# SL5 Standard for AI Security > The SL5 Standard is an integrated security control profile for frontier AI infrastructure, anchored in NIST SP 800-53 Rev. 5 and extended with NIST SP 800-161 Rev. 1 Update 1 supply-chain controls and ICD 705-derived facility requirements. It targets nation-state-level security by 2028/2029. The profile selects 60 controls across 12 families and is maintained by Security Level 5, a 501(c)(3) research nonprofit. The current release is 0.1.2 (2026-06-23). The standard assumes adversaries are nation-state intelligence services with budgets up to $1B and multi-year operational timelines. It covers five security streams: network isolation, physical protection, machine/accelerator security, personnel vetting, and supply chain risk management. Key concepts: - Weight Enclave: A physically and logically isolated environment where covered AI model weights are stored and processed. All controls assume this boundary. - Covered models: Frontier AI models whose weights require SL5-level protection. - SL5 Network: The broader network encompassing model development, training, and deployment operations. External network connections are prohibited. - OSCAL profile: A machine-readable profile that imports the NIST SP 800-53 Rev. 5 catalog and a published local SP 800-161 Rev. 1 Update 1 catalog containing SR-13. Controls use the format: official NIST control text, SL5 parameter assignments, and SL5 supplemental guidance. SR-13 (Supplier Inventory) originates from NIST SP 800-161 Rev. 1 Update 1; the other selected controls originate from NIST SP 800-53 Rev. 5. ICD 705-derived facility requirements are published as a separate normative section rather than as OSCAL controls. ## Context - [Threat Model](https://standard.sl5.org/threat-model): Nation-state adversaries, protected assets, and attack vectors - [Security Architecture](https://standard.sl5.org/security-architecture): Five security streams and their architectural requirements - [ICD 705 Facility Requirements](https://standard.sl5.org/icd-705): Facility requirements with no direct NIST SP 800-53 equivalent ## Control Families - [Access Control (AC)](https://standard.sl5.org/controls/ac): 7 controls — AC-2 Account Management; AC-2(13) Disable Accounts for High-risk Individuals; AC-3 Access Enforcement; AC-3(2) Dual Authorization; AC-4 Information Flow Enforcement; AC-4(9) Human Reviews; AC-4(15) Detection of Unsanctioned Information - [Configuration Management (CM)](https://standard.sl5.org/controls/cm): 2 controls — CM-7 Least Functionality; CM-7(5) Least Functionality | Authorized Software — Allow-by-exception - [Identification and Authentication (IA)](https://standard.sl5.org/controls/ia): 1 control — IA-3 Device Identification and Authentication - [Incident Response (IR)](https://standard.sl5.org/controls/ir): 1 control — IR-4 Incident Handling - [Physical and Environmental Protection (PE)](https://standard.sl5.org/controls/pe): 6 controls — PE-2 Physical Access Authorizations; PE-2(3) Restrict Unescorted Access; PE-3 Physical Access Control; PE-3(8) Access Control Vestibules; PE-19 Information Leakage; PE-19(1) National Emissions Policies and Procedures - [Program Management (PM)](https://standard.sl5.org/controls/pm): 1 control — PM-12 Insider Threat Program - [Personnel Security (PS)](https://standard.sl5.org/controls/ps): 3 controls — PS-2 Position Risk Designation; PS-3 Personnel Screening; PS-6 Access Agreements - [Risk Assessment (RA)](https://standard.sl5.org/controls/ra): 1 control — RA-3 Risk Assessment - [System and Services Acquisition (SA)](https://standard.sl5.org/controls/sa): 5 controls — SA-4 Acquisition Process; SA-11 Developer Testing and Evaluation; SA-17 Developer Security and Privacy Architecture and Design; SA-20 Customized Development of Critical Components; SA-21 Developer Screening - [Supply Chain Risk Management (SR)](https://standard.sl5.org/controls/sr): 11 controls — SR-3 Supply Chain Controls and Processes; SR-3(1) Diverse Supply Base; SR-3(3) Sub-Tier Flow Down; SR-5 Acquisition Strategies, Tools, and Methods; SR-5(2) Assessments Prior to Selection, Acceptance, Modification, or Update; SR-6 Supplier Assessments and Reviews; SR-9 Tamper Resistance and Detection; SR-9(1) Multiple Stages of System Development Life Cycle; SR-10 Inspection of Systems or Components; SR-11 Component Authenticity; SR-13 Supplier Inventory (SP 800-161 Rev. 1 Update 1) - [System and Communications Protection (SC)](https://standard.sl5.org/controls/sc): 15 controls — SC-7 Boundary Protection; SC-7(10) Prevent Exfiltration; SC-7(21) Isolation of System Components; SC-8 Transmission Confidentiality and Integrity; SC-8(1) Cryptographic Protection; SC-8(5) Protected Distribution System; SC-12 Cryptographic Key Establishment and Management; SC-13 Cryptographic Protection; SC-15 Collaborative Computing Devices and Applications; SC-15(3) Disabling and Removal in Secure Work Areas; SC-28 Protection of Information at Rest; SC-28(3) Cryptographic Keys; SC-29 Heterogeneity; SC-32 System Partitioning; SC-49 Hardware-Enforced Separation and Policy Enforcement - [System and Information Integrity (SI)](https://standard.sl5.org/controls/si): 7 controls — SI-3 Malicious Code Protection; SI-3(10) Malicious Code Analysis; SI-4 System Monitoring; SI-7 Software, Firmware, and Information Integrity; SI-7(9) Verify Boot Process; SI-7(10) Protection of Boot Firmware; SI-7(15) Code Authentication ## Machine-Readable Data - [OSCAL Profile (JSON)](https://standard.sl5.org/sl5-profile.json): Integrated profile importing both published catalogs - [NIST SP 800-161 SR-13 Catalog (JSON)](https://standard.sl5.org/catalogs/NIST_SP-800-161r1-upd1_sr-13_catalog.json): Local OSCAL catalog for the selected SP 800-161 control ## Additional Resources - [Cite the Standard](https://standard.sl5.org/cite): Canonical arXiv record, DOI, and downloadable citation formats - [Licensing and Attribution](https://standard.sl5.org/license): License scope and NIST provenance - [Changelog](https://standard.sl5.org/changelog): Release history and affected controls - [Open Questions](https://standard.sl5.org/open-questions): Areas of genuine uncertainty and active research - [References](https://standard.sl5.org/references): 28 cited standards, publications, and resources - [About](https://standard.sl5.org/about): Security Level 5, authors, acknowledgments, and contribution information