3.3 Control Tailoring, Scoping & Overlay Guidance

Key Takeaways

  • Control tailoring customizes an initial control baseline to match an organization's operational mission, technical environment, and specific threat landscape.
  • Scoping guidance identifies and documents inapplicable controls based on architectural, physical, or technical factors, but controls can never be scoped out due to cost or convenience.
  • Organization-Defined Parameters (ODPs) complete control statements by assigning specific frequencies, thresholds, and configuration values defined by organization policy.
  • Compensating controls are alternative safeguards deployed when baseline controls cannot be practically implemented; they must meet the original intent and provide equivalent protection.
  • Specialized overlays (e.g., CNSSI 1253 for DoD/Classified, NIST SP 800-82 for ICS/OT, Privacy Overlays) provide pre-tailored control baselines for specialized mission domains.
Last updated: August 2026

3.3 Control Tailoring, Scoping & Overlay Guidance

Core Blueprint Focus: No standardized control baseline fits every operational environment perfectly out of the box. RMF Step 2 (Select / Task S-2: Control Tailoring) empowers organizations to modify, scope, parameterize, and supplement baseline controls to align with their specific risk tolerance, technical architecture, and legal constraints. Mastering the rigorous justification rules for scoping exclusions, compensating controls, and specialized overlays is critical for both the CGRC exam and real-world system authorizations.

Tailoring is the systematic process by which an organization takes an initial control baseline (Low, Moderate, High, or Privacy) selected from NIST SP 800-53B and modifies it to produce a tailored control baseline uniquely suited to the information system's operational environment and mission requirements.


The NIST SP 800-53B Tailoring Process

The tailoring process consists of four major, interconnected engineering activities:

┌─────────────────────────────────────────────────────────────────────────────┐
│                     THE CONTROL TAILORING WORKFLOW                          │
│                                                                             │
│  ┌───────────────────────────────────────────────────────────────────────┐  │
│  │ 1. INITIAL CONTROL BASELINE SELECTION (FIPS 199 / NIST SP 800-53B)    │  │
│  │    • Low, Moderate, or High Security Baseline + Privacy Baseline      │  │
│  └──────────────────────────────────┬────────────────────────────────────┘  │
│                                     │                                       │
│                                     ▼                                       │
│  ┌───────────────────────────────────────────────────────────────────────┐  │
│  │ 2. APPLY SCOPING GUIDANCE                                             │  │
│  │    • Identify inapplicable controls (e.g., wireless, mobile code)     │  │
│  │    • Document technical and operational rationale                     │  │
│  └──────────────────────────────────┬────────────────────────────────────┘  │
│                                     │                                       │
│                                     ▼                                       │
│  ┌───────────────────────────────────────────────────────────────────────┐  │
│  │ 3. PARAMETERIZE CONTROLS (ODPs)                                       │  │
│  │    • Assign organizational values to placeholders (frequencies/limits)│  │
│  └──────────────────────────────────┬────────────────────────────────────┘  │
│                                     │                                       │
│                                     ▼                                       │
│  ┌───────────────────────────────────────────────────────────────────────┐  │
│  │ 4. SELECT COMPENSATING CONTROLS & SUPPLEMENT BASELINE                 │  │
│  │    • Engineer alternative safeguards for legacy/constrained systems   │  │
│  │    • Add enhancements based on unique threat intelligence & overlays  │  │
│  └──────────────────────────────────┬────────────────────────────────────┘  │
│                                     │                                       │
│                                     ▼                                       │
│  ┌───────────────────────────────────────────────────────────────────────┐  │
│  │ 5. FINAL TAILORED CONTROL BASELINE (Documented in SSP)                │  │
│  └───────────────────────────────────────────────────────────────────────┘  │
└─────────────────────────────────────────────────────────────────────────────┘

1. Scoping Guidance: Identifying Inapplicable Controls

Scoping guidance provides criteria for determining which baseline controls are applicable to a system based on its technical architecture, physical environment, and operational mission. If a control is determined to be inapplicable, it is scoped out of the baseline, and a formal justification is documented in the System Security Plan (SSP).

Valid Scoping Categories & Considerations:

  • Technology-Specific Inapplicability: Controls designed for technologies not present within the authorization boundary can be scoped out. For example:
    • PE-18 (Wireless Access): Inapplicable if the facility and system strictly prohibit and contain zero wireless networking hardware, interfaces, or protocols.
    • MP-4 / MP-5 (Media Transport / Media Sanitization): Inapplicable if the system operates as a 100% diskless, containerized cloud workload that never interacts with physical removable media.
    • SC-19 (Mobile Code): Inapplicable if the operating environment completely blocks and does not execute mobile code (e.g., Java applets, ActiveX).
  • Physical & Environmental Considerations: Systems deployed in commercial secure colocation facilities may scope out certain environmental controls that are handled at the facility level, or air-gapped systems in a Sensitive Compartmented Information Facility (SCIF) may scope out public remote access controls.
  • Operational & Mission Constraints: Systems supporting real-time deterministic workflows (e.g., weapons telemetry or surgical robotics) may scope out automated reboot controls after patching to prevent catastrophic loss of life.

[!CAUTION] The Cardinal Rule of Scoping: Controls CAN NEVER be scoped out due to cost, administrative inconvenience, lack of staff, or scheduling delays. Scoping exclusions must be justified strictly on objective technical, physical, or architectural facts.


2. Parameterization: Organization-Defined Parameters (ODPs)

Many controls in NIST SP 800-53 Rev. 5 contain flexible placeholders designated as Organization-Defined Parameters (ODPs). Parameterization is the process of completing these placeholders with specific, measurable values, thresholds, and frequencies established by organizational policy.

ODPs are structured into two distinct grammatical operations:

  1. Assignment Operations: Requires the organization to define a specific value, timeframe, threshold, or parameter.
    • Example (AC-2b): "Require approval by [Assignment: organization-defined personnel or roles] for requests to create information system accounts." -> Tailored Value: "Department Information System Security Officer (ISSO) and System Owner."
    • Example (AC-7a): "Enforce a limit of consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period] to [Assignment: organization-defined number]." -> Tailored Value: "3 failed attempts within a 15-minute window."
  2. Selection Operations: Requires the organization to select one or more options from a pre-defined list provided in the control statement.
    • Example (IA-2(1)): "Implement multifactor authentication for network access to privileged accounts using [Selection: PIV credential; FIDO2 hardware authenticator; biometric authentication]." -> Tailored Value: "PIV credential and FIDO2 hardware authenticator."

Multi-Tier Parameterization Hierarchy:

  • Tier 1 / Tier 2 Parameterization: Enterprise leadership (CISO/CIO) establishes organization-wide mandatory ODP baselines (e.g., enterprise-wide password policy, enterprise session lock times) in enterprise security standards.
  • Tier 3 Parameterization: System Owners fill in remaining system-specific parameters (e.g., application-specific audit review frequencies) within the boundaries permitted by Tier 1/2 policies.

3. Compensating Controls: Criteria & Justification

A Compensating Control is an alternative technical, operational, or management safeguard implemented in lieu of a baseline control when the baseline control cannot be practically or technically implemented due to legacy system limitations, architectural constraints, physical barriers, or severe operational friction.

┌─────────────────────────────────────────────────────────────────────────────┐
│               THE FOUR MANDATORY COMPENSATING CONTROL CRITERIA              │
│                                                                             │
│  1. INTENT COMPLIANCE                                                       │
│     • Must satisfy the core security and risk mitigation intent of the     │
│       original baseline control.                                            │
│                                                                             │
│  2. COMPARABLE PROTECTION                                                   │
│     • Must provide an equivalent or greater level of protection against     │
│       the targeted threat vector.                                           │
│                                                                             │
│  3. NO UNACCEPTABLE RESIDUAL RISK                                           │
│     • Must not introduce new unmanaged vulnerabilities or create            │
│       collateral risk to interconnected systems.                            │
│                                                                             │
│  4. FORMAL JUSTIFICATION & APPROVAL                                         │
│     • Must be thoroughly documented in the SSP, validated by the Assessor   │
│       (SCA), and formally approved by the Authorizing Official (AO).        │
└─────────────────────────────────────────────────────────────────────────────┘

Practical Engineering Example of a Compensating Control:

  • Baseline Requirement: SI-2 (Flaw Remediation) and IA-2 (MFA) on a legacy biomedical imaging workstation running an unpatchable legacy operating system embedded in an MRI machine.
  • Operational Constraint: Applying patches or modern MFA agents will crash the FDA-certified medical imaging software.
  • Compensating Control Strategy:
    1. Isolate the workstation on a dedicated, air-gapped micro-segmented VLAN (SC-7 Boundary Protection).
    2. Enforce strict MAC address filtering and disable all physical USB and peripheral ports (MP-7 Media Use).
    3. Route all telemetry through an inline Web Application Firewall / IPS that inspects traffic for known exploit signatures (SI-4 Information System Monitoring).
    4. Require two-person physical room badge authentication before physical console access is permitted (PE-3 Physical Access Control).

4. Supplementing Baselines & Specialized Overlays

Supplementing Baselines

Organizations may supplement baselines by adding controls or control enhancements that are not included in the standard FIPS 199 Low/Moderate/High baseline. Supplementation is driven by threat intelligence, unique high-value asset (HVA) protection requirements, specific vulnerability trends, or higher local risk appetite.

Specialized Overlays

An Overlay is a fully tailored, pre-packaged specification of security and privacy controls, parameter values, and supplemental guidance designed for a specific operational domain, technology stack, regulatory environment, or threat community.

Specialized OverlayAuthority / StandardKey Focus & Tailoring Characteristics
DoD / National Security Systems (NSS) OverlaysCNSSI 1253 (Committee on National Security Systems Instruction 1253)• Categorizes C-I-A independently (e.g., C: High, I: Moderate, A: Low) rather than using a single High-Water Mark.<br>• Specialized overlays for Classified Enclaves, Tactical Edge Deployments, Weapons Systems, and Cross-Domain Solutions (CDS).
Industrial Control Systems (ICS) / OT OverlayNIST SP 800-82 Rev. 3 (Guide to Operational Technology Security)• Tailors controls for SCADA, DCS, and PLC environments.<br>• Prioritizes Availability and Human Safety over Confidentiality.<br>• Restricts automated patching/reboots; mandates strict deterministic network latency and physical isolation.
Privacy OverlaysNIST Privacy Framework / SP 800-53B• Focuses on systems ingesting high volumes of PII, biometric data, or public surveillance.<br>• Enforces data minimization (PT-1), privacy notices (PT-2), consent tracking (PT-3), and data retention limits.
Internet of Things (IoT) / Mobile OverlaysNIST SP 800-213 / SP 800-124• Tailors controls for constrained compute devices, battery-powered sensors, remote field devices, and mobile device management (MDM).

Tailoring Documentation Requirements in the SSP

Every tailoring decision must be documented within the System Security Plan (SSP). The table below summarizes how tailoring actions must be recorded for assessor review and AO approval:

Tailoring ActionRequired Documentation in SSPAssessor Verification Standard
Scoping Out a ControlFormal statement of inapplicability, architectural proof (e.g., network diagram showing no wireless), and environmental justification.Assessor examines architecture and tests configurations to confirm the technology or condition is genuinely absent.
Parameterization (ODP)Explicit organizational values inserted into all bracketed assignment/selection clauses.Assessor verifies that assigned values comply with enterprise Tier 1/2 policies and are technically enforced.
Compensating ControlFull engineering description of the alternative safeguard, technical rationale why baseline was impossible, and risk equivalence analysis.Assessor conducts focused testing on the compensating mechanism to ensure risk is mitigated to the same degree.
Applying an OverlayIdentification of the overlay standard (e.g., CNSSI 1253, NIST SP 800-82) and baseline delta mapping.Assessor reviews compliance against the specific overlay requirements and baseline additions.

Real-World RMF Scenario: Tailoring and Applying the NIST SP 800-82 OT Overlay

Scenario: A municipal public utility operates a supervisory control and data acquisition (SCADA) system controlling city water filtration valves. The initial baseline selected is Moderate based on public safety impact. The standard baseline control SI-2 (Flaw Remediation) requires applying critical security patches within 30 days of release and automatically rebooting the systems.

GRC Action: Applying automated reboot patching to real-time programmable logic controllers (PLCs) could disrupt chemical dosing, causing water contamination or physical pipe rupture. The security engineering team applies the NIST SP 800-82 OT Overlay. They tailor SI-2 by implementing a compensating control: vendor patches are tested in an offline sandbox environment, delayed until scheduled annual plant maintenance windows, and the PLCs are protected by unidirectional security gateways (data diodes) and continuous network anomaly sensors.

Loading diagram...
NIST SP 800-53B Control Tailoring Workflow & Decision Logic
Test Your Knowledge

An Information System Security Officer (ISSO) is tailoring the baseline controls for a cloud-native database that processes non-sensitive transactional records. The ISSO wishes to exclude control PE-18 (Wireless Access) and MP-4 (Media Transport). Under what condition is this scoping decision legally and procedurally compliant?

A
B
C
D
Test Your Knowledge

A legacy air-traffic radar processing system cannot technically support multi-factor authentication (IA-2) or automated patching (SI-2) without crashing proprietary flight tracking software. The engineering team proposes isolating the radar system inside an air-gapped physical enclave protected by strict biometric door access, network data diodes, and continuous passive network monitoring. What type of control mechanism does this deployment represent?

A
B
C
D
Test Your Knowledge

How does the Committee on National Security Systems Instruction (CNSSI) 1253 security categorization and control selection methodology differ fundamentally from standard NIST SP 800-53B baseline selection?

A
B
C
D