Author(s):
Series Title
National Institute of Standards and Technology
Abstract
This publication provides security and privacy control baselines for the Federal Government.
There are three security control baselines (one for each system impact level—low-impact,
moderate-impact, and high-impact), as well as a privacy baseline that is applied to systems
irrespective of impact level. In addition to the control baselines, this publication provides
tailoring guidance and a set of working assumptions that help guide and inform the control
selection process. Finally, this publication provides guidance on the development of overlays to
facilitate control baseline customization for specific communities of interest, technologies, and
environments of operation.
Reference details
DOI
10.6028/NIST.SP.800-53B
Resource type
Report
Year of Publication
2020
Publication Area
Cybersecurity and defense
Date Published
2020-10-28
How to cite this reference:
FORCE, J. T. (2020). Control Baselines for Information Systems and Organizations. In National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53B (Original work published)