NIST 800-53 on AWS: AC, AU, SC and more, mapped
A control-family guide for AWS teams working against NIST SP 800-53. Every control below — Access Control, Audit & Accountability, Configuration Management, Contingency Planning, Identification & Authentication, System & Communications Protection, System & Information Integrity — is paired with the exact read-only CloudArq checks that evidence it. This is posture and evidence, not an authorization.
Updated 2026-07-20 · ~11 minute read
Who this is for
Engineering and security teams on AWS who have been handed a NIST 800-53 control set — because you sell to a federal or regulated buyer, because a prime contractor flowed the requirement down, or because your own control framework is built on 800-53. You need to know which controls your AWS configuration already evidences and which it does not, without hand-auditing every account. If you have a GRC team running the full assessment, use this to keep the AWS-technical controls green between reviews.
What NIST 800-53 actually is (one paragraph)
NIST Special Publication 800-53 is a catalog of security and privacy controls published by the U.S. National Institute of Standards and Technology. Controls are grouped into families identified by a two-letter prefix — AC (Access Control), AU (Audit & Accountability), SC (System & Communications Protection), and so on — and each control carries an identifier like AC-2 or SC-28. It is the backbone of FedRAMP and of most U.S. federal authorization work, but it is control-set, not cloud-specific: a control such as “protect information at rest” applies whether the data lives on-prem or in an S3 bucket. This page maps the AWS-technical half of that catalog to concrete, read-only checks.
How CloudArq maps to the control families
CloudArq maps 102 of its automated checks to NIST 800-53 control identifiers across 7 families. The number is the provable per-framework mapped count — the distinct checks that carry an 800-53 control, not the full check registry (most cost, performance, and sustainability checks have no 800-53 control, so they are excluded). It is bound to a single source of truth and drift-guarded against the backend mapping, so the figure on this page can never quietly diverge from what the scanner actually maps.
Each check below describes a capability the read-only audit can surface — a configuration that does not evidence its control — never an observed attack or an asserted violation. When a control fails, CloudArq groups it under its 800-53 identifier and ships a copy-paste CLI or Terraform fix plus the evidence pointer an assessor will ask for.
How CloudArq groups the gaps by control
Illustrative only — sample rows, not a real account. Each failing control ships a copy-paste CLI / Terraform fix and its evidence pointer for the assessor.
What this does — and what it does not do
CloudArq maps 102 checks to the technical controls in the AC, AU, CM, CP, IA, SC, and SI families — encryption, access, logging, monitoring, and backup posture a read-only scanner can read from your AWS configuration.
It does not cover the management, operational, and physical controls — policy, training, media handling, personnel, physical access — that live in people and process, not in AWS configuration. It is not a NIST 800-53 assessment and not an Authorization to Operate. A scanner shows posture; it does not certify, guarantee, or grant an authorization — that is the job of an assessor and an authorizing official. CloudArq the business holds no certifications; the product maps its checks to framework controls so you walk into the assessment with the AWS-technical evidence already in hand.
Frequently asked
- 01Does CloudArq make my AWS environment NIST 800-53 compliant?
- No — and no scanner can. CloudArq maps 102 of its automated checks to the technical controls in seven NIST 800-53 families (AC, AU, CM, CP, IA, SC, SI) and shows you where your AWS configuration does and does not evidence them. That is posture, not compliance: 800-53 compliance is an organizational judgement about the full control set, made by an assessor. CloudArq gives you the AWS-technical evidence and a guided fix for each gap; it does not certify, guarantee, or grant an authorization.
- 02Which NIST 800-53 revision does CloudArq target — Rev 4 or Rev 5?
- CloudArq maps to the technical controls by their control identifier (AC-2, AU-9, SC-28, and so on) rather than to a specific revision, and it does not assert Rev 4 or Rev 5. Those identifiers are stable across revisions for the AWS-infrastructure controls this mapping covers — encryption, access, logging, monitoring, backup — so the mapping stays useful whichever baseline your assessor works from.
- 03Which control families does CloudArq cover, and how deep?
- The mapping spans seven families — Access Control (AC), Audit & Accountability (AU), Configuration Management (CM), Contingency Planning (CP), Identification & Authentication (IA), System & Communications Protection (SC), and System & Information Integrity (SI) — across 17 controls. It covers the AWS-technical controls a scanner can read (MFA, least privilege, encryption at rest and in transit, CloudTrail, GuardDuty, backups, patch state). It does not cover the management, operational, and physical controls — policy, training, media handling, personnel — that live in people and process, not in AWS configuration.
- 04Is CloudArq read-only? Will it change my AWS configuration?
- CloudArq connects through a read-only IAM role secured with an ExternalId. It never stores your credentials, application data, database contents, or S3 objects, and the audit is read-only end to end. Every finding is detection plus a guided fix — a copy-paste CLI or Terraform change you apply yourself. CloudArq never auto-fixes.
- 05Does this replace a NIST 800-53 assessment or an ATO?
- No. An Authorization to Operate is granted by an authorizing official after an assessor evaluates the full control set — including the organizational controls a scanner cannot see. CloudArq is continuous evidence for the AWS-technical slice of that work: it keeps the encryption, access, logging, and monitoring controls green between assessments and shows drift the moment it appears, so you walk into the assessment with the technical posture already documented.
- 06How does NIST 800-53 relate to the other frameworks CloudArq maps?
- The AWS-technical controls overlap heavily. A single encrypted-at-rest finding evidences NIST SC-28, ISO 27001 Annex A.8.24, and SOC 2 CC6.1 at once. CloudArq maps the same read-only audit to eight frameworks, so one scan produces control-mapped evidence for each — see the ISO 27001 and SOC 2 pages for those control breakdowns.