NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
AC-3Access Enforcement••• •••STRIDE-LM
(3)Mandatory Access Control       STRIDE-LM
(4)Discretionary Access Control       STRIDE-LM
(7)Role-based Access Control       STRIDE-LM
(9)Controlled Release       STRIDE-LM
(11)Restrict Access to Specific Information Types      •STRIDE-LM
(13)Attribute-based Access Control       STRIDE-LM
(15)Discretionary and Mandatory Access Control       STRIDE-LM
AC-4Information Flow Enforcement ••  ••STRIDE-LM
(1)Object Security and Privacy Attributes       STRIDE-LM
(2)Processing Domains       STRIDE-LM
(3)Dynamic Information Flow Control       STRIDE-LM
(4)Flow Control of Encrypted Information  •   •STRIDE-LM
(8)Security and Privacy Policy Filters       STRIDE-LM
(10)Enable and Disable Security or Privacy Policy Filters       STRIDE-LM
(11)Configuration of Security or Privacy Policy Filters       STRIDE-LM
(14)Security or Privacy Policy Filter Constraints       STRIDE-LM
(15)Detection of Unsanctioned Information       STRIDE-LM
(21)Physical or Logical Separation of Information Flows       STRIDE-LM
(23)Modify Non-releasable Information       STRIDE-LM
(25)Data Sanitization       STRIDE-LM
(32)Process Requirements for Information Transfer       STRIDE-LM
AC-6Least Privilege ••  ••STRIDE-LM
AC-7(2)Purge or Wipe Mobile Device       STRIDE-LM
AC-11Device Lock ••  ••STRIDE-LM
(1)Pattern-hiding Displays ••  ••STRIDE-LM
AC-16Security and Privacy Attributes       STRIDE-LM
(1)Dynamic Attribute Association       STRIDE-LM
(5)Attribute Displays on Objects to Be Output       STRIDE-LM
(9)Attribute Reassignment - Regrading Mechanisms       STRIDE-LM
AC-17(2)Protection of Confidentiality and Integrity Using Encryption ••  ••STRIDE-LM
(6)Protection of Mechanism Information       STRIDE-LM
AC-18(1)Authentication and Encryption ••  ••STRIDE-LM
(3)Disable Wireless Networking ••  ••STRIDE-LM
AC-19Access Control for Mobile Devices••• •••STRIDE-LM
(4)Restrictions for Classified Information       STRIDE-LM
(5)Full Device or Container-based Encryption ••  ••STRIDE-LM
AC-20Use of External Systems••• •••STRIDE-LM
(2)Portable Storage Devices - Restricted Use ••  ••STRIDE-LM
(3)Non-organizationally Owned Systems - Restricted Use       STRIDE-LM
(4)Network Accessible Storage Devices - Prohibited Use       STRIDE-LM
(5)Portable Storage Devices - Prohibited Use       STRIDE-LM
AC-21Information Sharing ••  ••STRIDE-LM
(2)Information Search and Retrieval       STRIDE-LM
AC-22Publicly Accessible Content••• •••STRIDE-LM
AC-23Data Mining Protection       STRIDE-LM
AC-24Access Control Decisions       STRIDE-LM
AC-25Reference Monitor       STRIDE-LM
AT-2Literacy Training and Awareness•••••••STRIDE-LM
(2)Insider Threat••• •••STRIDE-LM