NIST 800-53 REV 5 • PLANNING

PL-10Baseline Selection

Select a control baseline for the system.

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

Supplemental Guidance

Control baselines are predefined sets of controls specifically assembled to address the protection needs of a group, organization, or community of interest. Controls are chosen for baselines to either satisfy mandates imposed by laws, executive orders, directives, regulations, policies, standards, and guidelines or address threats common to all users of the baseline under the assumptions specific to the baseline. Baselines represent a starting point for the protection of individuals’ privacy, information, and information systems with subsequent tailoring actions to manage risk in accordance with mission, business, or other constraints (see [PL-11](#pl-11) ). Federal control baselines are provided in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) . The selection of a control baseline is determined by the needs of stakeholders. Stakeholder needs consider mission and business requirements as well as mandates imposed by applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. For example, the control baselines in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) are based on the requirements from [FISMA](#0c67b2a9-bede-43d2-b86d-5f35b8be36e9) and [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) . The requirements, along with the NIST standards and guidelines implementing the legislation, direct organizations to select one of the control baselines after the reviewing the information types and the information that is processed, stored, and transmitted on the system; analyzing the potential adverse impact of the loss or compromise of the information or system on the organization’s operations and assets, individuals, other organizations, or the Nation; and considering the results from system and organizational risk assessments. [CNSSI 1253](#4e4fbc93-333d-45e6-a875-de36b878b6b9) provides guidance on control baselines for national security systems.

Practitioner Notes

Baseline selection means choosing the appropriate set of security controls for your system based on its impact level (Low, Moderate, or High). NIST SP 800-53B defines the control baselines.

Example 1: Categorize your system using FIPS 199 criteria (confidentiality, integrity, and availability impact levels). Then select the corresponding control baseline from NIST SP 800-53B. For example, a Moderate-impact system uses the Moderate baseline. Document your categorization and baseline selection in your SSP.

Example 2: Use CNSSI 1253 for national security systems or reference CMMC level requirements if you are a defense contractor. Map the selected baseline controls to your SSP and begin documenting how each control is implemented in your environment. Use a GRC tool or a spreadsheet to track implementation status across all baseline controls.