NIST SP 800-53 Rev 5
U.S. federal security and privacy controls catalog. Includes both NIST-prefixed detection controls and cross-framework tags on all controls.
Official documentation35
Controls
24
Auto-Remediable
3
Domains
Entra ID(20)
NIST-AC-11Idle session timeout configured for Office 365 apps
NIST-AC-12No persistent browser session
NIST-AC-17.1Require approved or compliant client apps for mobile access
NIST-AC-2.12Identity protection risk detection monitoring configured
NIST-AC-2.3App credentials rotated within 180 days
NIST-AC-2.5Periodic access review enabled for privileged roles
NIST-AC-20.1B2B collaboration outbound access controlled
NIST-AC-20.2B2B direct connect outbound access controlled
NIST-AC-3Block all agent users
NIST-AC-3.1Workload identity Conditional Access policy configured
NIST-AC-6.2No guest users in Global Administrator role
NIST-AC-6.5Minimize standing Global Admin privilege
NIST-AC-6.6Application registrations with credentials have multiple owners
NIST-AC-6.7Global Administrators use PIM eligible assignments instead of permanent
NIST-IA-2.2Require MFA for device registration
NIST-IA-2.6Custom authentication strength policy defined
NIST-IA-5.1Application credentials do not exceed 12-month expiry
NIST-IA-5.2Applications use certificate credentials over secrets
NIST-IA-5.3Password notification window is at least 14 days
NIST-IA-5.4No expired app registration credentials
Intune(11)
NIST-CM-2Intune MDM authority configured
NIST-CM-3Configure Delivery Optimization
NIST-CM-6.1Platform enrollment restrictions configured
NIST-CM-7Deploy App Control for Business (application whitelisting)
NIST-IA-12Windows Hello for Business enrollment configured
NIST-SC-7Enable Windows Firewall on all profiles
NIST-SI-2Windows Update for Business rings configured
NIST-SI-2.1Feature update profile configured
NIST-SI-2.2Quality update expedite configured
NIST-SI-3Configure Attack Surface Reduction rules
NIST-SI-4Deploy Endpoint Detection and Response (EDR) policy
Exchange(4)
NIST-AU-2Exchange admin audit logging enabled
NIST-SC-7.1Inbound mail connector enforces TLS
NIST-SC-7.2Outbound mail connector enforces TLS
NIST-SI-3aZero-hour auto purge (ZAP) enabled for malware
