Control Atlas
Make federal cybersecurity
make sense.
A free, public research tool that connects the requirements, controls, and guidance published by NIST, DISA, FedRAMP, MITRE, and CISA. Not a government system and not a GRC platform — a place to find what applies to your system and what to do next.
Find what applies · understand it · act on itPress Enter or select Enter the Atlas to start
Make federal cybersecurity make sense.
Controls, STIGs, frameworks, and federal guidance—connected so you can trace where requirements come from, see how they relate, and know what to do next.
40K+ records · 49 source publications
Atlas
See how federal cybersecurity fits together.
Open the Atlas
RMF & ATO · STIGs & SRGs · Zero Trust · 6 more
Library
Browse the Library
Find controls, baselines, assessment procedures, STIGs, threats, and more.
- What you have to doControls & requirementsControls, enhancements, and the requirements that cite them.9,799 records
- What applies to your systemBaselines & profilesBaselines and profiles that set the starting control set.30 records
- How it gets checkedAssessment & processAssessment procedures, RMF steps, and program policy.1,152 records
- How systems get hardenedConfiguration rulesSTIG rules and benchmark checks for real configurations.27,079 records
- What it defends againstThreats & defensesATT&CK techniques and the D3FEND countermeasures that answer them.1,247 records