NIST Special Publication 800-53 Revision 4
IDNameBaselinesPriorityThreats
LowModerateHigh
CM-3(6)Cryptography Management   
  • P1
STRIDE-LM
IA-4(1)Prohibit Account Identifiers As Public Identifiers   
  • P1
STRIDE-LM
IA-5(6)Protection Of Authenticators   
  • P1
STRIDE-LM
(7)No Embedded Unencrypted Static Authenticators   
  • P1
STRIDE-LM
IR-4(6)Insider Threats - Specific Capabilities   
  • P1
STRIDE-LM
(7)Insider Threats - Intra-Organization Coordination   
  • P1
STRIDE-LM
IR-9Information Spillage Response   
  • P0
STRIDE-LM
(3)Post-Spill Operations   
  • P0
STRIDE-LM
(4)Exposure To Unauthorized Personnel   
  • P0
STRIDE-LM
MA-4Nonlocal Maintenance•••
  • P2
STRIDE-LM
(6)Cryptographic Protection   
  • P2
STRIDE-LM
MA-5(1)Individuals Without Appropriate Access  •
  • P2
STRIDE-LM
(2)Security Clearances For Classified Systems   
  • P2
STRIDE-LM
MP-1Media Protection Policy And Procedures•••
  • P1
STRIDE-LM
MP-2Media Access•••
  • P1
STRIDE-LM
MP-4Media Storage ••
  • P1
STRIDE-LM
(2)Automated Restricted Access   
  • P1
STRIDE-LM
MP-5Media Transport ••
  • P1
STRIDE-LM
(4)Cryptographic Protection ••
  • P1
STRIDE-LM
MP-6Media Sanitization•••
  • P1
STRIDE-LM
(3)Nondestructive Techniques  •
  • P1
STRIDE-LM
(8)Remote Purging / Wiping Of Information   
  • P1
STRIDE-LM
MP-7Media Use•••
  • P1
STRIDE-LM
(2)Prohibit Use Of Sanitization-Resistant Media   
  • P1
STRIDE-LM
MP-8Media Downgrading   
  • P0
STRIDE-LM
(3)Controlled Unclassified Information   
  • P0
STRIDE-LM
(4)Classified Information   
  • P0
STRIDE-LM
PE-2(3)Restrict Unescorted Access   
  • P1
STRIDE-LM
PE-4Access Control For Transmission Medium ••
  • P1
STRIDE-LM
PE-5Access Control For Output Devices ••
  • P2
STRIDE-LM
(1)Access To Output By Authorized Individuals   
  • P2
STRIDE-LM
(2)Access To Output By Individual Identity   
  • P2
STRIDE-LM
PE-19Information Leakage   
  • P0
STRIDE-LM
(1)National Emissions / Tempest Policies And Procedures   
  • P0
STRIDE-LM
PL-4(1)Social Media And Networking Restrictions ••
  • P2
STRIDE-LM
PM-12Insider Threat Program    STRIDE-LM
PS-3(1)Classified Information   
  • P1
STRIDE-LM
(3)Information With Special Protection Measures   
  • P1
STRIDE-LM
PS-4Personnel Termination•••
  • P1
STRIDE-LM
(1)Post-Employment Requirements   
  • P1
STRIDE-LM
PS-6(2)Classified Information Requiring Special Protection   
  • P3
STRIDE-LM
RA-5(4)Discoverable Information  •
  • P1
STRIDE-LM
RA-6Technical Surveillance Countermeasures Survey   
  • P0
STRIDE-LM
SA-4(7)Niap-Approved Protection Profiles   
  • P1
STRIDE-LM
SA-9(3)Establish / Maintain Trust Relationship With Providers   
  • P1
STRIDE-LM
SA-11Developer Security Testing And Evaluation ••
  • P1
STRIDE-LM
(1)Static Code Analysis   
  • P1
STRIDE-LM
(2)Threat And Vulnerability Analyses   
  • P1
STRIDE-LM
(4)Manual Code Reviews   
  • P1
STRIDE-LM
(5)Penetration Testing   
  • P1
STRIDE-LM