NIST SP 800-53 / 800-171

NIST SP 800-53 defines security & privacy control families for federal information systems; SP 800-171 protects controlled unclassified information in non-federal systems. The families are abstract, so a Pavois check is a **supporting** reference, it provides evidence toward several at once, not standalone fulfilment of a family. The 800-171 references are pinned to **Rev 2**: the crosswalk was anchored against it, and Rev 3 (May 2024) renumbers the requirements, so re-anchoring is a full cross-validation pass, not a search-and-replace. Stating the revision is the point: a mapping to an unnamed revision is worthless.

Authority NISTVersion 800-53 Rev 5 · 800-171 Rev 2 (pinned)coverage 323 controlsOfficial documentation →Evidence & exportsID modelOSCAL ↓
13 high273 medium26 low9 OS94% reboot-proof
How to read the references

A NIST reference on a control can come from two publications at once, that is why a single rule may show both 3.1.1 and AC-3:

LL-NSP 800-53 Rev 5, the federal control catalogue (~1000 controls). e.g. AC-3, CM-6, SC-7.
3.X.YSP 800-171, the smaller subset derived from 800-53 to protect Controlled Unclassified Information at non-federal organisations. e.g. 3.1.1, 3.3.7.

The same hardening control maps to both publications, so Pavois carries both forms.

Anatomy of an 800-53 reference, reading CM-7(5)(b):

  • CM, the family (Configuration Management)
  • 7, the control number within that family
  • (5), a numbered enhancement: a stricter, optional add-on to the base control
  • (b), a lettered statement part of the requirement text

So CM-6(a) is simply part (a) of control CM-6, while AC-6(8) is the 8th enhancement of AC-6.

The families you will see here: AC Access Control · AU Audit & Accountability · CM Configuration Management · IA Identification & Authentication · SC System & Communications Protection · SI System & Information Integrity.

323 / 323
RefRuleOSDomainSev.NIST control
SOCLE-CLD-IAM-001Verify Only Root Has UID 09Accountscritical3.1.1 · AC-6(5) · IA-2 · IA-4(b)
SOCLE-CLD-IAM-002Verify All Account Password Hashes are Shadowed9Accountscritical3.5.10 · CM-6(a) · IA-5(h)
SOCLE-CLD-IAM-004Set Account Expiration Following Inactivity8Accounts (login.defs)mediumIA-4(e) · AC-2(3) · CM-6(a)
SOCLE-CLD-IAM-005All GIDs referenced in /etc/passwd must be defined in /etc/group9AccountslowCM-6(a) · IA-2
SOCLE-CLD-IAM-006Prevent Login to Accounts With Empty Password9Accountscritical3.1.1 · CM-6(a) · IA-5(1)(a) · IA-5(c)
SOCLE-RUN-AUD-001Record Events that Modify the System's Discretionary Access Controls - chmod9Audit (auditd)medium3.1.7 · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-004Record Any Attempts to Run chacl9Audit (auditd)medium3.1.7
SOCLE-RUN-AUD-005Ensure auditd Collects File Deletion Events by User - rename9Audit (auditd)medium3.1.7 · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-006Make the auditd Configuration Immutable9Audit (auditd)medium3.3.1 · AC-6(9) · CM-6(a)
SOCLE-RUN-AUD-007Ensure auditd Collects Information on Kernel Module Unloading - create_module4Audit (auditd)medium3.1.7
SOCLE-RUN-AUD-008Record Attempts to Alter Logon and Logout Events - faillock9Audit (auditd)medium3.1.7 · AC-6(9) · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-009Record Events that Modify the System's Mandatory Access Controls9Audit (auditd)medium3.1.8 · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-010Ensure auditd Collects Information on Exporting to Media (successful)9Audit (auditd)medium3.1.7 · AC-6(9) · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-011Record Events that Modify the System's Network Environment9Audit (auditd)medium3.1.7 · AC-6(9) · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-013Ensure auditd Collects Information on the Use of Privileged Commands - fdisk3Audit (auditd)medium3.1.7
SOCLE-RUN-AUD-015Record Attempts to Alter Process and Session Initiation Information9Audit (auditd)medium3.1.7 · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-018Record Events When Privileged Executables Are Run7Audit (auditd)mediumAC-6(9) · AU-12(3) · AU-7(a) · AU-7(b) · AU-8(b) · CM-5(1)
SOCLE-RUN-AUD-019Ensure auditd Collects System Administrator Actions8Audit (auditd)medium3.1.7 · AC-2(7)(b) · AC-6(9) · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-020Record attempts to alter time through adjtimex9Audit (auditd)medium3.1.7 · AC-6(9) · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-021Record Attempts to Alter Time Through clock_settime9Audit (auditd)medium3.1.7 · AC-6(9) · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-022Record Unsuccessful Access Attempts to Files - creat9Audit (auditd)medium3.1.7 · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-023Record Events that Modify User/Group Information - /etc/group9Audit (auditd)medium3.1.7 · AC-2(4) · AC-6(9) · AU-12(c) · AU-2(d) · CM-6(a)
SOCLE-RUN-AUD-025Configure auditd mail_acct Action on Low Disk Space9Audit (auditd daemon)medium3.3.1 · AU-5(2) · AU-5(a) · CM-6(a) · IA-5(1)
SOCLE-RUN-AUD-026Configure auditd admin_space_left Action on Low Disk Space9Audit (auditd daemon)medium3.3.1 · AU-5(1) · AU-5(2) · AU-5(4) · AU-5(b) · CM-6(a)
SOCLE-RUN-AUD-028Configure auditd Disk Error Action on Disk Error9Audit (auditd daemon)mediumAU-5(1) · AU-5(2) · AU-5(4) · AU-5(b) · CM-6(a)
SOCLE-RUN-AUD-029Configure auditd Disk Full Action when Disk Space Is Full9Audit (auditd daemon)mediumAU-5(1) · AU-5(2) · AU-5(4) · AU-5(b) · CM-6(a)
SOCLE-RUN-AUD-030Configure auditd flush priority4Audit (auditd daemon)medium3.3.1
SOCLE-RUN-AUD-032Configure auditd Max Log File Size9Audit (auditd daemon)mediumAU-11 · CM-6(a)
SOCLE-RUN-AUD-033Configure auditd max_log_file_action Upon Reaching Maximum Log Size9Audit (auditd daemon)mediumAU-5(1) · AU-5(2) · AU-5(4) · AU-5(b) · CM-6(a)
SOCLE-RUN-AUD-035Configure auditd Number of Logs Retained1Audit (auditd daemon)medium3.3.1
SOCLE-RUN-AUD-036Configure auditd space_left Action on Low Disk Space9Audit (auditd daemon)medium3.3.1 · AU-5(1) · AU-5(2) · AU-5(4) · AU-5(b) · CM-6(a)
SOCLE-RUN-AUD-037Configure auditd space_left on Low Disk Space7Audit (auditd daemon)mediumAU-5(1) · AU-5(2) · AU-5(4) · AU-5(b) · CM-6(a)
SOCLE-CLD-KRN-001Enable Auditing for Processes Which Start Prior to the Audit Daemon9Kernel command linelow3.3.1 · AC-17(1) · AU-10 · AU-14(1) · CM-6(a) · IR-5(1)
SOCLE-CLD-KRN-002Extend Audit Backlog Limit for the Audit Daemon9Kernel command linelowCM-6(a)
SOCLE-CLD-KRN-010Enable page allocator poisoning9Kernel command linemediumCM-6(a)
SOCLE-CLD-KRN-011Enable Kernel Page-Table Isolation (KPTI)9Kernel command linelowSI-16
SOCLE-CLD-KRN-013Ensure SELinux Not Disabled in /etc/default/grub4Kernel command linemedium3.1.2
SOCLE-CLD-KRN-015Enable SLUB/SLAB allocator poisoning9Kernel command linemediumCM-6(a)
SOCLE-CLD-GEN-004Enable GNOME3 Login Warning Banner9GNOME desktop (dconf)medium3.1.9 · AC-8(a) · AC-8(b) · AC-8(c)
SOCLE-CLD-GEN-005Disable GNOME3 Automounting9GNOME desktop (dconf)medium3.1.7 · CM-6(a) · CM-7(a) · CM-7(b)
SOCLE-CLD-GEN-006Disable GNOME3 Automount Opening9GNOME desktop (dconf)medium3.1.7 · CM-6(a) · CM-7(a) · CM-7(b)
SOCLE-CLD-GEN-007Disable GNOME3 Automount running9GNOME desktop (dconf)low3.1.7 · CM-6(a) · CM-7(a) · CM-7(b)
SOCLE-CLD-GEN-008Disable Ctrl-Alt-Del Reboot Key Sequence in GNOME37GNOME desktop (dconf)high3.1.2 · AC-6(1) · CM-6(a) · CM-7(b)
SOCLE-CLD-GEN-009Disable the GNOME3 Login Restart and Shutdown Buttons3GNOME desktop (dconf)high3.1.2
SOCLE-CLD-GEN-010Disable the GNOME3 Login User List9GNOME desktop (dconf)mediumAC-23 · CM-6(a)
SOCLE-CLD-GEN-012Set the GNOME3 Login Warning Banner Text9GNOME desktop (dconf)medium3.1.9 · AC-8(a) · AC-8(c)
SOCLE-CLD-GEN-013Set the GNOME3 Login Number of Failures1GNOME desktop (dconf)medium3.1.8
SOCLE-CLD-GEN-016Set GNOME3 Screensaver Lock Delay After Activation Period3GNOME desktop (dconf)medium3.1.10 · AC-11(a) · CM-6(a)
SOCLE-CLD-GEN-017Enable GNOME3 Screensaver Idle Activation1GNOME desktop (dconf)medium3.1.10
SOCLE-CLD-GEN-018Set GNOME3 Screensaver Inactivity Timeout3GNOME desktop (dconf)medium3.1.10 · AC-11(a) · CM-6(a)
SOCLE-CLD-GEN-019Enable GNOME3 Screensaver Lock After Idle Period9GNOME desktop (dconf)mediumCM-6(a) · 3.1.10
SOCLE-CLD-GEN-020Ensure Users Cannot Change GNOME3 Screensaver Lock After Idle Period4GNOME desktop (dconf)medium3.1.10
SOCLE-CLD-GEN-021Implement Blank Screensaver5GNOME desktop (dconf)medium3.1.10 · AC-11(1) · AC-11(1).1 · CM-6(a)
SOCLE-CLD-GEN-023Ensure Users Cannot Change GNOME3 Screensaver Settings8GNOME desktop (dconf)medium3.1.10
SOCLE-CLD-GEN-024Ensure Users Cannot Change GNOME3 Session Idle Settings8GNOME desktop (dconf)medium3.1.10
SOCLE-CLD-IAM-008Lock Accounts After Failed Password Attempts9Accounts (faillock)medium3.1.8 · AC-7(a) · CM-6(a)
SOCLE-CLD-IAM-009Set Lockout Time for Failed Password Attempts9Accounts (faillock)medium3.1.8 · AC-7(b) · CM-6(a)
SOCLE-CLD-FSP-003Verify Group Who Owns Backup group File9File ownershipmediumAC-6 (1)
SOCLE-CLD-FSP-004Verify Group Who Owns Backup gshadow File9File ownershipmediumAC-6 (1)
SOCLE-CLD-FSP-005Verify Group Who Owns Backup passwd File9File ownershipmediumAC-6 (1)