Legacy Re-Mapping NIST 800-53 R4 Changes

Here is the list of the mapping changes that resulted from the re-mapping of legacy document NIST 800-53 R4.

December 3, 2020

Here is the list of the mapping changes that resulted from the re-mapping of legacy document NIST 800-53 R4.

  • Legacy Document: AD 1374, Security and Privacy Controls for Federal Information Systems and Organizations, NIST SP 800-53, Revision 4, Deprecated
  • Re-mapped Document: AD 3212, Security and Privacy Controls for Federal Information Systems and Organizations, NIST SP 800-53, Revision 4

There are two types of changes:

  1. The mandate of the citation maps to a different control.
    This occurs when a better control match is created after the original mapping. This is typically a result of newer control having been written since the initial mapping.
  2. The mandates of the citation map to additional controls.
    Prior mappings typically mapped one citation to one control. We now identify all the mandates in each citation and map each mandate to a control. You can see the color-coded mandates at research.unifiedcompliance.com.

Please note if there were no changes to the mapping, it is not in this table.

Legacy and New Control Mappings

CitationLegacy CC IDLegacy CC NameNew CC IDNew CC Name CM-7(4)(b) 868 Establish and maintain a software accountability policy. 11780 Establish, implement, and maintain whitelists and blacklists of software. CM-8(6) ¶ 1 8710 Establish and maintain a configuration change log. 862 Establish and maintain a current configuration baseline based on the least functionality principle. 8711 Document approved configuration deviations. AC-3(9)(a) 544 Establish and maintain a Boundary Defense program. 6310 Prohibit restricted data or restricted information from being copied or moved absent approval of system boundaries for information flow control. AC-3(9)(b) 544 Establish and maintain a Boundary Defense program. 6310 Prohibit restricted data or restricted information from being copied or moved absent approval of system boundaries for information flow control. AC-3(10) ¶ 1 512 Establish, implement, and maintain access control policies. 645 Configure the log to capture actions taken by individuals with root privileges or administrative privileges and add logging option to the root file system. AC-4(15) ¶ 1 6763 Constrain the information flow of restricted data or restricted information. 6763 Constrain the information flow of restricted data or restricted information. 6761 Perform content filtering scans on network traffic. AC-4(18) ¶ 1 4542 Establish and maintain information flow procedures. 6764 Associate records with their security attributes. AC-16b. 6764 Associate records with their security attributes. 6764 Associate records with their security attributes. 968 Retain records in accordance with applicable requirements. AC-16c. 6764 Associate records with their security attributes. 3 Interpret and apply security requirements based upon the information classification of the system. AC-16d. 6764 Associate records with their security attributes. 1903 Apply security controls to each level of the information classification standard. AC-16(6) ¶ 1 6764 Associate records with their security attributes. 12304 Document the roles and responsibilities for all activities that protect restricted data in the information security procedures. AC-16(7) ¶ 1 6764 Associate records with their security attributes. 7184 Apply asset protection mechanisms for all assets according to their assigned Asset Classification Policy. AC-16(9) ¶ 1 6764 Associate records with their security attributes. 13036 Establish and maintain records management systems, as necessary. AC-16(10) ¶ 1 6765 Reconfigure the security attributes of records as the information changes. 11885 Assign information security responsibilities to interested personnel and affected parties in the information security program. AC-16(1) ¶ 1 6765 Reconfigure the security attributes of records as the information changes. 6765 Reconfigure the security attributes of records as the information changes. 6764 Associate records with their security attributes. AC-21(2) ¶ 1 6310 Prohibit restricted data or restricted information from being copied or moved absent approval of system boundaries for information flow control. 10010 Provide structures for searching for items stored in the Electronic Document and Records Management system. AC-24(1) ¶ 1 4553 Enable access control for objects and users on each system. 1410 Establish, implement, and maintain information flow control policies inside the system and between interconnected systems. AC-24(2) ¶ 1 4553 Enable access control for objects and users on each system. 11836 Include the objects and users subject to access control in the security policy. AU-5b. 6290 Protect the event logs from failure. 10679 Shut down systems when an integrity violation is detected, as necessary. 14308 Overwrite the oldest records when audit logging fails. 1712 Configure the security parameters for all logs. AU-5(3) ¶ 1 1619 Establish and maintain system capacity monitoring procedures. 1619 Establish and maintain system capacity monitoring procedures. 6883 Establish, implement, and maintain rate limiting filters. AU-10(1)(a) 6764 Associate records with their security attributes. 12729 Assign an information owner to organizational assets, as necessary. AU-10(1)(b) 6764 Associate records with their security attributes. 920 Establish and maintain data input and data access authorization tracking. AU-10(2)(a) 6764 Associate records with their security attributes. 920 Establish and maintain data input and data access authorization tracking. AU-10(3) ¶ 1 567 Implement non-repudiation for transactions. 13203 Validate transactions using identifiers and credentials. AU-13 Control 10419 Search the Internet for evidence of data leakage. 10419 Search the Internet for evidence of data leakage. 10593 Review monitored websites for data leakage. CA-8(2) ¶ 1 1277 Perform network-layer penetration testing on all systems, as necessary. 12131 Conduct Red Team exercises, as necessary. PE-18(1) ¶ 1 6351 Define selection criteria for facility locations. 6351 Define selection criteria for facility locations. 6479 Employ risk assessment procedures that take into account the target environment. PE-20a. 10626 Attach asset location technologies to distributed Information Technology assets. 10626 Attach asset location technologies to distributed Information Technology assets. 11684 Monitor the location of distributed Information Technology assets. CM-3(3) ¶ 1 2130 Create a Configuration Baseline Documentation Record before promoting the system to a production environment. 12103 Review and update Configuration Baseline Documentation Records, as necessary. 12503 Apply configuration standards to all systems, as necessary. CM-5(4) ¶ 1 11776 Implement changes according to the change control program. 11776 Implement changes according to the change control program. 887 Manage change requests. CM-6a. 2132 Establish and maintain an accurate Configuration Management Database with accessible reporting capabilities. 11953 Establish and maintain configuration standards for all systems based upon industry best practices. CM-7(3) ¶ 1 537 Include a protocols, ports, applications, and services list in the firewall and router configuration standard. 12547 Include approval of the protocols, ports, applications, and services list in the firewall and router configuration standard. CP-2(6) ¶ 1 742 Designate an alternate facility in the continuity plan. 744 Prepare the alternate facility for an emergency offsite relocation. 1169 Include restoration procedures in the continuity plan. CP-2(7) ¶ 1 1386 Coordinate continuity planning with other business units responsible for related continuity plans. 13242 Coordinate and incorporate supply chain members' continuity plans, as necessary. CP-4(3) ¶ 1 1389 Automate the off-site testing to more thoroughly test the continuity plan. 755 Test the continuity plan, as necessary. CP-11 Control 1294 Include Wide Area Network continuity procedures in the continuity plan. 750 Include emergency communications procedures in the continuity plan. CP-8(5) ¶ 1 755 Test the continuity plan, as necessary. 12777 Validate the emergency communications procedures during continuity plan tests. IA-2(6) ¶ 1 561 Implement two-factor authentication techniques. 561 Implement two-factor authentication techniques. 6836 Establish and maintain a register of approved third parties, technologies and tools. IA-2(7) ¶ 1 561 Implement two-factor authentication techniques. 561 Implement two-factor authentication techniques. 6836 Establish and maintain a register of approved third parties, technologies and tools. IA-2(10) ¶ 1 11841 Include digital identification procedures in the access control program. 553 Enable logon authentication management techniques. IA-4 Control 0 UCF CE List 515 Control the addition and modification of user identifiers, user credentials, or other object identifiers. IA-4(2) ¶ 1 515 Control the addition and modification of user identifiers, user credentials, or other object identifiers. 515 Control the addition and modification of user identifiers, user credentials, or other object identifiers. 6641 Review and approve logical access to all assets based upon organizational policies. IA-4(6) ¶ 1 515 Control the addition and modification of user identifiers, user credentials, or other object identifiers. 12201 Provide identification mechanisms for the organization's supply chain members. IA-4(7) ¶ 1 8712 Require multiple forms of personal identification prior to issuing user IDs. 13750 Support the identity proofing process through in-person proofing or remote proofing. IA-9 Control 513 Establish and maintain an access rights management plan. 14053 Establish, implement, and maintain identification and authentication procedures. IA-9(1) ¶ 1 1429 Require the system to identify and authenticate approved devices before establishing a connection to restricted data. 14227 Include coordination amongst entities in the identification and authentication policy. IA-9(2) ¶ 1 1429 Require the system to identify and authenticate approved devices before establishing a connection to restricted data. 14053 Establish, implement, and maintain identification and authentication procedures. IR-3(1) ¶ 1 6752 Use automated mechanisms in the training environment, where appropriate. 1216 Test the incident response procedures. IR-4(10) ¶ 1 1212 Share incident information with interested personnel and affected parties. 13196 Coordinate incident response activities with interested personnel and affected parties. MA-4(4) ¶ 1 0 UCF CE List 1433 Control remote maintenance according to the system's asset classification. MA-4(7) ¶ 1 4262 Activate third party maintenance accounts and user identifiers, as necessary. 12083 Terminate remote maintenance sessions when the remote maintenance is complete. MA-5(4)(b) 1434 Conduct maintenance with authorized personnel. 11873 Control granting access to third parties performing maintenance on organizational assets. 6509 Include a description of the product or service to be provided in third party contracts. MP-4a. 11664 Physically secure all electronic storage media that store restricted data or restricted information. 11664 Physically secure all electronic storage media that store restricted data or restricted information. 965 Control the storage of restricted storage media. MP-4(2) ¶ 1 371 Establish and maintain access controls for all records. 12462 Authorize physical access to sensitive areas based on job functions. 6797 Monitor for unauthorized physical access at physical entry points. 12080 Establish and maintain a physical access log. PE-2(2) ¶ 1 713 Establish and maintain physical identification procedures. 6701 Check the visitor's stated identity against a provided government issued identification. PE-3(2) ¶ 1 1441 Control the delivery of assets through physical entry points and physical exit points. 11681 Control the removal of assets through physical entry points and physical exit points. PE-3(3) ¶ 1 6653 Employ security guards to provide physical security, as necessary. 6653 Employ security guards to provide physical security, as necessary. 11669 Maintain all security alarm systems. PE-5(1)(b) 926 Establish, implement, and maintain document handling procedures for paper documents. 11656 Establish and maintain document security requirements for the output of records. PE-5(2)(a) 926 Establish, implement, and maintain document handling procedures for paper documents. 371 Establish and maintain access controls for all records. PE-5(2)(b) 926 Establish, implement, and maintain document handling procedures for paper documents. 372 Provide audit trails for all pertinent records. PL-9 Control 6328 Adhere to operating procedures as defined in the Standard Operating Procedures Manual. 12415 Establish and maintain a baseline of internal controls. RA-3b. 6481 Include the results of the risk assessment in the risk assessment report. 6481 Include the results of the risk assessment in the risk assessment report. 6481 Include the results of the risk assessment in the risk assessment report. 11978 Include risk assessment results in the risk treatment plan. 6481 Include the results of the risk assessment in the risk assessment report. SA-4(3) ¶ 1 1447 Require the Information System developer to create a Security Testing and Evaluation plan, implement the test, and provide the test results for all newly acquired Information Technology assets. 1447 Require the Information System developer to create a Security Testing and Evaluation plan, implement the test, and provide the test results for all newly acquired Information Technology assets. 1124 Include security requirements in system acquisition contracts. 14256 Include a description of the development environment and operational environment in system acquisition contracts. 1100 Perform Quality Management on all newly developed or modified systems. SA-4(5)(b) 1446 Provide a Configuration Management plan by the Information System developer for all newly acquired information technology assets. 12503 Apply configuration standards to all systems, as necessary. SA-4(6)(a) 1133 Establish, implement, and maintain a product and services acquisition strategy. 6836 Establish and maintain a register of approved third parties, technologies and tools. SA-11(3)(b) 11638 Assign vulnerability scanning to qualified personnel or external third parties. 11638 Assign vulnerability scanning to qualified personnel or external third parties. 12186 Grant access to authorized personnel. SA-11(7) ¶ 1 1100 Perform Quality Management on all newly developed or modified systems. 1447 Require the Information System developer to create a Security Testing and Evaluation plan, implement the test, and provide the test results for all newly acquired Information Technology assets. SA-12(5) ¶ 1 8808 Establish, implement, and maintain a supply chain management policy. 8811 Include risk management procedures in the supply chain management policy. SA-12(7) ¶ 1 1135 Conduct a risk assessment to determine operational risks as a part of the acquisition feasibility study. 1129 Conduct an acquisition feasibility study prior to acquiring Information Technology assets. 1144 Establish, implement, and maintain facilities, assets, and services acceptance procedures. 12218 Establish and maintain product update procedures. SA-12(11) ¶ 1 8811 Include risk management procedures in the supply chain management policy. 8854 Conduct all parts of the supply chain due diligence process. 8861 Assign the appropriate individuals or groups to oversee and support supply chain due diligence. 655 Perform penetration tests, as necessary. SA-12(8) ¶ 1 8811 Include risk management procedures in the supply chain management policy. 8854 Conduct all parts of the supply chain due diligence process. SA-12(9) ¶ 1 8818 Use third parties that are compliant with the applicable requirements. 13109 Establish and maintain information security controls for the supply chain. SA-12(13) ¶ 1 1435 Perform periodic maintenance according to organizational standards. 6388 Maintain contact with the device manufacturer or component manufacturer for maintenance requests. SA-12(14) ¶ 1 8958 Include a unique reference identifier on products for sale. 8958 Include a unique reference identifier on products for sale. 968 Retain records in accordance with applicable requirements. SA-12(15) ¶ 1 8810 Include a clear management process in the supply chain management policy. 8815 Implement measurable improvement plans with all third parties. SA-13b. 1124 Include security requirements in system acquisition contracts. 1125 Include security controls in system acquisition contracts. SA-15(1)(b) 8667 Include measurable system performance requirements in the system design specification. 1100 Perform Quality Management on all newly developed or modified systems. SA-15(2) ¶ 1 1096 Supervise and monitor outsourced development projects. 14307 Require the information system developer to create a continuous monitoring plan. SA-15(4) ¶ 1 0 UCF CE List 6829 Include threat models in the system design specification. 11828 Perform vulnerability assessments, as necessary. SA-15(7)(a) 11637 Perform vulnerability scans, as necessary. 11637 Perform vulnerability scans, as necessary. SA-15(7)(b) 11744 Establish and maintain system testing procedures. 11940 Rank discovered vulnerabilities. SA-15(7)(c) 6910 Change the scope, definition, and work breakdown of the system development project after corrective actions are taken. 6909 Initiate preventive actions to achieve the system development project's goals and outputs. SA-15(7)(d) 4881 Recommend mitigation techniques based on penetration test results. 11639 Recommend mitigation techniques based on vulnerability scan reports. SA-15(8) ¶ 1 11637 Perform vulnerability scans, as necessary. 6829 Include threat models in the system design specification. 1000 Perform a risk assessment for each system development project. SA-15(9) ¶ 1 1103 Restrict production data from being used in the test environment. 11744 Establish and maintain system testing procedures. 6609 Document the procedures and environment used to create the system or software. 1103 Restrict production data from being used in the test environment. SA-15(10) ¶ 1 588 Include intrusion detection procedures in the Incident Management program. 12056 Establish and maintain an incident response plan. SA-17(2)(a) 4558 Establish, implement, and maintain a system implementation representation document. 8666 Include hardware requirements in the system design specification. 8664 Include supporting software requirements in the system design specification. SA-17(3)(c) 4556 Include all confidentiality, integrity, and availability functions in the system design specification. 4559 Include the relationships and dependencies between modules in the system design specification. SA-17(3)(e) 4556 Include all confidentiality, integrity, and availability functions in the system design specification. 11734 Include a description of each module and asset in the system design specification. SA-17(4)(c) 4556 Include all confidentiality, integrity, and availability functions in the system design specification. 4559 Include the relationships and dependencies between modules in the system design specification. SA-17(4)(d) 4556 Include all confidentiality, integrity, and availability functions in the system design specification. 4559

Newsletter

Compliance Intelligence Insights Delivered to Your Inbox

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.