ComplianceForge News & Announcements

Welcome to ComplianceForge! We want to provide useful information to help you handle your cybersecurity and data protection compliance efforts.

Apply PPTDF For Cybersecurity Compliance

Apply PPTDF For Cybersecurity Compliance

ComplianceForge Support

ComplianceForge Support January 24th, 2024 4 minute read

Compliance

Simplified CMMC Compliance Policies

Simplified CMMC Compliance Policies

ComplianceForge Support

ComplianceForge Support January 22nd, 2024 4 minute read

Chevron Deference and Cybersecurity Compliance

Chevron Deference and Cybersecurity Compliance

ComplianceForge Support

ComplianceForge Support January 19th, 2024 6 minute read

CMMC | Compliance | Governance, Risk & Compliance (GRC)

Cybersecurity Controls Shape Continuous Monitoring

Cybersecurity Controls Shape Continuous Monitoring

ComplianceForge Support

ComplianceForge Support January 16th, 2024 4 minute read

CMMC: Document, Implement & Assess

CMMC: Document, Implement & Assess

ComplianceForge Support

ComplianceForge Support January 9th, 2024 6 minute read

Secure Controls Framework (SCF)

NIST 800-171 & CMMC Terms Guide

NIST 800-171 & CMMC Terms Guide

ComplianceForge Support

ComplianceForge Support August 9th, 2023 1 minute read

CMMC | Compliance

NIST SP 800-53 vs FedRAMP vs SP 800-171: A Clear Guide

NIST SP 800-53 vs FedRAMP vs SP 800-171: A Clear Guide

ComplianceForge Support

ComplianceForge Support June 20th, 2023 2 minute read

Strategy vs Operations vs Tactics

Strategy vs Operations vs Tactics

ComplianceForge Support

ComplianceForge Support June 15th, 2023 14 minute read

Policy vs Standard vs Control vs Procedure

Policy vs Standard vs Control vs Procedure

ComplianceForge Support

ComplianceForge Support June 15th, 2023 14 minute read

NIST SP 800‑53 R5 Control Families

This release includes a total of 1,189 controls, organized into 20 families:

  1. Access Control
  2. Awareness & Training
  3. Audit & Accountability
  4. Assessment, Authorization & Monitoring
  5. Configuration Management
  6. Contingency Planning
  7. Identification & Authentication
  8. Incident Response
  9. Maintenance
  10. Media Protection
  11. Physical & Environmental Protection
  12. Planning
  13. Program Management
  14. Personnel Security
  15. Personally Identifiable Information (PII) Processing & Transparency
  16. Risk Assessment
  17. System & Services Acquisition
  18. System & Communications Protection
  19. System & Information Integrity
  20. Supply Chain Risk Management

This count includes deprecated controls that have been removed or folded into others. Some controls are not categorized under baselines—low, moderate, high, or privacy—per NIST SP 800‑53B.

ComplianceForge provides full 1:1 mapping of all 20 families and their controls in its CDPP documentation.