NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
SC-28(1)Cryptographic Protection ••  ••STRIDE-LM
(2)Offline Storage       STRIDE-LM
(3)Cryptographic Keys       STRIDE-LM
SC-30(3)Change Processing and Storage Locations       STRIDE-LM
SC-31Covert Channel Analysis       STRIDE-LM
(1)Test Covert Channels for Exploitability       STRIDE-LM
SC-37(1)Ensure Delivery and Transmission       STRIDE-LM
SC-38Operations Security       STRIDE-LM
SC-39Process Isolation••• •••STRIDE-LM
(2)Separate Execution Domain Per Thread       STRIDE-LM
SC-40Wireless Link Protection       STRIDE-LM
SC-42(5)Collection Minimization       STRIDE-LM
SC-46Cross Domain Policy Enforcement       STRIDE-LM
SC-49Hardware-enforced Separation and Policy Enforcement       STRIDE-LM
SC-50Software-enforced Separation and Policy Enforcement       STRIDE-LM
SI-4(4)Inbound and Outbound Communications Traffic ••  ••STRIDE-LM
(10)Visibility of Encrypted Communications  •   •STRIDE-LM
(11)Analyze Communications Traffic Anomalies       STRIDE-LM
(18)Analyze Traffic and Covert Exfiltration       STRIDE-LM
SI-10(6)Injection Prevention       STRIDE-LM
SI-11Error Handling ••  ••STRIDE-LM
SI-12(1)Limit Personally Identifiable Information Elements   •   STRIDE-LM
(2)Minimize Personally Identifiable Information in Testing, Training, and Research   •   STRIDE-LM
(3)Information Disposal   •   STRIDE-LM
SI-14(2)Non-persistent Information       STRIDE-LM
SI-15Information Output Filtering       STRIDE-LM
SI-18(2)Data Tags       STRIDE-LM
SI-19De-identification   •   STRIDE-LM
(3)Release       STRIDE-LM
(4)Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers       STRIDE-LM
(5)Statistical Disclosure Control       STRIDE-LM
(6)Differential Privacy       STRIDE-LM
(8)Motivated Intruder       STRIDE-LM
SR-12Component Disposal••• •••STRIDE-LM