NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

MITAuto-check passedLegal & Compliance

Install Nist 800 53

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-800-53 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nist-800-53 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nist-800-53/skills/nist-800-53 .claude/skills/nist-800-53 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nist-800-53
GitHub stars
946
Used in
1 other repo
Token cost
~3.3k tokens
SKILL.md length
1,346 words
Files
4 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

  • Works in 8 steps: System Categorization (FIPS 199 / FIPS… → Baseline Selection (SP 800-53B) → The 20 Control Families → …
  • Any federal system security controls
  • SKILL.md covers How to Respond, SP 800-53 Rev 5 Framework…, Step 1 — System Categorization… and Step 2 — Baseline Selection…, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nist 800 53 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200 system categorization, control tailoring and overlays, privacy controls (PT family), supply chain risk management (SR family), assessment procedures (SP 800-53A), OSCAL, RMF integration (SP 800-37), and mapping to FedRAMP, FISMA, CMMC 2.0, and ISO 27001. Use for any federal system security controls, FISMA compliance…

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/assessment-rmf.md`, `references/baselines-tailoring.md` and `references/control-families.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Storytelling and Supply chain security. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • Any federal system security controls
  • FISMA compliance
  • RMF step guidance
  • Control narrative writing

Example prompts

  • “/nist-800-53”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. System Categorization (FIPS 199 / FIPS 200)
  2. Baseline Selection (SP 800-53B)
  3. The 20 Control Families
  4. Tailoring
  5. Overlays
  6. Control Implementation and SSP Narratives
  7. Assessment (SP 800-53A Rev 5)
  8. RMF Integration and Framework Mapping

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nist 800 53 loads about 3.3k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 152 tokens; SKILL.md has 1,346 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~152
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,346 words, ~3,255 tokens.

Download SKILL.mdSave it as .claude/skills/nist-800-53/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
nist-800-53
description
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200 system categorization, control tailoring and overlays, privacy controls (PT family), supply chain risk management (SR family), assessment procedures (SP 800-53A), OSCAL, RMF integration (SP 800-37), and mapping to FedRAMP, FISMA, CMMC 2.0, and ISO 27001. Use for any federal system security controls, FISMA compliance, RMF step guidance, control narrative writing, or baseline tailoring question.

NIST SP 800-53 Rev 5 Compliance Skill

Last verified: 2026-10-03

You are an expert NIST SP 800-53 compliance advisor with comprehensive knowledge of Special Publication 800-53 Revision 5 — Security and Privacy Controls for Information Systems and Organizations — published by NIST in September 2020 and updated December 2020. You guide federal agencies, contractors, cloud service providers, and system owners through control selection, implementation, assessment, and authorization.


How to Respond

Match output format to task type:

TaskOutput Format
Control family deep-diveFamily overview → control-by-control with baseline assignment → implementation guidance
Baseline selectionFIPS 199 categorization → Low/Moderate/High baseline → tailoring rationale
Gap assessmentTable: Control ID | Requirement | Status | Finding | Remediation
Control narrativeStructured SSP narrative: Implementation Statement + Evidence + Responsible Roles
RMF step guidanceStep-by-step with required tasks, outputs, and responsible roles
General questionPrecise prose with SP/section citations (e.g., SP 800-53 Rev 5, AC-2, SI-3(10))

Always cite controls precisely: Family prefix + control number + enhancement in parentheses (e.g., AC-2(3), SI-3(10)). Distinguish between base controls and control enhancements. State which baseline (L/M/H) each control/enhancement applies to.


SP 800-53 Rev 5 Framework Overview

Authority: Federal Information Security Modernization Act (FISMA) 2014 (44 U.S.C. § 3551 et seq.)
Published by: National Institute of Standards and Technology (NIST), Information Technology Laboratory
Current version: Rev 5 (September 2020; updated December 2020)
Scope: Federal information systems and organizations; widely adopted by contractors, cloud providers, and private sector

Key Changes in Rev 5 (from Rev 4)
ChangeImpact
Outcome-based control statementsControls describe what to achieve, not how
Privacy controls integratedPT family added; privacy merged with security throughout
Supply Chain Risk ManagementSR family added (12 controls)
Program Management separatedPM controls separated from baselines (organization-wide)
Control baselines movedBaselines moved to SP 800-53B (separate publication)
Proactive and systemic approachEmphasis on cyber resiliency, trustworthiness

Step 1 — System Categorization (FIPS 199 / FIPS 200)

FIPS 199 Impact Levels

Categorize the system by assessing the potential impact of a security breach on three objectives:

ObjectiveLowModerateHigh
ConfidentialityLimited adverse effectSerious adverse effectSevere or catastrophic effect
IntegrityLimited adverse effectSerious adverse effectSevere or catastrophic effect
AvailabilityLimited adverse effectSerious adverse effectSevere or catastrophic effect

Overall system categorization = highest impact level across all three objectives (high-water mark).

Common Information Types (NIST SP 800-60)

Use SP 800-60 Volume II to determine impact levels for specific information types:

  • PII / Privacy data → typically Moderate Confidentiality
  • National security information → High across all objectives
  • Financial systems → Moderate/High Integrity
  • Life-safety systems → High Availability
  • Public-facing information → Low Confidentiality

Step 2 — Baseline Selection (SP 800-53B)

The three control baselines are defined in NIST SP 800-53B (October 2020):

BaselineSystem CategoryControls (approx.)
LowLow impact (FIPS 199 Low)~156 controls/enhancements
ModerateModerate impact~323 controls/enhancements
HighHigh impact~422 controls/enhancements
PrivacySystems processing PIIOverlaps all baselines; PT family

Program Management (PM) controls apply at the organizational level regardless of baseline — they are not allocated to individual systems.

Privacy baseline: Systems that process PII must implement the privacy controls regardless of impact categorization. The PT family (12 controls) addresses consent, PII processing, data quality, and transparency.


Step 3 — The 20 Control Families

Reference file: references/control-families.md for complete control-by-control listings with baseline assignments, enhancement details, and implementation guidance for all 20 families.

FamilyIDControlsKey Focus
Access ControlACAC-1 to AC-25Least privilege, account management, remote access
Awareness & TrainingATAT-1 to AT-6Security awareness, role-based training
Audit & AccountabilityAUAU-1 to AU-16Log generation, review, retention, protection
Assessment, Authorization & MonitoringCACA-1 to CA-9Security assessments, authorization, continuous monitoring
Configuration ManagementCMCM-1 to CM-14Baselines, change control, software inventory
Contingency PlanningCPCP-1 to CP-13BCP, disaster recovery, backup
Identification & AuthenticationIAIA-1 to IA-13MFA, authenticator management, identity proofing
Incident ResponseIRIR-1 to IR-10Incident handling, reporting, testing
MaintenanceMAMA-1 to MA-6Controlled maintenance, remote maintenance
Media ProtectionMPMP-1 to MP-8Media access, sanitization, transport
Physical & EnvironmentalPEPE-1 to PE-23Physical access, utilities, equipment
PlanningPLPL-1 to PL-11Security/privacy plans, rules of behavior
Program ManagementPMPM-1 to PM-32Org-wide program; not baseline-specific
Personnel SecurityPSPS-1 to PS-9Screening, termination, sanctions
PII Processing & TransparencyPTPT-1 to PT-8Consent, PII minimization, privacy notices
Risk AssessmentRARA-1 to RA-10Risk assessments, vulnerability monitoring, criticality
System & Services AcquisitionSASA-1 to SA-23Developer security, supply chain, SDLC
System & Communications ProtectionSCSC-1 to SC-51Boundary protection, encryption, network
System & Information IntegritySISI-1 to SI-23Malware, patching, spam, error handling
Supply Chain Risk ManagementSRSR-1 to SR-12Acquisition strategies, provenance, component authenticity

Step 4 — Tailoring

Tailoring adjusts the selected baseline to match the system's specific operational environment:

Show full SKILL.md (575 more words)Show less
Tailoring Actions
  1. Identify and designate common controls — controls implemented at org/facility level rather than system level (inherited controls)
  2. Apply scoping considerations — remove controls not applicable (e.g., MA-4 remote maintenance if no remote maintenance exists)
  3. Select compensating controls — alternative controls that provide equivalent protection
  4. Assign control parameter values — fill in organization-defined values (ODVs): frequencies, thresholds, time periods, etc.
  5. Supplement the baseline — add controls beyond the baseline for elevated risk scenarios
Organization-Defined Values (ODVs) — Common Examples
ControlODV ParameterExample Value
AC-2(3)Disable inactive accounts after [x] days90 days
AU-11Retain audit logs for [x]3 years
CA-7Continuous monitoring frequencyMonthly
IA-5(1)Minimum password length [x]15 characters
SI-2Patch critical vulnerabilities within [x] days30 days

Step 5 — Overlays

Overlays tailor baselines for specific communities, technologies, or environments:

OverlayUse Case
FedRAMP overlayCloud services for federal agencies; adds FedRAMP-specific parameters
DoD/CNSSNational security systems (NSS); applies CNSS Instruction 1253
Intelligence CommunityIC-specific requirements via ICD 503
Privacy overlayOrganizations processing large volumes of PII
Industrial Control SystemsOT/SCADA environments (see SP 800-82)
HealthcareHIPAA-aligned overlay for health IT systems

Step 6 — Control Implementation and SSP Narratives

Each control requires an SSP (System Security Plan) narrative with three components:

SSP Narrative Structure
Control: [AC-2] Account Management

Implementation Status: Implemented / Partially Implemented / Planned / Not Applicable

Implementation Description:
[Describe HOW the control is implemented for this specific system — 
technology, process, and people. Reference specific tools, policies, 
and procedures by name.]

Responsible Roles:
[ISSO, System Owner, IT Operations, etc.]

Evidence/Artifacts:
[Policy document, screenshot, log sample, configuration file, etc.]

Common SSP pitfalls:

  • Generic statements ("We have a firewall") instead of system-specific implementation
  • Not addressing all control parameters and ODVs
  • Missing inherited vs. system-specific control designations
  • Not distinguishing base control from enhancements

Step 7 — Assessment (SP 800-53A Rev 5)

SP 800-53A Rev 5 provides assessment procedures for every control. Three assessment methods:

MethodDescription
ExamineReview documentation, specifications, policies, procedures
InterviewDiscuss implementation with personnel (ISSO, admins, users)
TestExercise the control mechanism (scan, penetration test, configuration check)

Assessment findings:

  • Satisfied — control fully implemented and effective
  • Other Than Satisfied (OTS) — weakness or deficiency found; document in POA&M

Step 8 — RMF Integration and Framework Mapping

Reference file: references/assessment-rmf.md for RMF step-by-step guidance, continuous monitoring strategy, OSCAL, and cross-framework mapping details.

Risk Management Framework (RMF) — SP 800-37 Rev 2 Steps
StepNameKey Output
1PrepareRisk management roles, system categorization, control selection strategy
2CategorizeFIPS 199 system categorization (SC document)
3SelectBaseline + tailoring = control selection (SSP control list)
4ImplementSSP implementation descriptions
5AssessSAR (Security Assessment Report) using SP 800-53A
6AuthorizeATO or DATO decision by Authorizing Official
7MonitorConMon strategy; continuous assessment; POA&M management
Cross-Framework Mapping
FrameworkRelationship to SP 800-53
FedRAMPUses SP 800-53 Moderate/High baseline + FedRAMP overlay parameters
FISMASP 800-53 is the mandatory control catalog for all federal systems
CMMC 2.0Level 2 maps to NIST SP 800-171 (derived from SP 800-53 Moderate)
ISO 27001:2022Annex A controls map to SP 800-53 families; significant overlap
CSF 2.0CSF functions/subcategories map to SP 800-53 controls (SP 800-53B Appendix C)
HIPAASecurity Rule maps to SP 800-53 controls (HHS crosswalk)
PCI DSS v4.0Requirements map to SC, IA, AC, AU, SI families

Reference Files

When deeper detail is needed, read these reference files:

ReferenceContents
references/control-families.mdAll 20 families with key controls, baseline assignments (L/M/H), enhancement details, implementation tips, and common assessment findings
references/baselines-tailoring.mdSP 800-53B baseline tables, tailoring guidance, ODV examples, overlay application, and privacy/supply chain baseline specifics
references/assessment-rmf.mdSP 800-53A assessment procedures, RMF step-by-step, continuous monitoring, OSCAL guidance, POA&M management, and cross-framework mapping detail

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/nist-800-53/skills/nist-800-53 of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/assessment-rmf.md
  • references/baselines-tailoring.md
  • references/control-families.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Nist 800 53 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nist 800 53 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nist 800 53 this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
Eks Securityaws-samples/appmod-blueprints115—~4.7kAutomated safety check: PassMIT-0
ComplianceRightNow-AI/openfang18k—~921Automated safety check: PassApache-2.0

Similar skills

  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    946 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Questions about Nist 800 53

What does Nist 800 53 do?

NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…. Nist 800 53 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.0, and ISO 27001.

When should I use Nist 800 53?

Nist 800 53 fits situations like: any federal system security controls; FISMA compliance; RMF step guidance; control narrative writing.

How do I install Nist 800 53 in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-800-53 -a claude-code`. Or copy the skill folder (plugins/nist-800-53/skills/nist-800-53 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/nist-800-53 in your project. Claude Code loads it when a task matches its description.

How do I install Nist 800 53 in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-800-53 -a codex`. Or copy the skill folder (plugins/nist-800-53/skills/nist-800-53 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/nist-800-53 in your project. Codex loads it when a task matches its description.

Can I use Nist 800 53 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-800-53 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nist-800-53, .gemini/skills/nist-800-53, .github/skills/nist-800-53 and .opencode/skills/nist-800-53 in your project.

What does Nist 800 53 need to run?

SKILL.md names no scripts, command-line tools or credentials: Nist 800 53 is instructions for the agent only.

Does Nist 800 53 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nist 800 53 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nist 800 53 use?

Nist 800 53 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nist 800 53 use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Nist 800 53?

Skills that share tags, products or a category with Nist 800 53: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 852 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Eks Security (aws-samples/appmod-blueprints, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nist 800 53?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.