Control Baseline
A control baseline is a predefined set of security or privacy controls that an organization uses as a starting point to protect an information system. Rather than selecting protections from scratch, teams begin with an established baseline and then adjust it to fit the specific system and its requirements. For federal systems, NIST publishes baselines that reflect how sensitive a system is and what legal, regulatory, or policy obligations apply.
Per the NIST CSRC glossary, a control baseline is the set of controls applicable to information or an information system to meet legal, regulatory, or policy requirements, as well as to address protection needs. NIST SP 800-53B provides security and privacy control baselines for the Federal Government, and NIST generally defines security control baselines as the set of minimum security controls associated with low-impact, moderate-impact, or high-impact information systems. Baselines are intended as a starting point for the control selection process and are typically tailored to the specific system, mission, and operating environment; readers should verify the specific controls, impact-level assignments, and any agency-specific tailoring against the current authoritative NIST publications, as baselines change across revisions.
Why it matters
Control baselines solve a fundamental problem in securing federal information systems: without a predefined starting point, teams would have to select protections from scratch for every system, an approach that is inconsistent, error-prone, and difficult to assess or audit. By anchoring control selection to an established baseline that reflects a system's impact level, organizations bring consistency and defensibility to their security posture and give assessors and authorizing officials a common reference against which to evaluate a system.
The impact-level structure matters because it ties the rigor of protection to the sensitivity of the system. A low-impact system does not warrant the same set of minimum controls as a high-impact system, and starting from the wrong baseline can either leave a system under-protected or burden it with controls that do not fit its mission and operating environment. Because a baseline is a starting point rather than a finished control set, the tailoring that follows is where much of the real risk decision-making happens; treating the baseline itself as sufficient without tailoring to the specific system is a common misunderstanding an expert would correct.
It is also important not to equate selecting or implementing a baseline with being secure or authorized. A baseline informs the controls applicable to a system, but assessment and authorization are separate activities, and control baselines change across revisions. Practitioners should verify the specific controls, impact-level assignments, and any agency-specific tailoring against the current authoritative NIST publications rather than relying on a baseline snapshot that may be out of date.
Who it's relevant to
Inside Control Baseline
Common questions
Answers to the questions practitioners most commonly ask about Control Baseline.