NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research   •   STRIDE-LM
PS-3(1)Classified Information       STRIDE-LM
(3)Information Requiring Special Protective Measures       STRIDE-LM
PS-4Personnel Termination••• •••STRIDE-LM
PS-6(2)Classified Information Requiring Special Protection       STRIDE-LM
(3)Post-employment Requirements       STRIDE-LM
PT-2(1)Data Tagging       STRIDE-LM
PT-4(2)Just-in-time Consent       STRIDE-LM
PT-7Specific Categories of Personally Identifiable Information   •   STRIDE-LM
(1)Social Security Numbers   •   STRIDE-LM
(2)First Amendment Information   •   STRIDE-LM
RA-5(4)Discoverable Information  •   •STRIDE-LM
RA-6Technical Surveillance Countermeasures Survey       STRIDE-LM
RA-8Privacy Impact Assessments   •   STRIDE-LM
SA-3(2)Use of Live or Operational Data       STRIDE-LM
SA-8(6)Minimized Sharing       STRIDE-LM
(18)Trusted Communications Channels       STRIDE-LM
(20)Secure Metadata Management       STRIDE-LM
(23)Secure Defaults       STRIDE-LM
SA-9External System Services•••••••STRIDE-LM
(5)Processing, Storage, and Service Location       STRIDE-LM
SA-11(1)Static Code Analysis       STRIDE-LM
(2)Threat Modeling and Vulnerability Analyses       STRIDE-LM
(5)Penetration Testing       STRIDE-LM
(6)Attack Surface Reviews       STRIDE-LM
(9)Interactive Application Security Testing       STRIDE-LM
SA-15(7)Automated Vulnerability Analysis       STRIDE-LM
(12)Minimize Personally Identifiable Information       STRIDE-LM
SA-17Developer Security and Privacy Architecture and Design  •   •STRIDE-LM
SC-4Information in Shared System Resources ••  ••STRIDE-LM
(2)Multilevel or Periods Processing       STRIDE-LM
SC-7(4)External Telecommunications Services ••  ••STRIDE-LM
(9)Restrict Threatening Outgoing Communications Traffic       STRIDE-LM
(10)Prevent Exfiltration       STRIDE-LM
(23)Disable Sender Feedback on Protocol Validation Failure       STRIDE-LM
(24)Personally Identifiable Information   •   STRIDE-LM
(25)Unclassified National Security System Connections       STRIDE-LM
(26)Classified National Security System Connections       STRIDE-LM
SC-8Transmission Confidentiality and Integrity ••  ••STRIDE-LM
(1)Cryptographic Protection ••  ••STRIDE-LM
(2)Pre- and Post-transmission Handling       STRIDE-LM
(3)Cryptographic Protection for Message Externals       STRIDE-LM
(4)Conceal or Randomize Communications       STRIDE-LM
(5)Protected Distribution System       STRIDE-LM
SC-12Cryptographic Key Establishment and Management••• •••STRIDE-LM
(2)Symmetric Keys       STRIDE-LM
(6)Physical Control of Keys       STRIDE-LM
SC-13Cryptographic Protection••• •••STRIDE-LM
SC-15Collaborative Computing Devices and Applications••• •••STRIDE-LM
SC-28Protection of Information at Rest ••  ••STRIDE-LM