NIST SP 800-53 controls, mapped to STIG rules
Each control below lists the Control Correlation Identifiers that map to it and the DISA STIG rules that implement those CCIs. Built from the same data as our STIG mapper and served by the compliance API.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
| Control | Title | Family | CCIs | STIG rules |
|---|---|---|---|---|
| CM-6 | Configuration Settings | Configuration Management | 26 | 525 |
| AU-12 | Audit Record Generation | Audit and Accountability | 18 | 270 |
| CM-7 | Least Functionality | Configuration Management | 40 | 234 |
| AC-6 | Least Privilege | Access Control | 25 | 184 |
| IA-5 | Authenticator Management | Identification and Authentication | 101 | 113 |
| AC-3 | Access Enforcement | Access Control | 65 | 92 |
| MA-4 | Nonlocal Maintenance | Maintenance | 27 | 76 |
| AU-3 | Content of Audit Records | Audit and Accountability | 14 | 76 |
| AC-17 | Remote Access | Access Control | 25 | 55 |
| SC-8 | Transmission Confidentiality and Integrity | System and Communications Protection | 11 | 44 |
| CM-5 | Access Restrictions for Change | Configuration Management | 35 | 41 |
| AU-9 | Protection of Audit Information | Audit and Accountability | 21 | 41 |
| AC-7 | Unsuccessful Logon Attempts | Access Control | 16 | 40 |
| IA-2 | Identification and Authentication (Organizational Users) | Identification and Authentication | 33 | 39 |
| AC-2 | Account Management | Access Control | 93 | 37 |
| SC-3 | Security Function Isolation | System and Communications Protection | 6 | 37 |
| IA-11 | Re-authentication | Identification and Authentication | 4 | 37 |
| AU-4 | Audit Log Storage Capacity | Audit and Accountability | 4 | 34 |
| SC-4 | Information in Shared System Resources | System and Communications Protection | 3 | 28 |
| SC-23 | Session Authenticity | System and Communications Protection | 7 | 27 |
Of the 307 controls carrying a CCI mapping in this data, 60 have at least one STIG rule behind them in these benchmarks. We publish a page only where there is enough underlying data to be worth reading; the rest are served by the API.