nist_800_53_controls
Retrieve NIST SP 800-53 Rev 5 security and privacy controls by ID, family, or keyword. Returns full details—title, statement, guidance, and enhancements—for FedRAMP, CMMC, and RMF compliance.
Instructions
Look up NIST SP 800-53 Rev 5 security & privacy CONTROLS (keyless) — the requirement backbone for FedRAMP / CMMC / RMF compliance work. Complements cve_lookup + cisa_kev_lookup. Retrieve by controlId (exact, e.g. 'AC-2', 'SC-7', 'AC-2(1)'), family (2-letter 'AC'/'SC'/'IA' or name substring), and/or keyword (case-insensitive substring over title + statement); limit/offset pagination. Each row: { id, family, title, status ('withdrawn'|null), statement (requirement prose; NULL for a WITHDRAWN control, never ''), guidance (discussion), incorporatedInto:[ids that superseded a withdrawn control], enhancements:[{id,title}] }. HONESTY: source is NIST's OFFICIAL OSCAL catalog at github.com/usnistgov/oscal-content (authoritative first-party data served from GitHub, not a .gov API host — provenance disclosed in _meta); the exact OSCAL version + last-modified are surfaced in _meta (catalog fetched live from the MOVING 'main' branch, so control text can shift between point releases — cite the version); a WITHDRAWN control has statement:null and is NOT an active requirement (see incorporatedInto for what replaced it); filtering is CLIENT-SIDE and totalAvailable is the EXACT match count; applicability depends on the system's FIPS-199 impact baseline (Low/Moderate/High), which the catalog does not encode; a download failure or implausibly-truncated catalog (< 15 families) THROWS (never fake-empty).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max controls returned (default 25, max 200). | |
| family | No | Control family — the 2-letter code ('AC', 'SC', 'IA') OR a substring of the family name ('Access Control', 'Audit'). Case-insensitive. | |
| offset | No | Zero-based page offset (default 0). | |
| keyword | No | Case-insensitive substring searched over the control title + requirement statement. | |
| controlId | No | Exact control identifier, e.g. 'AC-2', 'SC-7', 'AC-2(1)' (case-insensitive; zero-padding is normalized). |