway with trust zones and distributed policy enforcement, and the capability catalog that goes with it.
What this framework takes- Trust zones and policy enforcement points as the boundary vocabulary the terrain overlay is drawn in, so that zone crossings on the map are the same crossings an agency already documents.
- The perimeter sub-tower’s content, expressed in the program’s own capability language.
What it does not take- The use cases as an architecture prescription.Which use case an agency adopts is left open. The requirement is narrower: whichever boundaries exist belong on the map, and traffic crossing them has to be observed.
FISMAThe Federal Information Security Modernization Act
United States statute
The statute the whole federal obligation set descends from, and the reason a federal estate is different ground to defend than a commercial one.
What this framework takes- The obligation treated as terrain rather than as paperwork. Privacy, controlled unclassified information, shared tenancy, statutory availability and the supply chain are ground the framework defends, which is why they form a control family of their own.
- The requirement that a program be assessed rather than described, which is why every control here carries an assessment procedure and an evidence artifact.
What it does not take- Reporting instrumentation.The framework produces no FISMA metrics submission and no inspector-general evaluation score, and is not a substitute for either.
- Compliance as the objective.A compliant estate can still be lost. Statutory obligation sets a floor that the framework treats as ground to be defended, not as the definition of a successful defense.
OMB M-22-09OMB M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
Office of Management and Budget (2022)
The federal zero-trust strategy memorandum: a set of specific end-state goals across identity, devices, networks, applications and data, with dates attached.
What this framework takes- The concrete end states — phishing-resistant multifactor authentication, endpoint detection and response, encryption in transit, meaningful segmentation, application-layer testing — as outcomes the maneuver catalog must actually be able to produce. A form of maneuver that cannot be traced to one of them is decoration.
- The principle that a strategy carries dates. Tempo thresholds here are stated as numbers with owners for the same reason.
What it does not take- The action-item list as an adoption plan.The memorandum sequences by deadline. This framework sequences by what the next phase of a defensive campaign requires, and the two orders are not the same. Where they conflict, the deadline is the agency’s obligation and the framework yields to it.
- Applicability.The memorandum binds specific agencies under its own terms. Nothing here extends, interprets or restates that scope.