Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST 800-53 tailoring explained

NIST 800-53 Tailoring: A Clear Guide to the 5 Actions

NIST 800-53 tailoring is the step that turns a catalogue of over a thousand controls into a control set an organization can actually implement. You start from a baseline, then justify every change you make to it — and the justification, not the change, is what an assessor reads.

This guide covers where baselines come from, the five tailoring actions, how overlays work, and the documentation that makes a tailored set defensible.

NIST 800-53 tailoring: from baseline through tailoring actions to the final control set
Categorise, select a baseline, tailor with reasons, record the result.

Where the baseline comes from

The control catalogue lives in SP 800-53. The baselines live in SP 800-53B: three security baselines for low, moderate and high impact systems, plus a privacy baseline applied regardless of impact level. Which security baseline applies is decided by the impact level from your FIPS 199 categorisation — the highest of confidentiality, integrity and availability.

The baseline is where NIST 800-53 tailoring starts and explicitly not where it ends. SP 800-53B ships tailoring guidance alongside the baselines precisely because no baseline fits a real system as issued.

The five NIST 800-53 tailoring actions

Action What it does What has to be recorded
Identify common controls Inherit controls provided by another system or provider Who provides it, and what remains your responsibility
Apply scoping considerations Remove or narrow controls that do not apply to the system Why the technology, mission or environment makes it inapplicable
Select compensating controls Substitute where a baseline control cannot be implemented The equivalent protection provided, and the residual risk accepted
Assign parameter values Fill in the organization-defined values the controls leave open The value, and where the number came from
Supplement the baseline Add controls or enhancements the risk assessment demands The risk that justified the addition

Of the five NIST 800-53 tailoring actions, the fourth is the quiet one. Controls are written with organization-defined parameters — how often, how long, how many — and an unassigned parameter is an unimplemented control. Filling them in with the smallest defensible number, consistently, is most of what makes a control set testable.

Removing a control is the action that needs the most evidence

Scoping out is legitimate and frequently abused. “Not applicable” has to rest on something structural — the technology is not present, the function does not exist in this system, the control is provided elsewhere — and not on the fact that implementing it would be inconvenient. If the reason you cannot implement it is cost or capability, that is a compensating control or a plan of action, not a scoping decision. Our guide to the plan of action and milestones covers the second route.

Overlays: tailoring somebody else has already done

An overlay is a fully specified set of NIST 800-53 tailoring decisions for a community of interest, a technology or an environment — federal PKI, industrial control systems, privacy, classified systems. Adopting one saves the analysis and, more usefully, aligns you with peers and with the assessors who read those systems every day. NIST maintains a public repository for sharing them.

The live area here is artificial intelligence: NIST’s Control Overlays for Securing AI Systems project is developing overlays that apply the 800-53 catalogue to AI use cases, with material published for comment through 2025 and 2026. If you are securing an AI system today, that work is worth tracking rather than inventing your own tailoring from scratch.

Where NIST 800-53 tailoring goes wrong

The baseline is treated as the deliverable. Implementing a moderate baseline unchanged is not tailoring; it is avoiding a decision, and it produces controls that do not fit alongside controls that were needed and never added.

Parameters left at the example value. Copying a template’s numbers means you are testing against somebody else’s policy, and the mismatch surfaces the first time an assessor compares your parameter to your actual configuration.

Inheritance claimed without a boundary. Inheriting cloud provider controls is normal and correct — claiming inheritance without a shared responsibility analysis is how systems fail assessment. Our guide to the shared responsibility matrix covers the split.

No record of the reasoning. A tailored control set with no rationale column cannot be defended, reviewed, or inherited by whoever holds the system next.

Frequently asked questions

What is NIST 800-53 tailoring?
The process of adjusting a control baseline to a specific system — identifying common controls, scoping, applying compensating controls, assigning parameter values and supplementing — with the reasoning documented.

Where are the baselines published?
In SP 800-53B, separately from the control catalogue in SP 800-53. That split is deliberate: the catalogue is the superset, the baselines are one way of selecting from it.

Can we remove controls from a baseline?
Yes, with justification, through scoping considerations. The justification has to be structural rather than practical, and it is recorded in the system security plan.

What is an overlay?
A pre-built, fully specified set of tailoring decisions for a community, technology or environment — usable as-is or as a starting point, and shareable through NIST’s overlay repository.

Does FedRAMP allow NIST 800-53 tailoring?
FedRAMP baselines are themselves tailored from 800-53, and providers work within them rather than re-tailoring freely. The parameter assignments in particular are largely fixed for you.

Where this leaves you

Categorise honestly, take the matching baseline from SP 800-53B, then tailor with a written reason against every change. Assign every organization-defined parameter yourself, keep scoping decisions structural, and treat inheritance as something you prove with a responsibility split rather than assert. Look for an existing overlay before building your own — and if you are securing AI systems, watch NIST’s overlay work rather than inventing a control set nobody else will recognise.

References

More on NIST controls

Control selection worksheets, parameter registers and the system security plan are in the NIST SP 800-53 Security Controls Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.