Control Specifications
This section is a NIST SP 800-53 overlay—a set of supplemental guidance and parameter values that tailor existing controls without replacing base requirements. It is a partial overlay, covering only the long lead time interventions highlighted in Section 1. The complete SL5 overlay will build on IL6, which itself incorporates FedRAMP High, CNSSI 1253, and other frameworks; future revisions will explicitly map SL5 requirements to IL6.
Organized by NIST control family. "NIST Control Text" and "NIST Discussion" are taken verbatim from NIST SP 800-53 Rev 5. "SL5 Supplemental Guidance" and "Parameter Values" are additions specific to this standard. Where a Parameter Values section is absent or a specific assignment is not provided, organizations define values based on their specific context.
Access Control
4 controls
Configuration Management
1 control
Identification and Authentication
1 control
Physical and Environmental Protection
3 controls
Program Management
1 control
Personnel Security
3 controls
System and Services Acquisition
5 controls
Supply Chain Risk Management
9 controls
System and Communications Protection
11 controls
System and Information Integrity
5 controls