The National Institute of Standards and Technology (NIST) is a non-regulatory U.S. Commerce Department agency. 800-53 specifies the Security and Privacy Controls for Federal Information Systems and Organizations. NIST 800-53 is a requirement for federal government agencies that transmit federal information or otherwise handle sensitive agency and citizen data. NIST 800-53 provides a set of controls to architect and manage information security systems for these organizations. While it isn’t a requirement for private-sector businesses and companies, NIST 800-53 compliance provides a valuable framework for information security best practices. Compliance can ensure that the basic principles of data security such as mapping data and permissions, managing access control, and monitoring data, file activity, and user behavior are present in your organization’s security program.