Where should teams record the inheritance decision under NIST SP 800-53 Rev. 5?
Record the implementation approach in the system security plan or privacy plan and reference the common-control provider's implementation description and evidence. State whether the system inherits all or only part of the completed control statement.
If the provider supplies only part of the capability, treat it as a and document who implements, assesses, monitors, and remediates each portion. The system owner still determines whether the inherited protection and its dependencies address system-specific risk and requirements. NIST's CP-2 example uses a common contingency-plan template while system owners tailor the plan for their own systems; the template is common, but the system-specific plan content remains local work.
- Document each inherited control or portion in the system security plan or privacy plan with a reference to the provider.
- Compare the provider's completed control text, enhancements, parameters, implementation scope, dependencies, assessment coverage, findings, and date with the receiving system's needs.
- Treat the control as inherited only when another entity supplies the protection and the system actually uses it; treat locally supplied protection as system-specific.
- For hybrid controls, assign and assess the remaining system-specific work rather than presenting the whole control as inherited.
- Revisit the decision after changes to the provider, control, parameters, system boundary, service, assessment results, or operating environment.
Section 2.3 defines inheritable common controls and hybrid controls, assigns responsibility for each portion, and requires parameter compatibility to be examined.
Section 3.2.3 explains how a system assessment verifies inheritance and uses provider results while assessing system-specific hybrid portions.
RMF guidance for identifying common controls and recording inheritance in system authorization documentation.