How should teams choose a NIST SP 800-53 baseline?
Record the authorization boundary, information types, categorization result, privacy risk assessment, applicable requirements, selected security and privacy baselines, overlays, tailoring actions, added controls or enhancements, completed parameters, implementation approach, approvers, and resulting risk decisions.
Do not choose low, moderate, or high from organization size, budget, or a desired label. Under FIPS 199, categorize the potential impact of losing confidentiality, integrity, and availability for each information type and the system, then use the resulting system impact level to select the initial . Low means limited adverse effect, moderate means serious adverse effect, and high means severe or catastrophic adverse effect. The applies irrespective of that impact level, and the organization tailors it to privacy processing, risk, and obligations.
- Confirm the system boundary and security categorization before selecting the low-, moderate-, or high-impact security baseline.
- Apply the privacy baseline separately and tailor it using privacy risk and applicable privacy requirements.
- Use an applicable as an additional tailoring aid, not as an unexplained replacement for the underlying baseline.
- Preserve the original baseline and a traceable record of every tailoring, supplementation, parameter, and implementation-responsibility decision.
- Revisit selection after material categorization, privacy risk, requirement, boundary, mission, threat, technology, or common-control changes.
Explains control selection, organization-defined parameters, implementation approaches, and the role of SP 800-53B in federal baseline selection.
Explains that assessment evaluates selected controls and completed control statements; it does not create the initial baseline.
Primary source for the three federal security baselines, the privacy baseline, tailoring guidance, working assumptions, and overlays.
Defines low, moderate, and high potential impact and the federal security categorization used to select the initial security baseline.