NIST Special Publication 800-53 Revision 4
IDNameBaselinesPriorityThreats
LowModerateHigh
AC-3Access Enforcement•••
  • P1
STRIDE-LM
(3)Mandatory Access Control   
  • P1
STRIDE-LM
(4)Discretionary Access Control   
  • P1
STRIDE-LM
(9)Controlled Release   
  • P1
STRIDE-LM
AC-4Information Flow Enforcement ••
  • P1
STRIDE-LM
(1)Object Security Attributes   
  • P1
STRIDE-LM
(2)Processing Domains   
  • P1
STRIDE-LM
(3)Dynamic Information Flow Control   
  • P1
STRIDE-LM
(6)Metadata   
  • P1
STRIDE-LM
(7)One-Way Flow Mechanisms   
  • P1
STRIDE-LM
(8)Security Policy Filters   
  • P1
STRIDE-LM
(9)Human Reviews   
  • P1
STRIDE-LM
(11)Configuration Of Security Policy Filters   
  • P1
STRIDE-LM
(14)Security Policy Filter Constraints   
  • P1
STRIDE-LM
(15)Detection Of Unsanctioned Information   
  • P1
STRIDE-LM
(21)Physical / Logical Separation Of Information Flows   
  • P1
STRIDE-LM
(22)Access Only   
  • P1
STRIDE-LM
AC-7(2)Purge / Wipe Mobile Device   
  • P2
STRIDE-LM
AC-11Session Lock ••
  • P3
STRIDE-LM
AC-14Permitted Actions Without Identification Or Authentication•••
  • P3
STRIDE-LM
AC-16Security Attributes   
  • P0
STRIDE-LM
(5)Attribute Displays For Output Devices   
  • P0
STRIDE-LM
AC-17(2)Protection Of Confidentiality / Integrity Using Encryption ••
  • P1
STRIDE-LM
(6)Protection Of Information   
  • P1
STRIDE-LM
AC-18Wireless Access•••
  • P1
STRIDE-LM
(1)Authentication And Encryption ••
  • P1
STRIDE-LM
(3)Disable Wireless Networking   
  • P1
STRIDE-LM
AC-19Access Control For Mobile Devices•••
  • P1
STRIDE-LM
(4)Restrictions For Classified Information   
  • P1
STRIDE-LM
(5)Full Device / Container-Based Encryption ••
  • P1
STRIDE-LM
AC-20Use Of External Information Systems•••
  • P1
STRIDE-LM
(2)Portable Storage Devices ••
  • P1
STRIDE-LM
(3)Non-Organizationally Owned Systems / Components / Devices   
  • P1
STRIDE-LM
(4)Network Accessible Storage Devices   
  • P1
STRIDE-LM
AC-21Information Sharing ••
  • P2
STRIDE-LM
(2)Information Search And Retrieval   
  • P2
STRIDE-LM
AC-22Publicly Accessible Content•••
  • P3
STRIDE-LM
AC-23Data Mining Protection   
  • P0
STRIDE-LM
AC-24(1)Transmit Access Authorization Information   
  • P0
STRIDE-LM
AT-2(2)Insider Threat ••
  • P1
STRIDE-LM
AT-3Role-Based Security Training•••
  • P1
STRIDE-LM
AU-9Protection Of Audit Information•••
  • P1
STRIDE-LM
(3)Cryptographic Protection  •
  • P1
STRIDE-LM
AU-13Monitoring For Information Disclosure   
  • P0
STRIDE-LM
CA-3(1)Unclassified National Security System Connections   
  • P1
STRIDE-LM
(2)Classified National Security System Connections   
  • P1
STRIDE-LM
(3)Unclassified Non-National Security System Connections   
  • P1
STRIDE-LM
CA-8Penetration Testing  •
  • P2
STRIDE-LM
(1)Independent Penetration Agent Or Team   
  • P2
STRIDE-LM
(2)Red Team Exercises   
  • P2
STRIDE-LM