skip to content

In NIST SP 800-53 Rev. 5, how are controls grouped into families, and how is an SP 800-53B baseline selected and tailored?

level: middleimportance: must knowfreq 50%

answer

  1. twenty two-letter families
  2. base controls plus enhancements
  3. FIPS 199 then high water mark
  4. privacy baseline stands apart
  5. tailor, then document why

basics

~20 s

SP 800-53 Rev. 5 groups its controls into 20 families such as AC, AU and SR. A system's FIPS 199 impact levels, combined by the high water mark, pick the Low, Moderate or High baseline in SP 800-53B, which is then tailored and documented.

solid answer

~40 s

NIST SP 800-53 Rev. 5 is a consolidated catalog of security and privacy controls in **20 families** identified by two-letter codes (`AC` Access Control, `AU` Audit and Accountability, `SR` Supply Chain Risk Management, and so on). Each family has base controls and **control enhancements** such as `AC-2(1)`. Rev. 5 moved baselines into **SP 800-53B**. You categorize the system under **FIPS 199** for confidentiality, integrity and availability; the **high water mark** of the three picks the **Low, Moderate or High** security baseline. A separate **privacy baseline** applies when the system processes PII. The baseline is a starting point: you **tailor** it - designate common controls, apply scoping, choose compensating controls, set organization-defined parameters, supplement - and document the decisions in the security and privacy plans.

go deeper

for a junior

Recall that SP 800-53 has 20 families with two-letter IDs and that baselines are Low, Moderate and High.

for a middle

Explain FIPS 199 categorization, the high water mark, base controls versus enhancements, and why the privacy baseline and PM family sit apart.

for a senior

Walk through tailoring a Moderate baseline for a real system: inherited common controls, scoping, compensating controls with rationale, and parameter values in the plan.

for a principal

Weigh when to tailor down versus supplement up, and how shared common controls across many systems cut assessment effort without hiding risk.

## The catalog and its families **NIST SP 800-53 Revision 5** is the control catalog behind US federal information security and privacy programmes, and the catalog that SP 800-171 and cloud authorization baselines are derived from. Rev. 5 made four changes worth naming in an interview: - Controls became more **outcome-based**: the entity responsible ("the information system", "the organization") was removed from control statements. - Security and privacy controls were **integrated into one consolidated catalog**. - A new **Supply Chain Risk Management (SR)** family was established. - **Control selection was separated from the controls**: the baselines now live in a companion publication, **SP 800-53B**. The catalog is organized into **20 families**: | ID | Family | ID | Family | |---|---|---|---| | AC | Access Control | PE | Physical and Environmental Protection | | AT | Awareness and Training | PL | Planning | | AU | Audit and Accountability | PM | Program Management | | CA | Assessment, Authorization, and Monitoring | PS | Personnel Security | | CM | Configuration Management | PT | PII Processing and Transparency | | CP | Contingency Planning | RA | Risk Assessment | | IA | Identification and Authentication | SA | System and Services Acquisition | | IR | Incident Response | SC | System and Communications Protection | | MA | Maintenance | SI | System and Information Integrity | | MP | Media Protection | SR | Supply Chain Risk Management | Within a family, **base controls** carry an ID such as `IA-2` (Identification and Authentication for organizational users), and **control enhancements** add function or strength, written in parentheses: `IA-2(1)` is multi-factor authentication to privileged accounts. ## Selecting a baseline SP 800-53B defines the procedure: 1. **Categorize** the system under **FIPS 199**: rate the potential impact of a loss of confidentiality, integrity and availability as low, moderate or high. 2. Apply the **high water mark** (from FIPS 199, used in FIPS 200): the system's impact level is the highest of the three values. A low-impact system is low on all three; a moderate-impact system has at least one moderate and no high; a high-impact system has at least one high. 3. **Select** the matching **Low, Moderate or High security control baseline** from SP 800-53B's tables. The high water mark exists because the three objectives depend on one another, so controls are grouped by impact level rather than by objective. Examples of how baselines differ: - `IA-2(1)` and `IA-2(2)` (multi-factor authentication to privileged and non-privileged accounts) are in all three baselines. - `SC-28` (Protection of Information at Rest) appears in Moderate and High, not Low. - `CA-2(1)` (Independent Assessors) appears in Moderate and High. Two things sit outside the three security baselines: - The **privacy control baseline** is selected by privacy programmes for systems that process PII, based on their responsibilities under OMB Circular A-130, not on the FIPS 199 impact level. - **Program Management (PM)** controls are organization-wide and independent of FIPS 200 impact levels, so they are not associated with any baseline. ## Tailoring The word **baseline** is intentional: it is a starting point from which controls may be removed, added or specialized. SP 800-53B lists tailoring activities that include: - Identifying and designating **common controls** (inherited from the organization or a provider). - Applying **scoping considerations** (a control may not apply to a given technology or environment). - Selecting **compensating controls** from the catalog, with a rationale for how they give equivalent protection. - Assigning values to **organization-defined parameters** through assignment and selection operations. - **Supplementing** the baseline with additional controls and enhancements. - Providing **specification information** for implementation. Tailoring decisions are risk-based and must be **documented** in the security and privacy plans, so an assessor and the authorizing official can see why the delivered control set differs from the baseline. ## Why this matters beyond federal systems Even outside government, SP 800-53 is the catalog other frameworks map to. SP 800-171 is built by tailoring the Moderate baseline, and cloud authorization programmes build on the same baselines. In an interview, the difference between a middle and a senior answer is usually tailoring: a middle candidate names the baselines, while a senior one explains which controls were inherited, which were scoped out, and where the rationale is written. Knowing the family codes, the high-water-mark rule and what tailoring allows is what lets you read those derived documents quickly.

  • A system is rated confidentiality moderate, integrity low, availability low. Which baseline applies?
    Moderate. Under FIPS 199 and the high water mark used in SP 800-53B, the system's impact level is the highest of the three values, so one moderate objective with no high makes it a moderate-impact system.
  • When is the privacy baseline used?
    When a system processes personally identifiable information. SP 800-53B's privacy baseline is selected by the privacy programme under OMB A-130 and is not tied to the FIPS 199 security impact level; it is tailored using privacy risk assessments.
  • Can you drop a baseline control because it is expensive?
    Only through tailoring that is risk-based and documented - for example scoping it out where it does not apply, or replacing it with a compensating control plus a rationale showing equivalent protection. Silent removal is not tailoring.

saying these in an interview costs you the question

  • Averages the three FIPS 199 ratings instead of taking the highest
  • Says baselines are still defined inside SP 800-53 Rev. 5
  • Treats the privacy baseline as a fourth impact level above High
  • Believes tailoring lets you delete controls without documenting a rationale
  • Thinks PM controls appear in the Low baseline