NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
PE-3(7)Physical Barriers       STRIDE-LM
PE-4Access Control for Transmission ••  ••STRIDE-LM
PE-6(4)Monitoring Physical Access to Systems  •  ••STRIDE-LM
SA-4(7)NIAP-approved Protection Profiles       STRIDE-LM
SA-8(9)Trusted Components       STRIDE-LM
(11)Inverse Modification Threshold       STRIDE-LM
(18)Trusted Communications Channels       STRIDE-LM
(20)Secure Metadata Management       STRIDE-LM
(31)Secure System Modification       STRIDE-LM
SA-9(7)Organization-controlled Integrity Checking       STRIDE-LM
SA-10Developer Configuration Management ••  ••STRIDE-LM
(1)Software and Firmware Integrity Verification       STRIDE-LM
(2)Alternative Configuration Management Processes       STRIDE-LM
(3)Hardware Integrity Verification       STRIDE-LM
(4)Trusted Generation       STRIDE-LM
(5)Mapping Integrity for Version Control       STRIDE-LM
(6)Trusted Distribution       STRIDE-LM
SA-15Development Process, Standards, and Tools ••  ••STRIDE-LM
SA-20Customized Development of Critical Components       STRIDE-LM
SC-3(1)Hardware Separation       STRIDE-LM
SC-7(13)Isolation of Security Tools, Mechanisms, and Support Components       STRIDE-LM
SC-8Transmission Confidentiality and Integrity ••  ••STRIDE-LM
(1)Cryptographic Protection ••  ••STRIDE-LM
(2)Pre- and Post-transmission Handling       STRIDE-LM
(3)Cryptographic Protection for Message Externals       STRIDE-LM
(5)Protected Distribution System       STRIDE-LM
SC-13Cryptographic Protection••• •••STRIDE-LM
SC-16(1)Integrity Verification       STRIDE-LM
(3)Cryptographic Binding       STRIDE-LM
SC-18Mobile Code ••  ••STRIDE-LM
(1)Identify Unacceptable Code and Take Corrective Actions       STRIDE-LM
SC-20(2)Data Origin and Integrity       STRIDE-LM
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)••• •••STRIDE-LM
SC-28(1)Cryptographic Protection ••  ••STRIDE-LM
(3)Cryptographic Keys       STRIDE-LM
SC-34Non-modifiable Executable Programs       STRIDE-LM
(1)No Writable Storage       STRIDE-LM
(2)Integrity Protection on Read-only Media       STRIDE-LM
SC-35External Malicious Code Identification       STRIDE-LM
SC-37(1)Ensure Delivery and Transmission       STRIDE-LM
SC-39(2)Separate Execution Domain Per Thread       STRIDE-LM
SC-40Wireless Link Protection       STRIDE-LM
SC-49Hardware-enforced Separation and Policy Enforcement       STRIDE-LM
SC-50Software-enforced Separation and Policy Enforcement       STRIDE-LM
SC-51Hardware-based Protection       STRIDE-LM
SI-3(4)Updates Only by Privileged Users       STRIDE-LM
(8)Detect Unauthorized Commands       STRIDE-LM
SI-7Software, Firmware, and Information Integrity ••  ••STRIDE-LM
(1)Integrity Checks ••  ••STRIDE-LM
(2)Automated Notifications of Integrity Violations  •   •STRIDE-LM