NIST SP 800-53 Rev 5: the clauses the register cites
The 10 NIST SP 800-53 Rev 5 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.
The requirement lines are our statement of each clause, read against the copy we hold and cited to it.
10 clauses
the families they anchorSP 800-53 AC-2 Account managementRequires accounts to be managed across their full life cycle: permitted and prohibited account types defined, account managers assigned, membership prerequisites and approvals required, accounts created, modified, disabled and removed under documented criteria, usage monitored, and access reauthorized on a defined frequency.
Where answers usually fall short: Shared and service accounts sit outside the joiner mover leaver process entirely; Recertification is signed off in bulk without any account actually being removed
Source: NIST SP 800-53 Rev 5
SP 800-53 AU-6 Audit record review, analysis, and reportingRequires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.
Where answers usually fall short: Review is automated alerting only, with no periodic analytical review for slow patterns; Findings recorded but never reported to anyone able to act
Source: NIST SP 800-53 Rev 5
SP 800-53 CP-2 Contingency planRequires a contingency plan that identifies essential mission and business functions and their contingency requirements, sets recovery objectives, priorities and metrics, assigns roles and contacts, addresses operating through disruption and full restoration without weakening controls, is approved by defined personnel, distributed to defined recipients, coordinated with related plans, reviewed on a defined frequency and updated after change or testing.
Where answers usually fall short: Plan lists systems but never identifies the business functions they support; Contact details stale, naming people who left the organization
Source: NIST SP 800-53 Rev 5
SP 800-53 CP-9 System backupRequires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.
Where answers usually fall short: Documentation and configuration backed up nowhere, only application data; Backups unencrypted or reachable with the same credentials as production, so ransomware takes both
Source: NIST SP 800-53 Rev 5
SP 800-53 IA-2 Identification and authentication of organizational usersRequires organizational users to be uniquely identified and authenticated, and requires that unique identity to be carried through to the processes that act on their behalf, so that system activity is attributable to a specific person.
Where answers usually fall short: Shared administrative accounts destroy attribution at exactly the highest privilege; Automation runs under a generic identity that hides who initiated the action
Source: NIST SP 800-53 Rev 5
SP 800-53 IR-8 Incident response planRequires an incident response plan that sets the roadmap and structure for the capability, fits it to the organization, defines reportable incidents and success metrics, defines the resources and management support needed, is approved by defined personnel, distributed to defined recipients, reviewed on a defined frequency, updated for change and lessons learned, and protected from unauthorized disclosure and modification.
Where answers usually fall short: Plan defines severity levels but never defines what counts as a reportable incident; Plan stored only on the system it is meant to help recover
Source: NIST SP 800-53 Rev 5
SP 800-53 PS-3 Personnel screeningRequires individuals to be screened before access to the system is authorized, and to be rescreened where organization-defined conditions require it and at the frequency defined for those conditions.
Where answers usually fall short: Access granted on the start date while screening is still in progress; Rescreening conditions never defined, so screening happens once in a career
Source: NIST SP 800-53 Rev 5
SP 800-53 RA-5 Vulnerability monitoring and scanningRequires vulnerability monitoring and scanning of the system and hosted applications at a defined frequency or randomly by a defined process and when new relevant vulnerabilities are reported, using tools and techniques that support standardised enumeration, checklists and impact measurement, with results analysed, remediation within defined response times by risk, results shared with defined personnel, and privileged scanning access where required.
Where answers usually fall short: Unauthenticated scanning only, which understates the real vulnerability position; Remediation timeframes defined but routinely exceeded with no risk acceptance
Source: NIST SP 800-53 Rev 5
SP 800-53 SC-28 Protection of information at restRequires the confidentiality or integrity, as the organization determines, of organization-defined information at rest to be protected, so that stored information is safeguarded independently of the access controls in front of it.
Where answers usually fall short: Primary storage encrypted while backups, exports and logs are not; Encryption keys held beside the data they protect
Source: NIST SP 800-53 Rev 5
SP 800-53 SR-6 Supplier assessments and reviewsRequires assessment and review, at an organization-defined frequency, of the supply chain risk attached to each supplier or contractor and to the particular system, component or service they deliver.
Where answers usually fall short: Assessment performed at onboarding only with no defined review cadence; Assessment covers the supplier's corporate posture but not the specific component supplied
Source: NIST SP 800-53 Rev 5