Home/Documentation/Policies & standards
Policies & Standards — NIST SP 800-53 R5 (Moderate)
Family-by-family policies and control-level standards for the moderate baseline, written to satisfy the -1 policy-and-procedure control in each family.
What this set does
Every 800-53 control family opens with a requirement for documented policy and procedures. This set satisfies that requirement for all 20 families at the moderate baseline, with organisation-defined parameters called out in a single workbook so you set them once and they flow through the documents.
What's inside
- Policies for all 20 control families
- Standards for every moderate-baseline control and enhancement
- Organisation-defined parameter (ODP) workbook
- Control inheritance and shared-responsibility template
- Plan of Action and Milestones (POA&M) template
- Mapping workbook: 800-53 R5 to CSF 2.0, ISO 27002 and 800-171 R3
Who it is for
Federal contractors, FedRAMP-adjacent service providers, and organisations whose customers contractually require 800-53 alignment.
How the documents are structured
Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.
Tailoring effort
Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.
Licence
One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.
Related products
Policies & Standards — NIST CSF 2.0
Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.
£445 · 36 documentsProcedures Library
Step-by-step operating procedures that show how each control is actually carried out, who does it, how often, and what record it produces.
£595 · 118 documentsNIST SP 800-171 R3 & CMMC Level 2 Programme
Everything a defence supplier needs to document CUI handling: policies, standards, procedures, System Security Plan and POA&M, aligned to 800-171A assessment objectives.
£1,250 · 62 documents