Skip to main content
Author(s):
Joint Force
Series Title
National Institute of Standards and Technology (U.S.)
Abstract

This publication provides a methodology and set of procedures for conducting assessments of
security and privacy controls employed within systems and organizations within an effective risk
management framework. The assessment procedures, executed at various phases of the system
development life cycle, are consistent with the security and privacy controls in NIST Special
Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to
provide organizations with the needed flexibility to conduct security and privacy control
assessments that support organizational risk management processes and are aligned with the
stated risk tolerance of the organization. Information on building effective security and privacy
assessment plans is also provided with guidance on analyzing assessment results.

Reference details

DOI
10.6028/NIST.SP.800-53Ar5
Resource type
Report
Year of Publication
2022
Publication Area
Cybersecurity and defense
Date Published
2022-01-25

How to cite this reference:

Force, J. T. (2022). Assessing Security and Privacy Controls in Information Systems and Organizations. In National Institute of Standards and Technology (U.S.). https://doi.org/10.6028/NIST.SP.800-53Ar5 (Original work published)