Please use the NIST.org Forum to ask questions or discuss this document. Members can use the comment link below for short comments about this publication.
Annex 1 (.pdf)
Annex 2 (.pdf)
Annex 3 (.pdf)
The SP 800-53 rev. 3 document was created by the National Institute of Standards and Technology and is public domain (not subject to copyright).
(The below SP 800-53 rev.3 description is from NIST.gov, edited)
The implementation of appropriate security controls for an information system is an important task that can have major implications on the operations and assets of an organization. Security controls are the management, operational, and technical safeguards or ...view middle of the document...
It is of paramount importance that responsible individuals within the organization understand the risks and other factors that could adversely affect their operations and assets. Moreover, these officials must understand the current status of their security programs and the security controls planned or in place to protect their information systems in order to make informed judgments and investments that appropriately mitigate risks to an acceptable level. The ultimate objective is to conduct the day-to-day operations...