{"slug":"nist-800-53","title":"nist-800-53","summary":"Map a cloud system against NIST SP 800-53 Rev. 5 + FedRAMP baselines to produce the documentation an authorization needs — System Security Plan (SSP), Control Implementation Summary (CIS), Plan of Action and Milestones (POA&M), Continuous Monitoring (ConMon) Plan..","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-10-01T15:40:42.080017Z","repo":{"url":"https://github.com/tinh2/skills-hub-registry","stars":18,"forks":6,"license":null,"updatedAt":"2026-09-04T17:22:55Z"},"bodyHtml":"<hr>\n<p>name: nist-800-53\ndescription: \"Map a cloud system against NIST SP 800-53 Rev. 5 + FedRAMP baselines to produce the documentation an authorization needs — System Security Plan (SSP), Control Implementation Summary (CIS), Plan of Action and Milestones (POA&amp;M), Continuous Monitoring (ConMon) Plan..\"\nversion: \"1.0.1\"\ncategory: analysis\nplatforms:</p>\n<ul>\n<li>CLAUDE_CODE</li>\n</ul>\n<hr>\n<h1>NIST 800-53 / FedRAMP Authorization Engine</h1>\n<p>You map a cloud system to NIST SP 800-53 Rev. 5 controls and produce the documentation an authorization needs. FedRAMP demands SSP documentation often over 300 pages, plus CIS, POA&amp;M, and ConMon plan — and 3PAO + PMO will reject anything boilerplate.</p>\n<p><strong>2026 landscape (CR26)</strong>:</p>\n<ul>\n<li><strong>Certification Classes</strong> replace Impact Levels: <strong>A</strong> (Pilot/Ready), <strong>B</strong> (Li-SaaS/Low), <strong>C</strong> (Moderate), <strong>D</strong> (High).</li>\n<li><strong>JAB authorization model is gone</strong> — Agency authorization is the path.</li>\n<li><strong>Monthly ConMon required across all classes</strong> — vulnerability scans, POA&amp;M updates, inventory changes, executive summary.</li>\n<li><strong>Remediation timelines enforced</strong>: 30 days (high), 90 days (moderate), 180 days (low).</li>\n</ul>\n<h1>============================================================\n=== PRE-FLIGHT ===</h1>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <strong>System boundary defined</strong>: what's in scope? Components, data flows, interconnections, customer data, customer responsibility.</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <strong>Certification Class target</strong>: A / B / C / D — drives # of controls (~325 for C, ~421 for D).</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <strong>Underlying CSP</strong>: AWS GovCloud, Azure Government, GCC High, on-prem. Drives inheritable controls (the CSP carries some PE/SC/SI/AC controls).</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <strong>3PAO selected</strong>: required for assessment. Pick from FedRAMP marketplace.</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <strong>Agency sponsor</strong>: required since JAB is gone. Agency PMO sponsors authorization.</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <strong>Existing posture</strong>: SOC 2 Type II completed? StateRAMP? ISO 27001? Substantial uplift if any.</li>\n</ul>\n<p>Recovery:</p>\n<ul>\n<li>If system boundary is ambiguous, force the user to draft a system architecture diagram + data flow diagram before continuing. Without boundary, controls don't have scope.</li>\n<li>For \"FedRAMP Tailored\" / Li-SaaS path: scope is narrower (Class A or B) — 130-160 controls.</li>\n</ul>\n<h1>============================================================\n=== PHASE 1: BOUNDARY + INVENTORY ===</h1>\n<p>Generate <code>system_boundary.md</code> with:</p>\n<ol>\n<li><strong>Authorization Boundary Diagram (ABD)</strong> — every component, interface, external connection.</li>\n<li><strong>Data Flow Diagram (DFD)</strong> — how customer data enters, processes, stores, leaves.</li>\n<li><strong>Inventory</strong> — hosts, containers, databases, queues, secrets stores, identity providers. Linked to a CMDB (Datadog, AWS Config, ServiceNow).</li>\n<li><strong>Interconnections</strong> — every external API, every shared boundary with another system. ICA (Interconnection Security Agreement) required for shared boundaries.</li>\n</ol>\n<p>VALIDATION: Boundary diagram + DFD + inventory all consistent — every box in the ABD appears in the DFD and inventory.</p>\n<h1>============================================================\n=== PHASE 2: CONTROL APPLICABILITY MATRIX ===</h1>\n<p>For your Certification Class, enumerate the applicable controls + enhancements from 800-53 Rev. 5:</p>\n<table>\n<thead>\n<tr>\n<th>Family</th>\n<th>Controls Class C count</th>\n<th>Sample controls</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>AC (Access Control)</td>\n<td>25+</td>\n<td>AC-2, AC-3, AC-4, AC-5, AC-6, AC-7, AC-11, AC-17, AC-22</td>\n</tr>\n<tr>\n<td>AT (Awareness &amp; Training)</td>\n<td>4</td>\n<td>AT-1, AT-2, AT-3, AT-4</td>\n</tr>\n<tr>\n<td>AU (Audit &amp; Accountability)</td>\n<td>14+</td>\n<td>AU-2, AU-3, AU-6, AU-9, AU-12</td>\n</tr>\n<tr>\n<td>CA (Assessment, Authorization)</td>\n<td>9</td>\n<td>CA-2, CA-3, CA-5, CA-7, CA-9</td>\n</tr>\n<tr>\n<td>CM (Configuration Management)</td>\n<td>12</td>\n<td>CM-2, CM-3, CM-6, CM-7, CM-8, CM-10</td>\n</tr>\n<tr>\n<td>CP (Contingency Planning)</td>\n<td>13</td>\n<td>CP-2, CP-3, CP-4, CP-9, CP-10</td>\n</tr>\n<tr>\n<td>IA (Identification &amp; Authentication)</td>\n<td>11</td>\n<td>IA-2 (incl. MFA enhancements), IA-5, IA-8</td>\n</tr>\n<tr>\n<td>IR (Incident Response)</td>\n<td>10</td>\n<td>IR-4, IR-5, IR-6, IR-7, IR-8</td>\n</tr>\n<tr>\n<td>MA (Maintenance)</td>\n<td>6</td>\n<td>MA-2, MA-3, MA-4</td>\n</tr>\n<tr>\n<td>MP (Media Protection)</td>\n<td>8</td>\n<td>MP-2, MP-4, MP-5, MP-6</td>\n</tr>\n<tr>\n<td>PE (Physical &amp; Environmental)</td>\n<td>17</td>\n<td>PE-2, PE-6, PE-12, PE-14 (usually inherited from CSP)</td>\n</tr>\n<tr>\n<td>PL (Planning)</td>\n<td>11</td>\n<td>PL-2, PL-4, PL-8</td>\n</tr>\n<tr>\n<td>PS (Personnel Security)</td>\n<td>9</td>\n<td>PS-3, PS-4, PS-7</td>\n</tr>\n<tr>\n<td>PT (PII Processing &amp; Transparency)</td>\n<td>new in Rev 5</td>\n<td>PT-1, PT-2, PT-3</td>\n</tr>\n<tr>\n<td>RA (Risk Assessment)</td>\n<td>10</td>\n<td>RA-3, RA-5, RA-9</td>\n</tr>\n<tr>\n<td>SA (System &amp; Services Acquisition)</td>\n<td>22</td>\n<td>SA-4, SA-8, SA-11, SA-22</td>\n</tr>\n<tr>\n<td>SC (System &amp; Communications)</td>\n<td>30+</td>\n<td>SC-7, SC-8, SC-12, SC-13, SC-17, SC-23</td>\n</tr>\n<tr>\n<td>SI (System &amp; Information Integrity)</td>\n<td>17</td>\n<td>SI-2, SI-3, SI-4, SI-7, SI-10</td>\n</tr>\n<tr>\n<td>SR (Supply Chain Risk Mgmt)</td>\n<td>new in Rev 5</td>\n<td>SR-3, SR-5, SR-6, SR-11</td>\n</tr>\n<tr>\n<td>PM (Program Management)</td>\n<td>enterprise-level</td>\n<td>PM-1, PM-2, PM-7</td>\n</tr>\n</tbody>\n</table>\n<p>Mark each control as:</p>\n<ul>\n<li><strong>Customer Responsibility</strong> (you implement)</li>\n<li><strong>Provider Responsibility</strong> (CSP — inherited; reference CSP's FedRAMP package)</li>\n<li><strong>Shared</strong> (both — split the implementation)</li>\n<li><strong>Hybrid</strong> (system &amp; customer)</li>\n</ul>\n<p>VALIDATION: Every applicable control assigned an owner.</p>\n<h1>============================================================\n=== PHASE 3: IMPLEMENTATION STATEMENTS (SSP CORE) ===</h1>\n<p>For each Customer Responsibility / Shared / Hybrid control, draft an implementation statement. FedRAMP rejects boilerplate — be specific.</p>\n<p>Template per control:</p>\n<pre><code>### AC-2: Account Management\n\n#### Implementation Status\n\n- [x] Implemented\n- [ ] Partially Implemented\n- [ ] Planned\n- [ ] Alternative Implementation\n- [ ] Not Applicable\n\n#### Implementation Description\n\n{Tenant accounts are managed via {Identity Provider, e.g., AWS IAM Identity Center / Okta}\nwith the following lifecycle:\n\na. Account types: ...\nb. Provisioning: SCIM-based push from HRIS (Workday) on hire.\nc. Authorization workflow: tickets in JIRA Service Management with approval from manager + security.\nd. Deprovisioning: automated on termination event from HRIS within {N} minutes; manual review at {cadence}.\ne. Quarterly access review: documented in Confluence; failed reviews opened as POA&amp;M items.\n\nEvidence:\n\n- Screenshot of Identity Provider console\n- Sample provisioning ticket\n- Sample quarterly review report\n- Automated test in security CI: `tests/AC-2.test.ts`}\n\n#### Customer Responsibility\n\n{If shared/hybrid — explicit statement of what the customer agency must do.}\n\n#### Control Enhancements Implemented\n\n- AC-2(1) Automated System Account Management: ...\n- AC-2(2) Removal of Temporary / Emergency Accounts: ...\n- ...\n</code></pre>\n<p>Generate one per applicable control. Output <code>ssp/controls/{family}-{number}.md</code>.</p>\n<p>VALIDATION: Each implementation statement references SPECIFIC tools, processes, evidence locations. No \"documented elsewhere\" placeholders.</p>\n<h1>============================================================\n=== PHASE 4: POA&amp;M GENERATION ===</h1>\n<p>Plan of Action &amp; Milestones tracks every control NOT fully implemented + every finding from scans / assessments.</p>\n<p>Schema:</p>\n<pre><code>{\n  \"poam_id\": \"POAM-2026-0042\",\n  \"weakness\": \"AC-2(11): Account Use Conditions — circumstances and usage restrictions not documented for service accounts.\",\n  \"control\": \"AC-2(11)\",\n  \"severity\": \"Moderate\",\n  \"discovered_date\": \"2026-05-01\",\n  \"discovered_by\": \"Internal review\",\n  \"current_status\": \"Ongoing\",\n  \"scheduled_completion\": \"2026-08-01\",\n  \"remediation_plan\": \"Document service-account usage conditions in Confluence runbook; automate enforcement via IAM policy.\",\n  \"milestones\": [\n    { \"date\": \"2026-06-01\", \"milestone\": \"Runbook drafted, peer reviewed\" },\n    { \"date\": \"2026-07-01\", \"milestone\": \"IAM policy templates updated\" },\n    {\n      \"date\": \"2026-08-01\",\n      \"milestone\": \"All service accounts compliant; closing POA&amp;M\"\n    }\n  ],\n  \"resources_required\": \"1 FTE-week security engineering\",\n  \"vendor_dependency\": false\n}\n</code></pre>\n<p>Timelines (enforced per FedRAMP):</p>\n<ul>\n<li>High severity: 30 days</li>\n<li>Moderate: 90 days</li>\n<li>Low: 180 days</li>\n</ul>\n<p>VALIDATION: Every POA&amp;M item has milestones + deadline + owner.</p>\n<h1>============================================================\n=== PHASE 5: CONTINUOUS MONITORING (CONMON) PLAN ===</h1>\n<p>Monthly ConMon deliverables required across all classes:</p>\n<ol>\n<li><strong>Vulnerability Scans</strong> — authenticated scans of all in-boundary hosts (Tenable, Qualys, Nessus). Web app scans (OWASP ZAP, Burp Pro). Container scans (Snyk, Aqua). All scan results uploaded to FedRAMP repository.</li>\n<li><strong>POA&amp;M Updates</strong> — status changes, new findings, closures.</li>\n<li><strong>Inventory Changes</strong> — added/removed/changed components.</li>\n<li><strong>Configuration Drift</strong> — compare current state to baselines (CIS, DISA STIGs).</li>\n<li><strong>Executive Summary</strong> — 2-3 page agency-facing summary.</li>\n</ol>\n<p>Generate <code>conmon_plan.md</code> with monthly cadence, tooling, evidence retention rules (1-year minimum per FedRAMP).</p>\n<p>Plus <strong>Annual Assessment</strong> by 3PAO (Class C/D), <strong>Significant Change</strong> notifications.</p>\n<p>VALIDATION: Plan covers all 5 monthly artifacts + annual assessment cadence.</p>\n<h1>============================================================\n=== PHASE 6: 3PAO READINESS ===</h1>\n<p>Pre-assessment checklist before 3PAO engagement:</p>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> SSP complete (Phase 3)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> CIS (Control Implementation Summary) — 1-line per control of who owns what</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> POA&amp;M current</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Recent vulnerability scans (within 30 days)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> ConMon plan documented</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Incident Response Plan tested (tabletop exercise within 12 months)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Contingency Plan tested (DR exercise within 12 months)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Penetration test scheduled with 3PAO (required for Class C/D)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Privacy Impact Assessment (if PII processed)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Supply Chain Risk Management plan (SR family)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> FIPS 140-3 validated crypto modules in use (where required)</li>\n</ul>\n<p>VALIDATION: All checklist items have evidence pointers.</p>\n<h1>============================================================\n=== PHASE 7: PACKAGE &amp; SUBMISSION ===</h1>\n<pre><code>fedramp-package/\n├── README.md\n├── ssp/\n│   ├── core.md                   # exec summary + boundary\n│   ├── controls/                 # one MD per control\n│   └── attachments/\n│       ├── ABD.png\n│       ├── DFD.png\n│       ├── ICA-{partner}.pdf\n│       └── ...\n├── cis/\n│   └── control_implementation_summary.xlsx\n├── poam/\n│   └── poam_2026Q2.xlsx\n├── conmon/\n│   └── conmon_plan.md\n├── policies/                     # 20+ org policies (AC-1, AT-1, AU-1, etc.)\n└── evidence/                     # screenshots, scan results, test outputs\n    └── 2026-05/\n</code></pre>\n<p>Submit to FedRAMP via OMB Max + agency sponsor.</p>\n<p>VALIDATION: Package structure matches FedRAMP template. All required attachments present.</p>\n<h1>============================================================\n=== SELF-REVIEW ===</h1>\n<ul>\n<li><strong>Complete</strong>: Boundary + control matrix + SSP + POA&amp;M + ConMon + 3PAO checklist?</li>\n<li><strong>Robust</strong>: Inheritance correctly mapped to underlying CSP? Class-appropriate control set?</li>\n<li><strong>Clean</strong>: Each implementation statement references specific tools / evidence (no boilerplate)?</li>\n<li><strong>FedRAMP-credible</strong>: Would a 3PAO or PMO reviewer accept the SSP as substantive?</li>\n</ul>\n<p>Common gap: claiming \"implemented\" without evidence pointer. Every control needs traceable evidence.</p>\n<h1>============================================================\n=== LEARNINGS CAPTURE ===</h1>\n<p><code>~/.claude/skills/nist-800-53/LEARNINGS.md</code>.</p>\n<h1>============================================================\n=== STRICT RULES ===</h1>\n<ul>\n<li>Never use boilerplate implementation statements. 3PAO + PMO will reject.</li>\n<li>Never claim an inherited control without referencing the CSP's authorization package + Customer Responsibility Matrix.</li>\n<li>Never miss a ConMon month. Lapses jeopardize authorization.</li>\n<li>Never miss POA&amp;M remediation deadlines (30/90/180 days). Late POA&amp;Ms trigger agency conditional authorization or revocation.</li>\n<li>Always reference CR26 Certification Classes (A/B/C/D), not legacy Low/Mod/High. The labels changed in 2026.</li>\n<li>Always confirm FIPS 140-3 (not 140-2) crypto module validation — 140-2 sunset 2026.</li>\n</ul>\n","files":[{"path":"SKILL.md","sizeBytes":13720,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-10-01T15:44:02.470927Z","sha256":"883A77FF1117C29256542279423458E04F2CBAD0AAFCA2FE0FDA2809D28BBC8D","sizeBytes":5222},"review":null,"source":{"repositoryUrl":"https://github.com/tinh2/skills-hub-registry","path":"analysis/nist-800-53","license":null,"commit":"d38affbf56da216841e2b9e4032a4b978c2062fd","subtreeSha":"6614E2B83EB603D73D66C02A150DCE59557FBD8170B892FD8D8D5E31333D102D","lastSyncedAt":"2026-10-01T15:40:09.634878Z"},"reviewedAt":"2026-10-01T15:50:17.835082Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/tinh2/skills-hub-registry/tree/main/analysis/nist-800-53"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install tinh2-skills-hub-registry@llmmart"},{"target":"git","command":"git clone https://github.com/tinh2/skills-hub-registry.git"}]}