What are NIST SP 800-53B security and privacy control baselines?
NIST SP 800-53B defines security and privacy control baselines as pre-defined sets of controls that address common protection needs across information systems. Specifically, organizations use these baselines as a starting point for control selection. Moreover, the baseline they choose depends directly on the potential impact of losing confidentiality, integrity, or availability of their systems. In fact, this impact-driven approach is what makes NIST SP 800-53B practical rather than prescriptive.
In practice, NIST SP 800-53B provides three baselines aligned with the impact levels that FIPS 200 defines: low, moderate, and high. Furthermore, it introduces the concept of control overlays, which complement baselines for specific technologies, communities of interest, or unique operational environments.
How do you choose the right NIST SP 800-53B control baseline?
The system’s impact level determines which baseline applies. Specifically, FIPS 200 defines three impact levels based on the consequences of a loss of confidentiality, integrity, or availability. Moreover, organizations must make this determination before selecting any controls, because the baseline drives every downstream decision about control selection and tailoring.
In practice, the three levels work as follows:
- Low-impact systems: a loss of confidentiality, integrity, or availability would have a limited adverse effect on operations, assets, or individuals
- Moderate-impact systems: a loss would have a serious adverse effect, causing significant degradation of mission capability
- High-impact systems: a loss would have a severe or catastrophic adverse effect, potentially resulting in loss of life or major financial damage
Can organizations modify a NIST SP 800-53B control baseline?
Yes. Organizations can tailor any control baseline to better suit their specific security and privacy needs. Specifically, NIST SP 800-53B supports a risk-based tailoring process that gives organizations flexibility without abandoning the structure the baseline provides. Moreover, tailoring does not mean weakening controls. Instead, it means adapting them to the actual operational environment.
In practice, the tailoring process involves six actions:
- Identifying and designating common controls that apply across multiple systems
- Applying scoping considerations to remove controls that do not apply to the system’s environment
- Selecting compensating controls when organizations remove a baseline control and need to manage the residual risk
- Assigning values to organization-defined control parameters to make controls specific and actionable
- Supplementing baselines with additional controls to address risks that the baseline does not fully cover
- Documenting specific implementation details so everyone understands how each control operates in practice
What are control overlays and how do they relate to NIST SP 800-53B baselines?
Control overlays are specifications that complement and further refine security control baselines. Specifically, they provide tailored sets of controls for particular communities of interest, technologies, or unique operational environments. Moreover, overlays work on top of baselines rather than replacing them. As a result, organizations can apply both a baseline and one or more overlays simultaneously to address all their requirements.
In practice, overlays connect directly to the concept of capabilities. A capability represents a desired security outcome that multiple, mutually reinforcing controls achieve together. For example, secure remote authentication combines controls IA-2(1), IA-2(2), IA-2(8), IA-2(9), and SC-8(1) into a single coherent protection outcome. Therefore, thinking in terms of capabilities helps organizations select controls that reinforce each other rather than address requirements in isolation.
What is the high water mark concept in NIST SP 800-53B?
The high water mark concept reflects the interdependency between confidentiality, integrity, and availability. Specifically, a compromise in any one of these security objectives will likely affect the others. As a result, NIST SP 800-53B groups controls into impact-based baselines rather than separating them by individual security objective. Moreover, this grouping provides a general protection capability for each class of system.
In practice, this means organizations do not select separate control sets for confidentiality, integrity, and availability. Instead, they select a single baseline at the appropriate impact level and let that baseline address all three objectives together. Furthermore, when organizations need stronger protection in one specific area, they supplement the baseline with additional controls or apply an overlay, rather than rebuilding the baseline from scratch.