Artifact GuideGLOBALNIST SP 800-53 Rev. 5

NIST SP 800-53 Rev. 5 Baseline Selection Guide

Choose the SP 800-53B security baseline from federal system impact and select privacy controls from privacy risk and applicable requirements, then tailor both for the actual boundary.

The baseline is a starting point. The approved, parameterized, and documented control set is the implementation scope.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

For a federal system, select the low-, moderate-, or high-impact in SP 800-53B after completing the FIPS 199 security categorization. Review the separately because it applies irrespective of impact level and must be tailored from privacy risk and applicable requirements. Other organizations may adopt either baseline as a starting point, but should record the authority and rationale. In every case, the baseline is followed by tailoring, completed parameters, ownership allocation, approval, implementation, and assessment.

Section 1

1. Choose the security baseline from the categorization

FIPS 199 categorizes federal information and systems by the potential impact of losing confidentiality, integrity, and availability. The system's overall security category uses the high-water-mark impact across those objectives. Select the corresponding low-, moderate-, or high-impact security baseline in SP 800-53B before system-specific tailoring.

Preserve the information types, impact rationale, assumptions, boundary, categorization approval, and baseline version. If a contract, agency policy, overlay, or other requirement prescribes a different starting set, record that authority instead of silently substituting it.

  • Identify each information type and potential impact to confidentiality, integrity, and availability.
  • Explain the high-water-mark result and any approved adjustments made under the applicable categorization process.
  • Name the selected SP 800-53B release and preserve the unmodified starting baseline for comparison with the final set.
Section 2

2. Review the privacy baseline separately

SP 800-53B provides one that applies to federal systems irrespective of the FIPS 199 impact level. Select and tailor privacy controls by examining the processing of personally identifiable information, privacy risks to individuals, system design, and applicable laws, regulations, and policies.

Security and privacy can share controls, but the objectives are not interchangeable. Record whether a control addresses security, privacy, or both, which program owns each part, and how the implementation and assessment will cover both objectives.

  • Describe the processing purpose, data, individuals, lifecycle, disclosures, decisions, and privacy risks.
  • List the legal and policy requirements that affect selection or prevent a control from being tailored out.
  • Document privacy-control additions, exclusions, parameter values, ownership, and how residual privacy risk will be decided.
Section 3

3. Tailor the starting baseline without losing traceability

SP 800-53B allows tailoring activities such as identifying common controls, applying scoping considerations, selecting compensating controls, assigning organization-defined parameters, adding controls and enhancements, and specifying implementation details. The process can operate at organization or system level.

Account for every control in the starting baseline. Do not arbitrarily remove controls, and do not tailor out a control that is required by applicable federal law, regulation, or policy. For each change, record the mission and business need, risk analysis, approving role, and resulting control text in the security or privacy plan.

  • Common controls: name the provider, inheriting systems, common and hybrid portions, parameters, dependencies, assessment status, and change-notification process.
  • Compensating controls: show why the baseline control cannot be implemented and how the alternative provides equivalent or comparable protection for the stated requirement and risk.
  • Added controls: link each addition to a threat, requirement, risk, overlay, or assurance need.
  • Parameters and specifications: complete every assignment and selection so implementers and assessors know the required value and scope.
Section 4

4. Preserve the decision record and the final control set

Keep the starting baseline, overlay versions, tailoring log, approvals, and final controls together. The final security and privacy plans should state each selected control and enhancement, completed parameters, implementation level, responsible provider or owner, intended implementation, and inherited dependencies.

Keep baseline-selection evidence separate from later implementation and assessment evidence. A completed tailoring log proves what was selected and why; it does not prove that the control operates effectively.

  • Record: authority, boundary, categorization, privacy risk, baseline release, overlays, assumptions, and selection date.
  • For every starting control: retain, modify, supplement, compensate, or remove with a stated basis and approval.
  • For the final set: record parameters, control text, implementation responsibility, dependencies, evidence expectation, and assessment objective.
  • Set review triggers for changes to impact, processing, threats, technology, requirements, providers, overlays, and risk tolerance.
Section 5

5. Baseline selection workflow

Run security and privacy selection as connected tracks. Categorize federal security impact, assess privacy risk, choose the starting baselines and approved overlays, tailor each control, complete parameters, allocate responsibility, approve the final set, and place it in the security and privacy plans.

NIST issued SP 800-53B Release 5.2.0 on August 27, 2025 for consistency with SP 800-53 and SP 800-53A; NIST states that the release did not change the baselines. Still record the release used so later reviewers can reconcile catalog, baseline, and assessment data.

  • Step 1 | Authority and boundary | Confirm the adopting requirement, system, information, processing, environment, and dependencies.
  • Step 2 | Starting points | Select the security baseline from categorization and review the from privacy risk and requirements.
  • Step 3 | Tailor | Apply overlays, scoping, common-control decisions, compensating controls, additions, parameters, and implementation specifications.
  • Step 4 | Approve | Reconcile every starting control, approve the final set, and publish it in the applicable plans.
  • Step 5 | Maintain | Assess the final controls and revisit selection when the boundary, impact, privacy risk, threat, requirement, or inherited service changes.
Primary sources

References and citations

csrc.nist.gov
Referenced sections
  • Federal standard for categorizing information and systems by the potential impact of loss of confidentiality, integrity, and availability.
doi.org
Referenced sections
  • NIST source for accounting for baseline controls and documenting risk-based tailoring decisions in system security and privacy plans.
Related guides

Explore more topics

How do NIST SP 800-53A assessment methods work?
Use SP 800-53A examine, interview, and test methods against specific determination statements, with documented objects, depth, coverage, and findings.
How do teams select and tailor NIST SP 800-53B baselines?
Start with the applicable SP 800-53B security and privacy baselines, then document categorization, tailoring, parameters, overlays, responsibility, and additions.
How should teams complete NIST control parameters?
Complete every SP 800-53 assignment and selection operation with an approved, scoped, implementable value, then assess the completed control statement.
How should teams document NIST common controls?
Document the common-control provider, inherited capability, parameters, consumer boundary, assessment results, dependencies, and system-specific work.
How should teams document NIST control inheritance?
Verify actual control inheritance by comparing provider scope, completed parameters, assessment results, dependencies, and remaining system-specific work.
NIST SP 800-53 Rev. 5 Applicability Guide
Decide whether NIST SP 800-53 applies, identify the adopting authority and boundary, and document the control, assessment, and authorization path.
NIST SP 800-53 Rev. 5 Control Assessment Evidence Workflow
Plan and document SP 800-53A assessments by mapping determination statements to examine, interview, and test evidence, coverage, findings, and risk decisions.
NIST SP 800-53 Rev. 5 Control Families Explained
Understand all 20 NIST SP 800-53 Rev. 5 control families, how base controls and enhancements work, and how to assign ownership and assessment evidence.
NIST SP 800-53 Rev. 5 Control Tailoring Method
Tailor an NIST SP 800-53B baseline with scoping, common controls, parameters, compensating controls, additions, implementation detail, and documented approvals.
NIST SP 800-53 Rev. 5 Evidence and Audit Readiness Guide
Prepare assessment evidence for NIST SP 800-53A by linking each determination statement to scoped, current, reproducible examine, interview, or test records.
NIST SP 800-53 Rev. 5 FAQ: practical implementation questions
Answers to NIST SP 800-53 Rev. 5 questions on applicability, baselines, tailoring, parameters, enhancements, inheritance, assessments, evidence, and POA&Ms.
NIST SP 800-53 Rev. 5 Overlays and Common Controls Guide
Apply NIST SP 800-53 overlays and document common, hybrid, and inherited controls with clear provider, consumer, assessment, and change responsibilities.
NIST SP 800-53 Rev. 5 POA&M Evidence Guide
Document POA&M source findings, planned remediation, milestones, status evidence, governance decisions, and reassessment-backed closure under NIST SP 800-53 CA-5.
NIST SP 800-53 Rev. 5 POA&M Evidence Workflow
Turn assessed control deficiencies into governed POA&M records with risk, corrective actions, resources, milestones, status evidence, and validated closure.
NIST SP 800-53 Rev. 5 SP 800-53A Assessment Procedures Guide
NIST SP 800-53A gives assessors a methodology and set of procedures for checking whether security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.
NIST SP 800-53 Rev. 5 vs CIS Controls Decision Guide
Decide when to use NIST SP 800-53 Rev. 5 or CIS Controls v8.1, how selection differs, and when control evidence can be reused.
NIST SP 800-53 Rev. 5 vs CIS Controls: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 and CIS Controls v8.1 by scope, selection method, safeguards, assessment evidence, and assurance.
NIST SP 800-53 Rev. 5 vs ISO/IEC 27001: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 with ISO/IEC 27001:2022 by scope, controls, ISMS requirements, evidence, and certification.
NIST SP 800-53 Rev. 5 vs NIST CSF 2.0: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 and CSF 2.0 by scope, controls, outcomes, Profiles, Tiers, evidence, and assurance.
NIST SP 800-53 Rev. 5 vs NIST CSF Decision Guide
Decide when to use NIST SP 800-53 Rev. 5 or CSF 2.0, how controls relate to outcomes, and when evidence can support both.
NIST SP 800-53 Rev. 5 vs NIST SP 800-171 Decision Guide
Decide when to use NIST SP 800-53 Rev. 5 or SP 800-171 Rev. 3, how their scopes differ, and when control evidence can be reused.
NIST SP 800-53 Rev. 5 vs NIST SP 800-171 Rev. 3: practical side-by-side comparison
Compare NIST SP 800-53 Rev. 5 with SP 800-171 Rev. 3 by scope, adopting authority, CUI boundary, requirements, evidence, and assessment.
What evidence should teams collect for NIST SP 800-53A control assessments?
Collect evidence for each SP 800-53A determination statement, using the selected examine, interview, and test methods at the planned depth and coverage.
What should a POA&M item include for NIST SP 800-53 Rev. 5 control gaps?
A useful POA&M item identifies the finding, affected control and system, risk response, owner, milestones, status evidence, dependencies, and closure criteria.
When should teams select NIST control enhancements?
Select a control enhancement only with its base control, document the selection trigger and parameters, implement its added requirement, and assess it separately.