NIST 800-53 Rev 5 Scanning
Scan AWS, Azure and GCP against NIST 800-53 Rev 5 technical controls.
NIST Special Publication 800-53 Revision 5 guide.
Overview
NIST 800-53 is a catalog of security and privacy controls for federal information systems.
Who needs it: Federal contractors, FedRAMP Cloud Service Providers
Certification: Not a certification itself (used by FedRAMP, FISMA)
Total controls: 1,196 controls
AuditKit coverage: 149 automated technical controls, reached through the SOC 2 / PCI / CMMC crosswalk
What's not covered: the remaining 1,047 organizational and policy controls
How AuditKit Uses 800-53
Framework crosswalk: AuditKit maps existing SOC2, PCI-DSS, and CMMC controls to NIST 800-53 control families.
Example:
Your SOC2 control: CC6.6 - MFA enforcement
Maps to NIST 800-53:
- IA-2: Identification and Authentication
- IA-2(1): Multi-Factor Authentication
- IA-5: Authenticator Management
Benefit: Run one scan, see compliance across all frameworks
Control Families
NIST 800-53 has 20 control families. AuditKit reaches controls in 18 of them; PT (Personally Identifiable Information Processing) and SR (Supply Chain Risk Management) have no automated coverage:
AC - Access Control
AuditKit checks: IAM policies, MFA, least privilege, access key rotation
Example controls:
- AC-2: Account Management
- AC-3: Access Enforcement
- AC-17: Remote Access
AU - Audit and Accountability
AuditKit checks: CloudTrail, logging, log retention, audit trails
Example controls:
- AU-2: Event Logging
- AU-3: Content of Audit Records
- AU-12: Audit Record Generation
CA - Assessment, Authorization, & Monitoring
AuditKit checks: Security Hub, Config, compliance monitoring
Example controls:
- CA-7: Continuous Monitoring
CM - Configuration Management
AuditKit checks: Config baselines, change tracking, patch management
Example controls:
- CM-2: Baseline Configuration
- CM-6: Configuration Settings
IA - Identification and Authentication
AuditKit checks: MFA, password policies, authenticator management
Example controls:
- IA-2: Identification and Authentication
- IA-5: Authenticator Management
IR - Incident Response
AuditKit checks: GuardDuty, Defender, Security Command Center, alerting
Example controls:
- IR-4: Incident Handling
- IR-6: Incident Reporting
MA - Maintenance
AuditKit checks: Systems Manager, Update Management, maintenance windows
Example controls:
- MA-2: Controlled Maintenance
MP - Media Protection
AuditKit checks: Storage encryption, secure deletion policies
Example controls:
- MP-5: Media Transport
PE - Physical and Environmental Protection
What AuditKit checks: Limited - mostly manual verification
PL - Planning
What AuditKit checks: Limited - mostly organizational policies
PM - Program Management
What AuditKit checks: Limited - mostly organizational policies
PS - Personnel Security
What AuditKit checks: Limited - mostly organizational policies
RA - Risk Assessment
AuditKit checks: Vulnerability scanning, threat detection
Example controls:
- RA-5: Vulnerability Monitoring and Scanning
SA - System and Services Acquisition
What AuditKit checks: Limited - mostly organizational policies
SC - System and Communications Protection
AuditKit checks: Encryption, network segmentation, firewalls, TLS
Example controls:
- SC-7: Boundary Protection
- SC-8: Transmission Confidentiality
- SC-13: Cryptographic Protection
SI - System and Information Integrity
AuditKit checks: Malware protection, patch management, flaw remediation
Example controls:
- SI-2: Flaw Remediation
- SI-3: Malicious Code Protection
SR - Supply Chain Risk Management
What AuditKit checks: Limited - mostly organizational policies
What AuditKit Automates
Technical controls (149):
- Access controls and authentication
- Logging and monitoring
- Encryption and key management
- Network security
- Vulnerability management
- Configuration management
- Incident detection
- Backup and recovery
What AuditKit doesn't cover (about 1,050 controls):
- Organizational policies
- Training programs
- HR procedures
- Physical security
- Risk assessments
- Contingency planning
- System acquisition
- Privacy controls
Running 800-53 Scan
# AWS
auditkit scan -provider aws -framework 800-53
# Azure
auditkit scan -provider azure -framework 800-53
# GCP
auditkit scan -provider gcp -framework 800-53
# Generate report
auditkit scan -provider aws -framework 800-53 -format pdf -output nist-report.pdf
Output shows:
[FAIL] IA-2, IA-2(1), IA-5 - Authentication Controls (via CC6.6)
Issue: 12 users without MFA enabled
Source: SOC2 CC6.6 maps to NIST IA-2
[PASS] AU-2, AU-3, AU-12 - Audit Logging (via CC7.1)
Source: SOC2 CC7.1 maps to NIST AU-2
FedRAMP Baselines
NIST 800-53 is used by FedRAMP (Federal Risk and Authorization Management Program) for cloud services.
FedRAMP LOW
- 149 controls
- Low-impact data
- Public information
FedRAMP MODERATE
- 287 controls
- Moderate-impact data
- Most common baseline
FedRAMP HIGH
- 370 controls
- High-impact data
- National security systems
Note: AuditKit helps with technical controls, but FedRAMP requires full 800-53 implementation including all organizational controls.
800-53 vs Other Frameworks
| Framework | Total Controls | Automated by AuditKit |
|---|---|---|
| NIST 800-53 | 1,196 | 149 (12%) |
| SOC2 | 43 criteria | 38 on AWS (88%) |
| PCI-DSS | 312 requirements | 71 (23%) |
| CMMC Level 2 | 110 practices | 13 in Community, 42 cloud-queried in Pro |
Key insight: SOC2/PCI-DSS/CMMC are subsets of 800-53. Pass those, you're partway to 800-53 compliance.
Common Use Cases
Federal Contractor
Need: NIST 800-53 compliance for FISMA
AuditKit approach: 1. Scan for automated technical controls (~150) 2. Document organizational controls manually (about 1,050) 3. Use scan results as evidence for technical controls 4. Complete remaining documentation
FedRAMP Applicant
Need: FedRAMP authorization
AuditKit approach: 1. Start with SOC2 or CMMC (smaller scope) 2. Use 800-53 scan to see gaps 3. Work with FedRAMP 3PAO for full assessment 4. AuditKit provides technical control evidence
CMMC + Federal Work
Need: CMMC Level 2 + NIST 800-53
AuditKit approach: 1. Use Pro for CMMC Level 2 (110 practices) 2. Run 800-53 scan to see additional gaps 3. CMMC Level 2 covers ~30% of 800-53 technical controls 4. Document remaining controls
Cost Estimate
NIST 800-53 compliance costs vary widely:
| Item | Cost (Estimate) |
|---|---|
| AuditKit Free | $0 |
| Gap assessment | $10,000 - $50,000 |
| Implementation | $50,000 - $500,000 |
| Consulting | $100,000 - $1,000,000 |
| FedRAMP 3PAO (if applicable) | $250,000 - $1,500,000 |
Timeline: 12-24 months for full implementation
Note: These are estimates. Actual costs depend on organization size and current security posture.
FAQ
Q: Is NIST 800-53 a certification?
A: No. It's a control catalog used by FedRAMP, FISMA, and other compliance programs.
Q: Do I need all 1,000 controls?
A: No. Tailor based on your system's impact level (LOW/MODERATE/HIGH).
Q: Can AuditKit help with FedRAMP?
A: Yes, for technical controls. You'll still need organizational documentation and 3PAO assessment.
Q: What's the difference between Rev 4 and Rev 5?
A: Rev 5 (2020) added supply chain, privacy controls, and reorganized families. AuditKit uses Rev 5.
Q: Should I start with 800-53 or SOC2?
A: Start with SOC2. It's faster, cheaper, and maps to 800-53 technical controls.
Next Steps
Scan your environment
Point AuditKit at AWS, Azure or GCP with read-only credentials and get every finding with the command to fix it. Full results in about thirty minutes.
Start 14-Day Free Trial$297/month after the trial. Cancel any time. The Community Edition is free and open source.