NIST 800-53 Rev 5 Compliance Checklist for Windows Workstations

Hello BigFix Community,

We are pleased to announce the release of a new compliance checklist within BigFix Compliance, designed to support the NIST Special Publication 800-53 Revision 5 framework.

As organizations work to align their endpoint environments with NIST SP 800-53 Rev 5, we are expanding our compliance library to help you automate and audit technical security controls effectively across your Windows Workstation environment.

What is the NIST 800-53 Rev 5 Compliance Checklist?

The NIST 800-53 Rev 5 Compliance Checklist is a new Checklist designed to assess and enforce compliance against the security and privacy controls defined in NIST 800-53 Revision 5 for Windows Workstations.

This checklist maps technical controls directly to NIST 800-53 Rev 5 control families, allowing you to monitor, enforce, and report on your Windows Workstation security posture against one of the most comprehensive federal security frameworks available.

Technical Snapshot

Here is a quick overview of the coverage provided in this release:

Total Fixlets: 627

Fixlets with Remediation: 606

Parameterized Fixlets: 526

Framework: NIST SP 800-53 Rev 5

Applies To: Windows 10 Enterprise, Windows 11 Enterprise

Scope of Coverage

This checklist focuses on the technical controls that can be monitored and enforced via BigFix, mapped to NIST 800-53 Rev 5 control families. We currently support controls across 7 control families:

Access Control (AC) (Check Count: 128)

○ Device Lock, Session Termination, Account Management, Access Enforcement, Least Privilege, Unsuccessful Logon Attempts

Audit and Accountability (AU) (Check Count: 71)

○ Audit Record Retention, Audit Record Generation, Event Logging, Content of Audit Records, Audit Log Storage Capacity, Time Stamps

Configuration Management (CM) (Check Count: 271)

○ Configuration Settings, Least Functionality, System Component Inventory, Software Usage Restrictions

System and Communications Protection (SC) (Check Count: 143)

○ Information in Shared System Resources, Session Authenticity, Protection of Information at Rest, Boundary Protection, Transmission Confidentiality and Integrity

Identification and Authentication (IA) (Check Count: 2)

○ Identification and Authentication (Organizational Users), Authenticator Management, Identification and Authentication (Non-Organizational Users)

Awareness and Training (AT) (Check Count: 2)

○ Policy and Procedures

System and Information Integrity (SI) (Check Count: 10)

○ Information Management and Retention, Memory Protection, Malicious Code Protection, Spam Protection, System Monitoring

How to Get Started

The NIST 800-53 Rev 5 Checklist for Windows Workstations is available now. To get started, subscribe to the content from the NIST 800-53 Rev 5 Checklist for Windows Workstations external site and deploy it to your desired endpoints.

  1. Enable and gather the NIST 800-53 Rev 5 Checklist for Windows Workstations external site from the License Overview Dashboard.

  2. Create a custom site using the Create Custom Checks wizard.

  3. Change the default parameters if required.

  4. If you use custom sites, update them accordingly to use the latest content. You can synchronize your content by using the Synchronize Custom Checks wizard. For more information, see Using the Synchronize Custom Checks wizard.

  5. Subscribe all the relevant Windows 10 and Windows 11 Enterprise endpoints.

  6. Run SCA import to get the compliance status reports.

More information: To know more about the BigFix Compliance SCM checklists, please see the following resources:

● BigFix Forum: https://forum.bigfix.com/c/release-announcements/compliance

● BigFix Compliance SCM Checklists: https://forum.bigfix.com/c/release-announcements/scm-checklists/86

We are committed to helping you stay compliant with the latest regulatory frameworks. If you have questions regarding specific checks or need assistance with implementation, please feel free to reply to this thread.

– The BigFix Compliance Team