OSA's control catalogue now follows NIST SP 800-53 Release 5.2.0 control for control, and it carries the control enhancements too. All 300 controls read as NIST publishes them, and each one lists its enhancements, 714 in all, with the baselines that include them. The catalogue is generated from NIST's own files, so it stays in step.
Why it matters
If you quote a control in a design document or an audit response, the wording should be NIST's wording as it stands today. SP 800-53 has kept moving since Revision 5 came out in 2020, with later releases adding controls and revising the text of others.
A lot of what matters in practice also sits one level below the control, in its enhancements. NIST's baselines are built from them. The moderate baseline has 287 entries and 110 of them are enhancements. For the high baseline it's 182 of 370, close to half. Account management shows how this plays out: the moderate baseline doesn't stop at AC-2, it also asks for automated account management and for accounts to be disabled when they expire, and both of those are enhancements.
You can now see all of that on OSA, next to the patterns and framework mappings that build on it.
What's new
- Every current control carries NIST's title, statement, discussion and related controls from Release 5.2.0.
- Each control page lists the control's enhancements. Open one to read its statement and see which baselines include it.
- All four of NIST's baselines are shown: low, moderate, high and privacy.
- The two newest controls are in the catalogue: IA-13, Identity Providers and Authorization Servers, and SA-24, Design for Cyber Resiliency.
- Withdrawn controls that our older patterns refer to are kept, clearly marked, with links to the controls that took over their content. A reference to SC-9 in an older document leads you to SC-8.
- For agents, the control card names every enhancement with its baselines, and one API call returns their statements. The API description now has a version number and a change list.
Built from NIST's files
NIST publishes the catalogue in more than one form. We build ours from two of them, the CPRT export and the OSCAL files, and compare them as we go. They agree on the baselines of every control and enhancement.
From there a script writes NIST's wording into each control page, into the catalogue index and into the control names inside our patterns, more than 1,600 of them. Every build checks that those copies still match the source, and after the change we checked every control card on the live site against it as well. When NIST publishes its next release, we point the build at the new files.
Still light for agents
The work we did for agents carries over. A control's card is about 3 KB at the median with its enhancements named, so an agent reads the control, its enhancements and its framework clauses in one small request. The enhancement statements are one API call further on, and an agent only pays for them when the question needs them.
What stays OSA's
None of this changes what OSA adds. The patterns, the emphasis each pattern gives a control, the threats a control mitigates and the mappings to 88 compliance frameworks all sit on top of NIST's text, as they did before. Framework mappings stay at control level, so a clause still maps to AC-2 and not to one of its enhancements.
Try it
Pick a control you know well, AC-2 for instance, and open its enhancements. If you build agents, the same content is in the control card and the API. If you find wording that differs from NIST's, please raise an issue and we'll correct it at the source. Everything remains free under CC BY-SA 4.0.
Russell Wing, co-founder, Open Security Architecture