RRA
Security & Privacy Controls
NIST SP 800-53 Quick Reference Guide
A plain-language orientation to the NIST SP 800-53 Rev. 5 control families and a practical way to begin selecting and managing controls.
Designed for: Security leaders, assessors, system owners, compliance teams and public-sector suppliers
RRA Tech Zone LLC · Proprietary educational resource · Version 1.0 · September 2026
Governance and planning families
- PM — Program Management
- PL — Planning
- RA — Risk Assessment
- CA — Assessment, Authorization and Monitoring
- SR — Supply Chain Risk Management
People and access families
- AC — Access Control
- IA — Identification and Authentication
- PS — Personnel Security
- AT — Awareness and Training
Technology and operations families
- CM — Configuration Management
- MA — Maintenance
- MP — Media Protection
- SC — System and Communications Protection
- SI — System and Information Integrity
Response and resilience families
- AU — Audit and Accountability
- IR — Incident Response
- CP — Contingency Planning
- PE — Physical and Environmental Protection
- PT — Personally Identifiable Information Processing and Transparency
Recommended next steps
- 1Define the system boundary and information handled.
- 2Choose the applicable baseline or organizational control set.
- 3Tailor controls using risk, mission, technology and legal requirements.
- 4Assign control owners and expected evidence.
- 5Assess implementation and record findings.
- 6Monitor controls continuously and update after system changes.