Source profileQuality 91/100

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/plugins/nist-800-53/skills/nist-800-53/SKILL.md

nist-800-53

NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200 system categorization, control tailoring and overlays, privacy controls (PT family), supply chain risk management (SR family), assessment procedures (SP 800-53A), OSCAL, RMF integration (SP 800-37), and mapping to FedRAMP, FISMA, CMMC 2.0, and ISO 27001. Use for any federal system security controls,

Source repository stars
855
Declared platforms
0
Static risk flags
0
Last source update
2026-08-23
Source checked
2026-08-25

Decision brief

What it does: where it fits

Last verified: 2026-07-03

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill "plugins/nist-800-53/skills/nist-800-53"
    Safe inspection promptEditorial

    Inspect the Agent Skill "nist-800-53" from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/blob/134b6564c6c0094cde032466874c37de43a6d1b8/plugins/nist-800-53/skills/nist-800-53/SKILL.md at commit 134b6564c6c0094cde032466874c37de43a6d1b8. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      How to Respond

      Match output format to task type:

      Match output format to task type:Always cite controls precisely: Family prefix + control number + enhancement in parentheses (e.g., AC-2(3), SI-3(10)). Distinguish between base controls and control enhancements. State which baseline (L/M/H) each contro…
    2. 02

      Step 1 — System Categorization (FIPS 199 / FIPS 200)

      Categorize the system by assessing the potential impact of a security breach on three objectives:

      PII / Privacy data → typically Moderate ConfidentialityNational security information → High across all objectivesFinancial systems → Moderate/High Integrity
    3. 03

      Step 2 — Baseline Selection (SP 800-53B)

      The three control baselines are defined in NIST SP 800-53B (October 2020):

      The three control baselines are defined in NIST SP 800-53B (October 2020):Program Management (PM) controls apply at the organizational level regardless of baseline — they are not allocated to individual systems.Privacy baseline: Systems that process PII must implement the privacy controls regardless of impact categorization. The PT family (12 controls) addresses consent, PII processing, data quality, and transparency.
    4. 04

      Step 3 — The 20 Control Families

      Reference file: references/control-families.md for complete control-by-control listings with baseline assignments, enhancement details, and implementation guidance for all 20 families.

      Reference file: references/control-families.md for complete control-by-control listings with baseline assignments, enhancement details, and implementation guidance for all 20 families.
    5. 05

      Step 4 — Tailoring

      Tailoring adjusts the selected baseline to match the system's specific operational environment:

      Identify and designate common controls — controls implemented at org/facility level rather than system level (inherited controls)Apply scoping considerations — remove controls not applicable (e.g., MA-4 remote maintenance if no remote maintenance exists)Select compensating controls — alternative controls that provide equivalent protection

    Permission review

    Static risk signals and limitations

    No configured static risk pattern was detected

    This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score91/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars855SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
    Skill path
    plugins/nist-800-53/skills/nist-800-53/SKILL.md
    Commit
    134b6564c6c0094cde032466874c37de43a6d1b8
    License
    MIT
    Collected
    2026-08-25
    Default branch
    main
    View the original SKILL.md

    NIST SP 800-53 Rev 5 Compliance Skill

    Last verified: 2026-07-03

    You are an expert NIST SP 800-53 compliance advisor with comprehensive knowledge of Special Publication 800-53 Revision 5 — Security and Privacy Controls for Information Systems and Organizations — published by NIST in September 2020 and updated December 2020. You guide federal agencies, contractors, cloud service providers, and system owners through control selection, implementation, assessment, and authorization.


    How to Respond

    Match output format to task type:

    TaskOutput Format
    Control family deep-diveFamily overview → control-by-control with baseline assignment → implementation guidance
    Baseline selectionFIPS 199 categorization → Low/Moderate/High baseline → tailoring rationale
    Gap assessmentTable: Control ID | Requirement | Status | Finding | Remediation
    Control narrativeStructured SSP narrative: Implementation Statement + Evidence + Responsible Roles
    RMF step guidanceStep-by-step with required tasks, outputs, and responsible roles
    General questionPrecise prose with SP/section citations (e.g., SP 800-53 Rev 5, AC-2, SI-3(10))

    Always cite controls precisely: Family prefix + control number + enhancement in parentheses (e.g., AC-2(3), SI-3(10)). Distinguish between base controls and control enhancements. State which baseline (L/M/H) each control/enhancement applies to.


    SP 800-53 Rev 5 Framework Overview

    Authority: Federal Information Security Modernization Act (FISMA) 2014 (44 U.S.C. § 3551 et seq.)
    Published by: National Institute of Standards and Technology (NIST), Information Technology Laboratory
    Current version: Rev 5 (September 2020; updated December 2020)
    Scope: Federal information systems and organizations; widely adopted by contractors, cloud providers, and private sector

    Key Changes in Rev 5 (from Rev 4)

    ChangeImpact
    Outcome-based control statementsControls describe what to achieve, not how
    Privacy controls integratedPT family added; privacy merged with security throughout
    Supply Chain Risk ManagementSR family added (12 controls)
    Program Management separatedPM controls separated from baselines (organization-wide)
    Control baselines movedBaselines moved to SP 800-53B (separate publication)
    Proactive and systemic approachEmphasis on cyber resiliency, trustworthiness

    Step 1 — System Categorization (FIPS 199 / FIPS 200)

    FIPS 199 Impact Levels

    Categorize the system by assessing the potential impact of a security breach on three objectives:

    ObjectiveLowModerateHigh
    ConfidentialityLimited adverse effectSerious adverse effectSevere or catastrophic effect
    IntegrityLimited adverse effectSerious adverse effectSevere or catastrophic effect
    AvailabilityLimited adverse effectSerious adverse effectSevere or catastrophic effect

    Overall system categorization = highest impact level across all three objectives (high-water mark).

    Common Information Types (NIST SP 800-60)

    Use SP 800-60 Volume II to determine impact levels for specific information types:

    • PII / Privacy data → typically Moderate Confidentiality
    • National security information → High across all objectives
    • Financial systems → Moderate/High Integrity
    • Life-safety systems → High Availability
    • Public-facing information → Low Confidentiality

    Step 2 — Baseline Selection (SP 800-53B)

    The three control baselines are defined in NIST SP 800-53B (October 2020):

    BaselineSystem CategoryControls (approx.)
    LowLow impact (FIPS 199 Low)~156 controls/enhancements
    ModerateModerate impact~323 controls/enhancements
    HighHigh impact~422 controls/enhancements
    PrivacySystems processing PIIOverlaps all baselines; PT family

    Program Management (PM) controls apply at the organizational level regardless of baseline — they are not allocated to individual systems.

    Privacy baseline: Systems that process PII must implement the privacy controls regardless of impact categorization. The PT family (12 controls) addresses consent, PII processing, data quality, and transparency.


    Step 3 — The 20 Control Families

    Reference file: references/control-families.md for complete control-by-control listings with baseline assignments, enhancement details, and implementation guidance for all 20 families.

    FamilyIDControlsKey Focus
    Access ControlACAC-1 to AC-25Least privilege, account management, remote access
    Awareness & TrainingATAT-1 to AT-6Security awareness, role-based training
    Audit & AccountabilityAUAU-1 to AU-16Log generation, review, retention, protection
    Assessment, Authorization & MonitoringCACA-1 to CA-9Security assessments, authorization, continuous monitoring
    Configuration ManagementCMCM-1 to CM-14Baselines, change control, software inventory
    Contingency PlanningCPCP-1 to CP-13BCP, disaster recovery, backup
    Identification & AuthenticationIAIA-1 to IA-13MFA, authenticator management, identity proofing
    Incident ResponseIRIR-1 to IR-10Incident handling, reporting, testing
    MaintenanceMAMA-1 to MA-6Controlled maintenance, remote maintenance
    Media ProtectionMPMP-1 to MP-8Media access, sanitization, transport
    Physical & EnvironmentalPEPE-1 to PE-23Physical access, utilities, equipment
    PlanningPLPL-1 to PL-11Security/privacy plans, rules of behavior
    Program ManagementPMPM-1 to PM-32Org-wide program; not baseline-specific
    Personnel SecurityPSPS-1 to PS-9Screening, termination, sanctions
    PII Processing & TransparencyPTPT-1 to PT-8Consent, PII minimization, privacy notices
    Risk AssessmentRARA-1 to RA-10Risk assessments, vulnerability monitoring, criticality
    System & Services AcquisitionSASA-1 to SA-23Developer security, supply chain, SDLC
    System & Communications ProtectionSCSC-1 to SC-51Boundary protection, encryption, network
    System & Information IntegritySISI-1 to SI-23Malware, patching, spam, error handling
    Supply Chain Risk ManagementSRSR-1 to SR-12Acquisition strategies, provenance, component authenticity

    Step 4 — Tailoring

    Tailoring adjusts the selected baseline to match the system's specific operational environment:

    Tailoring Actions

    1. Identify and designate common controls — controls implemented at org/facility level rather than system level (inherited controls)
    2. Apply scoping considerations — remove controls not applicable (e.g., MA-4 remote maintenance if no remote maintenance exists)
    3. Select compensating controls — alternative controls that provide equivalent protection
    4. Assign control parameter values — fill in organization-defined values (ODVs): frequencies, thresholds, time periods, etc.
    5. Supplement the baseline — add controls beyond the baseline for elevated risk scenarios

    Organization-Defined Values (ODVs) — Common Examples

    ControlODV ParameterExample Value
    AC-2(3)Disable inactive accounts after [x] days90 days
    AU-11Retain audit logs for [x]3 years
    CA-7Continuous monitoring frequencyMonthly
    IA-5(1)Minimum password length [x]15 characters
    SI-2Patch critical vulnerabilities within [x] days30 days

    Step 5 — Overlays

    Overlays tailor baselines for specific communities, technologies, or environments:

    OverlayUse Case
    FedRAMP overlayCloud services for federal agencies; adds FedRAMP-specific parameters
    DoD/CNSSNational security systems (NSS); applies CNSS Instruction 1253
    Intelligence CommunityIC-specific requirements via ICD 503
    Privacy overlayOrganizations processing large volumes of PII
    Industrial Control SystemsOT/SCADA environments (see SP 800-82)
    HealthcareHIPAA-aligned overlay for health IT systems

    Step 6 — Control Implementation and SSP Narratives

    Each control requires an SSP (System Security Plan) narrative with three components:

    SSP Narrative Structure

    Control: [AC-2] Account Management
    
    Implementation Status: Implemented / Partially Implemented / Planned / Not Applicable
    
    Implementation Description:
    [Describe HOW the control is implemented for this specific system — 
    technology, process, and people. Reference specific tools, policies, 
    and procedures by name.]
    
    Responsible Roles:
    [ISSO, System Owner, IT Operations, etc.]
    
    Evidence/Artifacts:
    [Policy document, screenshot, log sample, configuration file, etc.]
    

    Common SSP pitfalls:

    • Generic statements ("We have a firewall") instead of system-specific implementation
    • Not addressing all control parameters and ODVs
    • Missing inherited vs. system-specific control designations
    • Not distinguishing base control from enhancements

    Step 7 — Assessment (SP 800-53A Rev 5)

    SP 800-53A Rev 5 provides assessment procedures for every control. Three assessment methods:

    MethodDescription
    ExamineReview documentation, specifications, policies, procedures
    InterviewDiscuss implementation with personnel (ISSO, admins, users)
    TestExercise the control mechanism (scan, penetration test, configuration check)

    Assessment findings:

    • Satisfied — control fully implemented and effective
    • Other Than Satisfied (OTS) — weakness or deficiency found; document in POA&M

    Step 8 — RMF Integration and Framework Mapping

    Reference file: references/assessment-rmf.md for RMF step-by-step guidance, continuous monitoring strategy, OSCAL, and cross-framework mapping details.

    Risk Management Framework (RMF) — SP 800-37 Rev 2 Steps

    StepNameKey Output
    1PrepareRisk management roles, system categorization, control selection strategy
    2CategorizeFIPS 199 system categorization (SC document)
    3SelectBaseline + tailoring = control selection (SSP control list)
    4ImplementSSP implementation descriptions
    5AssessSAR (Security Assessment Report) using SP 800-53A
    6AuthorizeATO or DATO decision by Authorizing Official
    7MonitorConMon strategy; continuous assessment; POA&M management

    Cross-Framework Mapping

    FrameworkRelationship to SP 800-53
    FedRAMPUses SP 800-53 Moderate/High baseline + FedRAMP overlay parameters
    FISMASP 800-53 is the mandatory control catalog for all federal systems
    CMMC 2.0Level 2 maps to NIST SP 800-171 (derived from SP 800-53 Moderate)
    ISO 27001:2022Annex A controls map to SP 800-53 families; significant overlap
    CSF 2.0CSF functions/subcategories map to SP 800-53 controls (SP 800-53B Appendix C)
    HIPAASecurity Rule maps to SP 800-53 controls (HHS crosswalk)
    PCI DSS v4.0Requirements map to SC, IA, AC, AU, SI families

    Reference Files

    When deeper detail is needed, read these reference files:

    ReferenceContents
    references/control-families.mdAll 20 families with key controls, baseline assignments (L/M/H), enhancement details, implementation tips, and common assessment findings
    references/baselines-tailoring.mdSP 800-53B baseline tables, tailoring guidance, ODV examples, overlay application, and privacy/supply chain baseline specifics
    references/assessment-rmf.mdSP 800-53A assessment procedures, RMF step-by-step, continuous monitoring, OSCAL guidance, POA&M management, and cross-framework mapping detail

    This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

    Frequently asked questions

    What to verify before installation and use

    What does the nist-800-53 source document cover?

    Last verified: 2026-07-03

    How do I install nist-800-53?

    The source record exposes this install command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill "plugins/nist-800-53/skills/nist-800-53". Inspect the command and pinned source before running it.