In NIST SP 800-53 Rev. 5, how are controls grouped into families, and how is an SP 800-53B baseline selected and tailored?
answer
- twenty two-letter families
- base controls plus enhancements
- FIPS 199 then high water mark
- privacy baseline stands apart
- tailor, then document why
basics
~20 sSP 800-53 Rev. 5 groups its controls into 20 families such as AC, AU and SR. A system's FIPS 199 impact levels, combined by the high water mark, pick the Low, Moderate or High baseline in SP 800-53B, which is then tailored and documented.
solid answer
~40 sNIST SP 800-53 Rev. 5 is a consolidated catalog of security and privacy controls in **20 families** identified by two-letter codes (`AC` Access Control, `AU` Audit and Accountability, `SR` Supply Chain Risk Management, and so on). Each family has base controls and **control enhancements** such as `AC-2(1)`. Rev. 5 moved baselines into **SP 800-53B**. You categorize the system under **FIPS 199** for confidentiality, integrity and availability; the **high water mark** of the three picks the **Low, Moderate or High** security baseline. A separate **privacy baseline** applies when the system processes PII. The baseline is a starting point: you **tailor** it - designate common controls, apply scoping, choose compensating controls, set organization-defined parameters, supplement - and document the decisions in the security and privacy plans.
go deeper
Recall that SP 800-53 has 20 families with two-letter IDs and that baselines are Low, Moderate and High.
Explain FIPS 199 categorization, the high water mark, base controls versus enhancements, and why the privacy baseline and PM family sit apart.
Walk through tailoring a Moderate baseline for a real system: inherited common controls, scoping, compensating controls with rationale, and parameter values in the plan.
Weigh when to tailor down versus supplement up, and how shared common controls across many systems cut assessment effort without hiding risk.
## The catalog and its families **NIST SP 800-53 Revision 5** is the control catalog behind US federal information security and privacy programmes, and the catalog that SP 800-171 and cloud authorization baselines are derived from. Rev. 5 made four changes worth naming in an interview: - Controls became more **outcome-based**: the entity responsible ("the information system", "the organization") was removed from control statements. - Security and privacy controls were **integrated into one consolidated catalog**. - A new **Supply Chain Risk Management (SR)** family was established. - **Control selection was separated from the controls**: the baselines now live in a companion publication, **SP 800-53B**. The catalog is organized into **20 families**: | ID | Family | ID | Family | |---|---|---|---| | AC | Access Control | PE | Physical and Environmental Protection | | AT | Awareness and Training | PL | Planning | | AU | Audit and Accountability | PM | Program Management | | CA | Assessment, Authorization, and Monitoring | PS | Personnel Security | | CM | Configuration Management | PT | PII Processing and Transparency | | CP | Contingency Planning | RA | Risk Assessment | | IA | Identification and Authentication | SA | System and Services Acquisition | | IR | Incident Response | SC | System and Communications Protection | | MA | Maintenance | SI | System and Information Integrity | | MP | Media Protection | SR | Supply Chain Risk Management | Within a family, **base controls** carry an ID such as `IA-2` (Identification and Authentication for organizational users), and **control enhancements** add function or strength, written in parentheses: `IA-2(1)` is multi-factor authentication to privileged accounts. ## Selecting a baseline SP 800-53B defines the procedure: 1. **Categorize** the system under **FIPS 199**: rate the potential impact of a loss of confidentiality, integrity and availability as low, moderate or high. 2. Apply the **high water mark** (from FIPS 199, used in FIPS 200): the system's impact level is the highest of the three values. A low-impact system is low on all three; a moderate-impact system has at least one moderate and no high; a high-impact system has at least one high. 3. **Select** the matching **Low, Moderate or High security control baseline** from SP 800-53B's tables. The high water mark exists because the three objectives depend on one another, so controls are grouped by impact level rather than by objective. Examples of how baselines differ: - `IA-2(1)` and `IA-2(2)` (multi-factor authentication to privileged and non-privileged accounts) are in all three baselines. - `SC-28` (Protection of Information at Rest) appears in Moderate and High, not Low. - `CA-2(1)` (Independent Assessors) appears in Moderate and High. Two things sit outside the three security baselines: - The **privacy control baseline** is selected by privacy programmes for systems that process PII, based on their responsibilities under OMB Circular A-130, not on the FIPS 199 impact level. - **Program Management (PM)** controls are organization-wide and independent of FIPS 200 impact levels, so they are not associated with any baseline. ## Tailoring The word **baseline** is intentional: it is a starting point from which controls may be removed, added or specialized. SP 800-53B lists tailoring activities that include: - Identifying and designating **common controls** (inherited from the organization or a provider). - Applying **scoping considerations** (a control may not apply to a given technology or environment). - Selecting **compensating controls** from the catalog, with a rationale for how they give equivalent protection. - Assigning values to **organization-defined parameters** through assignment and selection operations. - **Supplementing** the baseline with additional controls and enhancements. - Providing **specification information** for implementation. Tailoring decisions are risk-based and must be **documented** in the security and privacy plans, so an assessor and the authorizing official can see why the delivered control set differs from the baseline. ## Why this matters beyond federal systems Even outside government, SP 800-53 is the catalog other frameworks map to. SP 800-171 is built by tailoring the Moderate baseline, and cloud authorization programmes build on the same baselines. In an interview, the difference between a middle and a senior answer is usually tailoring: a middle candidate names the baselines, while a senior one explains which controls were inherited, which were scoped out, and where the rationale is written. Knowing the family codes, the high-water-mark rule and what tailoring allows is what lets you read those derived documents quickly.
- A system is rated confidentiality moderate, integrity low, availability low. Which baseline applies?Moderate. Under FIPS 199 and the high water mark used in SP 800-53B, the system's impact level is the highest of the three values, so one moderate objective with no high makes it a moderate-impact system.
- When is the privacy baseline used?When a system processes personally identifiable information. SP 800-53B's privacy baseline is selected by the privacy programme under OMB A-130 and is not tied to the FIPS 199 security impact level; it is tailored using privacy risk assessments.
- Can you drop a baseline control because it is expensive?Only through tailoring that is risk-based and documented - for example scoping it out where it does not apply, or replacing it with a compensating control plus a rationale showing equivalent protection. Silent removal is not tailoring.
saying these in an interview costs you the question
- Averages the three FIPS 199 ratings instead of taking the highest
- Says baselines are still defined inside SP 800-53 Rev. 5
- Treats the privacy baseline as a fourth impact level above High
- Believes tailoring lets you delete controls without documenting a rationale
- Thinks PM controls appear in the Low baseline