Compliance · NIST SP 800-53 Rev. 5

NIST 800-53for agentic AI

The NIST SP 800-53 Rev. 5 controls that agent adoption touches, each mapped to the Speakeasy AI Control Plane capability that implements it.

14

Rev. 5 controls mapped

The controls agent adoption touches, from access control through supply chain risk.

7

Control families covered

From access control (AC) to supply chain risk management (SR).

170+

Audit event types

Captured with per-call attribution and SIEM export, evidencing the mapped controls.


01 · The mapping

Rev. 5, control by control

Ids and titles follow the SP 800-53 Rev. 5 catalog. The capability column carries the same copy as the ISO 27001 mapping.

ISO 27001SOC 2NIST 800-53

AC

Access control

AC-2Account management

Registers agents and enrolls devices against named users before credentials are issued, and revokes sessions, consents, and keys when authorization ends.

AC-3Access enforcement

Issues every agent a revocable identity with scoped keys, and authorizes every tool call against toolset grants at the moment the agent acts.

AC-4Information flow enforcement

Blocks secrets and PII from crossing the tool-call boundary with risk policies, storing detected values masked.

AC-6Least privilege

Scopes access through roles and per-toolset grants separated by environment, with every grant change recorded as an audit event.

AU

Audit and accountability

AU-2Event logging

Captures more than 170 audit event types and redacted tool-call logs, with per-call attribution and SIEM export.

CM

Configuration management

CM-2Baseline configuration

Freezes tool lists to the approved deployment snapshot, so upstream changes cannot inject new capabilities, only downgrade to a subset or trigger an approval chain.

CM-3Configuration change control

Runs configuration changes through append-only deployments and approval workflows, with before-and-after snapshots on every state-changing update.

CM-8System component inventory

Maintains a live register of agents, tools, MCP servers, and owners as a side effect of use.

CM-11User-installed software

Discovers unsanctioned MCP servers from live traffic and enforces the approved disposition at the hook boundary inside coding agents.

IR

Incident response

IR-4Incident handling

Contains a compromised agent through session revocation, policy flips to block, audit snapshots, session transcripts, and deployment rollback lineage.

SC

System and communications protection

SC-7Boundary protection

Routes agent traffic through governed MCP endpoints and constrains egress to deployment-defined destinations.

SI

System and information integrity

SI-4System monitoring

Scans prompts and tool calls with Watchdog, scores findings by severity, and blocks spend past budget limits.

SI-12Information management and retention

Revokes sessions, consents, keys, and grants when an agent is decommissioned, with retention TTLs of 90, 400, and 730 days enforced automatically.

SR

Supply chain risk management

SR-6Supplier assessments and reviews

Records every MCP server as a supplier, with registry provenance, package metadata, and capability scoring for procurement review.

02 · Certification

Certified and audited

The control plane meets the standards it helps you enforce. Audit reports and compliance documentation are available through the trust center.

Visit trust center

AI everywhere.

Control here.