<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Controls on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/controls/</link><description>Recent content in Controls on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/controls/index.xml" rel="self" type="application/rss+xml"/><item><title>NIST 800-53</title><link>https://lesitedefrancois.be/en/compliance/nist-800-53/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/nist-800-53/</guid><description>&lt;p&gt;&lt;strong&gt;NIST Special Publication 800-53&lt;/strong&gt; is published by the &lt;strong&gt;National Institute of Standards and Technology (NIST)&lt;/strong&gt;, a US federal agency within the Department of Commerce. The current version is &lt;strong&gt;Revision 5&lt;/strong&gt; (September 2020, updated December 2020), which defines over &lt;strong&gt;1,000 security and privacy controls&lt;/strong&gt; organized in 20 control families (Access Control, Audit and Accountability, Configuration Management, Incident Response, System and Communications Protection, Supply Chain Risk Management, etc.). NIST 800-53 is &lt;strong&gt;mandatory for US federal agencies&lt;/strong&gt; and their contractors under FISMA (Federal Information Security Modernization Act) and serves as the control baseline for &lt;strong&gt;FedRAMP&lt;/strong&gt; (cloud), &lt;strong&gt;CMMC&lt;/strong&gt; (defense contractors), and many state/local government programs. Beyond the US, it is widely adopted internationally as a comprehensive reference catalog — organizations in finance, healthcare, and critical infrastructure worldwide use NIST 800-53 as their control framework. The standard defines three baselines (Low, Moderate, High) corresponding to the potential impact of a security breach. NIST 800-53 is &lt;strong&gt;not a certification&lt;/strong&gt; itself but the control catalog against which systems are assessed; formal authorization (ATO — Authority to Operate) is granted by an authorizing official after an assessor verifies control implementation using NIST SP 800-53A assessment procedures. The companion &lt;strong&gt;OSCAL&lt;/strong&gt; (Open Security Controls Assessment Language) standard, also from NIST, provides machine-readable formats for expressing 800-53 controls and assessment results.&lt;/p&gt;</description></item></channel></rss>