Skip to content

NIST SP 800-53

21 rules checking NIST SP 800-53 Rev. 5 compliance, with FIPS baseline applicability. LOW baseline rules apply to all federal systems, MODERATE adds controls for systems processing sensitive information.

Rule IDSeverityNIST ReferenceBaselineCategorySummary
NIST-NET-001CRITICALAC-4MODERATEInformation Flow EnforcementUnrestricted any-to-any information flow
NIST-NET-002CRITICALAC-4MODERATEInformation Flow EnforcementOverly broad source address
NIST-NET-003CRITICALAC-4MODERATEInformation Flow EnforcementOverly broad destination address
NIST-NET-004CRITICALAC-4, CM-7LOWLeast FunctionalityAll ports or wide port range permitted
NIST-NET-005HIGHAC-4, CM-7LOWLeast FunctionalityAll protocols permitted
NIST-NET-020HIGHSC-8, SC-8(1)MODERATEInsecure ServicesUnencrypted protocol detected
NIST-NET-021CRITICALCM-7, SC-8LOWInsecure ServicesDeprecated or broken protocol detected
NIST-NET-023HIGHSC-8, IA-5(1)MODERATEInsecure ServicesInsecure authentication protocol detected
NIST-NET-040CRITICALCM-7, SC-7LOWHigh-Risk Service ExposureHigh-risk port from broad source
NIST-NET-042CRITICALSC-7, CM-7LOWHigh-Risk Service ExposureHigh-risk port from broad/public source
NIST-NET-043CRITICALSC-7, CM-7LOWHigh-Risk Service ExposureDatabase port exposed to external network
NIST-NET-044CRITICALCM-7, SC-7LOWHigh-Risk Service ExposureContainer/orchestration API exposed
NIST-NET-045CRITICALCM-7, SC-7LOWHigh-Risk Service ExposureIPMI/BMC exposed from non-management
NIST-NET-046CRITICALSC-7, AC-4LOWHigh-Risk Service ExposureICS/SCADA protocols crossing boundaries
NIST-NET-050CRITICALAC-17, SC-7LOWRemote Access ControlsDirect remote admin access from external
NIST-NET-052HIGHAC-17, SC-7LOWRemote Access ControlsAdmin protocol from broad source
NIST-NET-061MEDIUMSC-7, CM-7LOWDNS and Covert ChannelsDNS-over-HTTPS to known DoH providers
NIST-NET-062MEDIUMSC-7, SC-7(9)MODERATEDNS and Covert ChannelsDirect external DNS from protected segment
NIST-NET-070INFOAC-4, SI-4LOWEncrypted Tunnel VisibilitySSH tunnelling risk
NIST-NET-071INFOAC-4, SC-7, SI-4LOWEncrypted Tunnel VisibilityVPN tunnel in protected segment
NIST-NET-072INFOSI-4, AC-4LOWEncrypted Tunnel VisibilityOutbound HTTPS inspection blind spot