NIST SP 800-53 Moderate Baseline and the AIC Kits
Analog Informatics Corporation (AIC) kits are designed to the National Institute of Standards and Technology (NIST) Special Publication 800-53 Revision 5 moderate baseline. This page lists all 287 controls and enhancements in that baseline and states what the kit does for each one. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit.

Capability Availability and Organizational Responsibilities
The 287 control and enhancement mappings below are grouped by the availability and scope of the named AIC capability:
- Available Now - 71 mappings: The named AIC module is available for the systems and access paths the kit manages.
- Available Now, Wider Scope Planned - 60 mappings: The named module is available within its current scope. Coverage beyond that scope is planned or remains with the organization, as described in the mapping.
- Planned - 9 mappings: The named product capability is not yet available.
- Organization - 147 mappings: The control is addressed through the organization's people, facilities, policies, or tools. The Assessment Binder can store the supporting records.
These labels describe product availability and responsibility, not whether a control has been satisfied. Control titles are taken from the public NIST catalog.
Moderate Baseline Catalog
| Control | Title | Kit Module |
|---|---|---|
| AC-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| AC-2 | Account Management | Identity Governance and Administration and Privileged Identity Management |
| AC-2(1) | Account Management: Automated System Account Management | Identity Governance and Administration and Privileged Identity Management |
| AC-2(2) | Account Management: Automated Temporary and Emergency Account Management | Just-in-time elevation |
| AC-2(3) | Account Management: Disable Accounts | Identity Governance and Administration and Privileged Identity Management |
| AC-2(4) | Account Management: Automated Audit Actions | Audit |
| AC-2(5) | Account Management: Inactivity Logout | Kit sessions |
| AC-2(13) | Account Management: Disable Accounts for High-risk Individuals | Identity Governance and Administration and Privileged Identity Management |
| AC-3 | Access Enforcement | Privileged Identity Management, Privileged Access Management, and Privileged User Management |
| AC-4 | Information Flow Enforcement | Document sharing vault and classification |
| AC-5 | Separation of Duties | Approvals in Privileged Access Management |
| AC-6 | Least Privilege | Privileged User Management |
| AC-6(1) | Least Privilege: Authorize Access to Security Functions | Privileged User Management |
| AC-6(2) | Least Privilege: Non-privileged Access for Nonsecurity Functions | Privileged User Management |
| AC-6(5) | Least Privilege: Privileged Accounts | Privileged User Management |
| AC-6(7) | Least Privilege: Review of User Privileges | Access review |
| AC-6(9) | Least Privilege: Log Use of Privileged Functions | Audit |
| AC-6(10) | Least Privilege: Prohibit Non-privileged Users from Executing Privileged Functions | Privileged User Management |
| AC-7 | Unsuccessful Logon Attempts | Kit sign-in |
| AC-8 | System Use Notification | Universal host logon banner |
| AC-11 | Device Lock | Kit session lock. Operating system lock stays with the organization |
| AC-11(1) | Device Lock: Pattern-hiding Displays | Kit session lock. Operating system lock stays with the organization |
| AC-12 | Session Termination | Kit sessions |
| AC-14 | Permitted Actions Without Identification or Authentication | Kit sign-in |
| AC-17 | Remote Access | Jump and Privileged Access Management |
| AC-17(1) | Remote Access: Monitoring and Control | Jump and Privileged Access Management |
| AC-17(2) | Remote Access: Protection of Confidentiality and Integrity Using Encryption | Jump and Privileged Access Management |
| AC-17(3) | Remote Access: Managed Access Control Points | Jump |
| AC-17(4) | Remote Access: Privileged Commands and Access | Command restriction |
| AC-18 | Wireless Access | Assessment Binder stores the record |
| AC-18(1) | Wireless Access: Authentication and Encryption | Assessment Binder stores the record |
| AC-18(3) | Wireless Access: Disable Wireless Networking | Assessment Binder stores the record |
| AC-19 | Access Control for Mobile Devices | Assessment Binder stores the record |
| AC-19(5) | Access Control for Mobile Devices: Full Device or Container-based Encryption | Assessment Binder stores the record |
| AC-20 | Use of External Systems | Configuration compliance for external systems that connect |
| AC-20(1) | Use of External Systems: Limits on Authorized Use | Configuration compliance for external systems that connect |
| AC-20(2) | Use of External Systems: Portable Storage Devices - Restricted Use | Assessment Binder stores the record |
| AC-21 | Information Sharing | Document sharing vault |
| AC-22 | Publicly Accessible Content | Assessment Binder stores the record |
| AT-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| AT-2 | Literacy Training and Awareness | Training and attestation |
| AT-2(2) | Literacy Training and Awareness: Insider Threat | Training and attestation |
| AT-2(3) | Literacy Training and Awareness: Social Engineering and Mining | Training and attestation |
| AT-3 | Role-based Training | Training and attestation |
| AT-4 | Training Records | Training and attestation records |
| AU-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| AU-2 | Event Logging | Audit |
| AU-3 | Content of Audit Records | Audit |
| AU-3(1) | Content of Audit Records: Additional Audit Information | Audit |
| AU-4 | Audit Log Storage Capacity | Audit |
| AU-5 | Response to Audit Logging Process Failures | Audit |
| AU-6 | Audit Record Review, Analysis, and Reporting | Audit, Windows Event Log, and syslog |
| AU-6(1) | Audit Record Review, Analysis, and Reporting: Automated Process Integration | Audit |
| AU-6(3) | Audit Record Review, Analysis, and Reporting: Correlate Audit Record Repositories | Audit, Windows Event Log, and syslog |
| AU-7 | Audit Record Reduction and Report Generation | Audit reports |
| AU-7(1) | Audit Record Reduction and Report Generation: Automatic Processing | Audit reports |
| AU-8 | Time Stamps | Audit |
| AU-9 | Protection of Audit Information | Audit |
| AU-9(4) | Protection of Audit Information: Access by Subset of Privileged Users | Audit |
| AU-11 | Audit Record Retention | Audit |
| AU-12 | Audit Record Generation | Audit |
| CA-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| CA-2 | Control Assessments | Assessment Binder and Current State Compliance |
| CA-2(1) | Control Assessments: Independent Assessors | Assessment Binder stores the record |
| CA-3 | Information Exchange | Assessment Binder stores the record |
| CA-5 | Plan of Action and Milestones | Assessment Binder plan of action support |
| CA-6 | Authorization | Assessment Binder stores the record |
| CA-7 | Continuous Monitoring | Current State Compliance and continuous configuration compliance monitoring |
| CA-7(1) | Continuous Monitoring: Independent Assessment | Current State Compliance |
| CA-7(4) | Continuous Monitoring: Risk Monitoring | Current State Compliance and continuous configuration compliance monitoring |
| CA-9 | Internal System Connections | Configuration compliance |
| CM-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| CM-2 | Baseline Configuration | Configuration compliance |
| CM-2(2) | Baseline Configuration: Automation Support for Accuracy and Currency | Configuration compliance |
| CM-2(3) | Baseline Configuration: Retention of Previous Configurations | Configuration compliance |
| CM-2(7) | Baseline Configuration: Configure Systems and Components for High-risk Areas | Assessment Binder stores the record |
| CM-3 | Configuration Change Control | Configuration compliance and Current State Compliance |
| CM-3(2) | Configuration Change Control: Testing, Validation, and Documentation of Changes | Assessment Binder stores the record |
| CM-3(4) | Configuration Change Control: Security and Privacy Representatives | Assessment Binder stores the record |
| CM-4 | Impact Analyses | Assessment Binder stores the record |
| CM-4(2) | Impact Analyses: Verification of Controls | Assessment Binder stores the record |
| CM-5 | Access Restrictions for Change | Privileged Access Management |
| CM-6 | Configuration Settings | Configuration compliance |
| CM-7 | Least Functionality | Privileged User Management application control |
| CM-7(1) | Least Functionality: Periodic Review | Privileged User Management application control |
| CM-7(2) | Least Functionality: Prevent Program Execution | Privileged User Management application control |
| CM-7(5) | Least Functionality: Authorized Software - Allow-by-exception | Privileged User Management application control |
| CM-8 | System Component Inventory | Inventory of enrolled systems |
| CM-8(1) | System Component Inventory: Updates During Installation and Removal | Inventory of enrolled systems |
| CM-8(3) | System Component Inventory: Automated Unauthorized Component Detection | Inventory of enrolled systems |
| CM-9 | Configuration Management Plan | Assessment Binder stores the record |
| CM-10 | Software Usage Restrictions | Assessment Binder stores the record |
| CM-11 | User-installed Software | Privileged User Management application control |
| CM-12 | Information Location | Assessment Binder stores the record |
| CM-12(1) | Information Location: Automated Tools to Support Information Location | Assessment Binder stores the record |
| CP-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| CP-2 | Contingency Plan | Assessment Binder stores the record |
| CP-2(1) | Contingency Plan: Coordinate with Related Plans | Assessment Binder stores the record |
| CP-2(3) | Contingency Plan: Resume Mission and Business Functions | Assessment Binder stores the record |
| CP-2(8) | Contingency Plan: Identify Critical Assets | Assessment Binder stores the record |
| CP-3 | Contingency Training | Assessment Binder stores the record |
| CP-4 | Contingency Plan Testing | Assessment Binder stores the record |
| CP-4(1) | Contingency Plan Testing: Coordinate with Related Plans | Assessment Binder stores the record |
| CP-6 | Alternate Storage Site | Assessment Binder stores the record |
| CP-6(1) | Alternate Storage Site: Separation from Primary Site | Assessment Binder stores the record |
| CP-6(3) | Alternate Storage Site: Accessibility | Assessment Binder stores the record |
| CP-7 | Alternate Processing Site | Assessment Binder stores the record |
| CP-7(1) | Alternate Processing Site: Separation from Primary Site | Assessment Binder stores the record |
| CP-7(2) | Alternate Processing Site: Accessibility | Assessment Binder stores the record |
| CP-7(3) | Alternate Processing Site: Priority of Service | Assessment Binder stores the record |
| CP-8 | Telecommunications Services | Assessment Binder stores the record |
| CP-8(1) | Telecommunications Services: Priority of Service Provisions | Assessment Binder stores the record |
| CP-8(2) | Telecommunications Services: Single Points of Failure | Assessment Binder stores the record |
| CP-9 | System Backup | Assessment Binder stores the record |
| CP-9(1) | System Backup: Testing for Reliability and Integrity | Assessment Binder stores the record |
| CP-9(8) | System Backup: Cryptographic Protection | Assessment Binder stores the record |
| CP-10 | System Recovery and Reconstitution | Assessment Binder stores the record |
| CP-10(2) | System Recovery and Reconstitution: Transaction Recovery | Assessment Binder stores the record |
| IA-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| IA-2 | Identification and Authentication (Organizational Users) | Kit sign-in with another step beyond a password |
| IA-2(1) | Identification and Authentication (Organizational Users): Multi-factor Authentication to Privileged Accounts | Kit sign-in with another step beyond a password |
| IA-2(2) | Identification and Authentication (Organizational Users): Multi-factor Authentication to Non-privileged Accounts | Kit sign-in with another step beyond a password |
| IA-2(8) | Identification and Authentication (Organizational Users): Access to Accounts - Replay Resistant | Kit sign-in with another step beyond a password |
| IA-2(12) | Identification and Authentication (Organizational Users): Acceptance of PIV Credentials | Personal identity verification card sign-in |
| IA-3 | Device Identification and Authentication | Enrolled agent identity |
| IA-4 | Identifier Management | Privileged Identity Management |
| IA-4(4) | Identifier Management: Identify User Status | Privileged Identity Management |
| IA-5 | Authenticator Management | Privileged Identity Management |
| IA-5(1) | Authenticator Management: Password-based Authentication | Privileged Identity Management |
| IA-5(2) | Authenticator Management: Public Key-based Authentication | Privileged Identity Management |
| IA-5(6) | Authenticator Management: Protection of Authenticators | Privileged Identity Management |
| IA-6 | Authentication Feedback | Kit sign-in |
| IA-7 | Cryptographic Module Authentication | Validated cryptographic module |
| IA-8 | Identification and Authentication (Non-organizational Users) | Kit sign-in |
| IA-8(1) | Identification and Authentication (Non-organizational Users): Acceptance of PIV Credentials from Other Agencies | Kit sign-in |
| IA-8(2) | Identification and Authentication (Non-organizational Users): Acceptance of External Authenticators | Kit sign-in |
| IA-8(4) | Identification and Authentication (Non-organizational Users): Use of Defined Profiles | Kit sign-in |
| IA-11 | Re-authentication | Kit sessions |
| IA-12 | Identity Proofing | Assessment Binder stores the record |
| IA-12(2) | Identity Proofing: Identity Evidence | Assessment Binder stores the record |
| IA-12(3) | Identity Proofing: Identity Evidence Validation and Verification | Assessment Binder stores the record |
| IA-12(5) | Identity Proofing: Address Confirmation | Assessment Binder stores the record |
| IR-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| IR-2 | Incident Response Training | Assessment Binder stores the record |
| IR-3 | Incident Response Testing | Assessment Binder stores the record |
| IR-3(2) | Incident Response Testing: Coordination with Related Plans | Assessment Binder stores the record |
| IR-4 | Incident Handling | Incident Response |
| IR-4(1) | Incident Handling: Automated Incident Handling Processes | Incident Response |
| IR-5 | Incident Monitoring | Incident Response |
| IR-6 | Incident Reporting | Incident Response |
| IR-6(1) | Incident Reporting: Automated Reporting | Incident Response |
| IR-6(3) | Incident Reporting: Supply Chain Coordination | Assessment Binder stores the record |
| IR-7 | Incident Response Assistance | Incident Response |
| IR-7(1) | Incident Response Assistance: Automation Support for Availability of Information and Support | Incident Response |
| IR-8 | Incident Response Plan | Assessment Binder stores the record |
| MA-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| MA-2 | Controlled Maintenance | Assessment Binder stores the record |
| MA-3 | Maintenance Tools | Privileged Access Management |
| MA-3(1) | Maintenance Tools: Inspect Tools | Assessment Binder stores the record |
| MA-3(2) | Maintenance Tools: Inspect Media | Assessment Binder stores the record |
| MA-3(3) | Maintenance Tools: Prevent Unauthorized Removal | Assessment Binder stores the record |
| MA-4 | Nonlocal Maintenance | Privileged Access Management |
| MA-5 | Maintenance Personnel | Privileged Access Management |
| MA-6 | Timely Maintenance | Assessment Binder stores the record |
| MP-1 | Policy and Procedures | Policy and procedures. Assessment Binder stores the record |
| MP-2 | Media Access | Document sharing vault |
| MP-3 | Media Marking | Document sharing vault classification |
| MP-4 | Media Storage | Document sharing vault |
| MP-5 | Media Transport | Assessment Binder stores the record |
| MP-6 | Media Sanitization | Assessment Binder stores the record |