Hello BigFix Community,
We are pleased to announce the release of a new compliance checklist within BigFix Compliance, designed to support the NIST Special Publication 800-53 Revision 5 framework.
As organizations work to align their endpoint environments with NIST SP 800-53 Rev 5, we are expanding our compliance library to help you automate and audit technical security controls effectively across your Windows Workstation environment.
What is the NIST 800-53 Rev 5 Compliance Checklist?
The NIST 800-53 Rev 5 Compliance Checklist is a new Checklist designed to assess and enforce compliance against the security and privacy controls defined in NIST 800-53 Revision 5 for Windows Workstations.
This checklist maps technical controls directly to NIST 800-53 Rev 5 control families, allowing you to monitor, enforce, and report on your Windows Workstation security posture against one of the most comprehensive federal security frameworks available.
Technical Snapshot
Here is a quick overview of the coverage provided in this release:
● Total Fixlets: 627
● Fixlets with Remediation: 606
● Parameterized Fixlets: 526
● Framework: NIST SP 800-53 Rev 5
● Applies To: Windows 10 Enterprise, Windows 11 Enterprise
Scope of Coverage
This checklist focuses on the technical controls that can be monitored and enforced via BigFix, mapped to NIST 800-53 Rev 5 control families. We currently support controls across 7 control families:
● Access Control (AC) (Check Count: 128)
○ Device Lock, Session Termination, Account Management, Access Enforcement, Least Privilege, Unsuccessful Logon Attempts
● Audit and Accountability (AU) (Check Count: 71)
○ Audit Record Retention, Audit Record Generation, Event Logging, Content of Audit Records, Audit Log Storage Capacity, Time Stamps
● Configuration Management (CM) (Check Count: 271)
○ Configuration Settings, Least Functionality, System Component Inventory, Software Usage Restrictions
● System and Communications Protection (SC) (Check Count: 143)
○ Information in Shared System Resources, Session Authenticity, Protection of Information at Rest, Boundary Protection, Transmission Confidentiality and Integrity
● Identification and Authentication (IA) (Check Count: 2)
○ Identification and Authentication (Organizational Users), Authenticator Management, Identification and Authentication (Non-Organizational Users)
● Awareness and Training (AT) (Check Count: 2)
○ Policy and Procedures
● System and Information Integrity (SI) (Check Count: 10)
○ Information Management and Retention, Memory Protection, Malicious Code Protection, Spam Protection, System Monitoring
How to Get Started
The NIST 800-53 Rev 5 Checklist for Windows Workstations is available now. To get started, subscribe to the content from the NIST 800-53 Rev 5 Checklist for Windows Workstations external site and deploy it to your desired endpoints.
-
Enable and gather the NIST 800-53 Rev 5 Checklist for Windows Workstations external site from the License Overview Dashboard.
-
Create a custom site using the Create Custom Checks wizard.
-
Change the default parameters if required.
-
If you use custom sites, update them accordingly to use the latest content. You can synchronize your content by using the Synchronize Custom Checks wizard. For more information, see Using the Synchronize Custom Checks wizard.
-
Subscribe all the relevant Windows 10 and Windows 11 Enterprise endpoints.
-
Run SCA import to get the compliance status reports.
More information: To know more about the BigFix Compliance SCM checklists, please see the following resources:
● BigFix Forum: https://forum.bigfix.com/c/release-announcements/compliance
● BigFix Compliance SCM Checklists: https://forum.bigfix.com/c/release-announcements/scm-checklists/86
We are committed to helping you stay compliant with the latest regulatory frameworks. If you have questions regarding specific checks or need assistance with implementation, please feel free to reply to this thread.
– The BigFix Compliance Team