NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
AC-2Account Management••• •••STRIDE-LM
(2)Automated Temporary and Emergency Account Management ••  ••STRIDE-LM
(6)Dynamic Privilege Management       STRIDE-LM
(7)Privileged User Accounts       STRIDE-LM
AC-3Access Enforcement••• •••STRIDE-LM
(7)Role-based Access Control       STRIDE-LM
(12)Assert and Enforce Application Access       STRIDE-LM
(13)Attribute-based Access Control       STRIDE-LM
(15)Discretionary and Mandatory Access Control       STRIDE-LM
AC-5Separation of Duties ••  ••STRIDE-LM
AC-6Least Privilege ••  ••STRIDE-LM
(1)Authorize Access to Security Functions ••  ••STRIDE-LM
(2)Non-privileged Access for Nonsecurity Functions ••  ••STRIDE-LM
(3)Network Access to Privileged Commands  •   •STRIDE-LM
(5)Privileged Accounts ••  ••STRIDE-LM
(6)Privileged Access by Non-organizational Users       STRIDE-LM
(7)Review of User Privileges ••  ••STRIDE-LM
(8)Privilege Levels for Code Execution       STRIDE-LM
(10)Prohibit Non-privileged Users from Executing Privileged Functions ••  ••STRIDE-LM
AC-16(7)Consistent Attribute Interpretation       STRIDE-LM
AC-17(4)Privileged Commands and Access ••  ••STRIDE-LM
AC-18(4)Restrict Configurations by Users  •   •STRIDE-LM
AC-24Access Control Decisions       STRIDE-LM
AC-25Reference Monitor       STRIDE-LM
CA-6Authorization•••••••STRIDE-LM
CA-8Penetration Testing  •   •STRIDE-LM
(1)Independent Penetration Testing Agent or Team  •    STRIDE-LM
(2)Red Team Exercises       STRIDE-LM
CM-2(7)Configure Systems and Components for High-risk Areas ••  ••STRIDE-LM
CM-5(4)Dual Authorization       STRIDE-LM
(5)Privilege Limitation for Production and Operation       STRIDE-LM
(6)Limit Library Privileges       STRIDE-LM
CM-6Configuration Settings••• •••STRIDE-LM
CM-7(6)Confined Environments with Limited Privileges       STRIDE-LM
CM-11(2)Software Installation with Privileged Status       STRIDE-LM
IA-2(1)Multi-factor Authentication to Privileged Accounts••• •••STRIDE-LM
IA-4(9)Attribute Maintenance and Protection       STRIDE-LM
IA-5(6)Protection of Authenticators ••  ••STRIDE-LM
IA-12(1)Supervisor Authorization      •STRIDE-LM
IA-13Identity Providers and Authorization Servers       STRIDE-LM
MA-3Maintenance Tools ••  ••STRIDE-LM
(4)Restricted Tool Use       STRIDE-LM
(5)Execution with Privilege       STRIDE-LM
(6)Software Updates and Patches       STRIDE-LM
PL-8Security and Privacy Architectures ••• ••STRIDE-LM
PM-10Authorization Process   •   STRIDE-LM
RA-5Vulnerability Monitoring and Scanning••• •••STRIDE-LM
SA-4(5)System, Component, and Service Configurations  •   •STRIDE-LM
SA-8(12)Hierarchical Protection       STRIDE-LM
(14)Least Privilege       STRIDE-LM