Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Security and Privacy Controls for Federal Information Systems and Organizations [includes updates as of 5/7/13]



Ronald S. Ross


[Superseded by NIST SP 800-53 Rev. 4 (April 2013 w/ updates through 1/15/14):] This publication provides a catalog of security and privacy controls for federal information systems and organizations and a process for selecting controls to protect organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation from a diverse set of threats including hostile cyber attacks, natural disasters, structural failures, and human errors (both intentional and unintentional). The security and privacy controls are customizable and implemented as part of an organization-wide process that manages information security and privacy risk. The controls address a diverse set of security and privacy requirements across the federal government and critical infrastructure, derived from legislation, Executive Orders, policies, directives, regulations, standards, and/or mission/business needs. The publication also describes how to develop specialized sets of controls, or overlays, tailored for specific types of missions/business functions, technologies, or environments of operation. Finally, the catalog of security controls addresses security from both a functionality perspective (the strength of security functions and mechanisms provided) and an assurance perspective (the measures of confidence in the implemented security capability). Addressing both security functionality and assurance helps to ensure that information technology component products and the information systems built from those products using sound system and security engineering principles are sufficiently trustworthy. [Supersedes NIST SP 800-53 Rev. 4 (April 2013):]
Special Publication (NIST SP) - 800-53 Rev 4
Report Number
800-53 Rev 4


assurance, computer security, FIPS Publication 199, FIPS Publication 200, FISMA, Privacy Act, Risk Management Framework, security controls, security requirements


Ross, R. (2013), Security and Privacy Controls for Federal Information Systems and Organizations [includes updates as of 5/7/13], Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD (Accessed May 22, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created May 7, 2013, Updated January 27, 2020