The National Institute of Standards and Technology (NIST) 800-53 security controls are generally applicable to Federal Information Systems. These are typically systems that must go through a formal assessment and authorization process to ensure sufficient protection of confidentiality, integrity, and availability of information and information systems, based on the security category and impact level of the system (low, moderate, or high), and a risk determination.
The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) has been supported by governments and industries worldwide as a recommended baseline for use by any organization, regardless of its sector or size. According to Gartner, the CSF is used by approximately 30 percent of U.S. organizations and projected to reach 50 percent by 2020. Since Fiscal Year 2016, federal agency Federal Information Security Modernization Act (FISMA) metrics have been organized around the CSF and agencies are now required to implement the CSF under the Cybersecurity Executive Order.