Skip to main content
Category: Security Controls & Tailoring

Control Tailoring

Also known as: Tailoring, Tailoring Security Controls
Simply put

Control tailoring is the process of adjusting a starting set of security controls (a baseline) so it fits the specific system and environment where it will be used. Rather than applying every control exactly as written, an organization modifies the baseline based on its actual risks, operations, and conditions. This generally helps ensure the resulting controls are appropriate and relevant rather than one-size-fits-all.

Formal definition

Control tailoring is the process by which security control baselines are modified to fit a specific system and its environment of operation. As described in the NIST glossary and associated guidance, this generally includes identifying and designating common controls, applying scoping considerations, and selecting or adjusting controls to reflect organizational context, which may involve adding, enhancing, or otherwise modifying baseline controls. Under NIST SP 800-37 (RMF Task S-2), organizations use risk assessments to inform and guide the tailoring process. Note that tailoring is one step within control selection and does not by itself constitute assessment or authorization; readers should verify specific procedures against the current authoritative NIST publications, since baselines and tailoring guidance vary by applicable revision and agency-specific implementation.

Why it matters

Control tailoring is what keeps a security control baseline from becoming an unwieldy, poorly fitting checklist. A baseline is only a starting point; it is selected to address a broad class of systems at a given impact level, not the particular mission, architecture, and threat environment of any single system. Without tailoring, organizations tend to either apply controls that do not fit their environment or overlook the scoping and common-control decisions that make a control set both defensible and manageable. Tailoring is the mechanism that connects the generic baseline to the actual risk posture of the system.

Because tailoring decisions shape which controls are ultimately implemented, they carry weight well beyond the selection step. Overly aggressive tailoring that removes or weakens controls without a documented risk basis can leave real gaps, while insufficient tailoring can burden a system with controls that do not apply to it. Under NIST SP 800-37, tailoring is expected to be driven by risk assessment rather than convenience, which is what allows an authorizing official and assessors to understand and accept the rationale behind the resulting control set.

It is worth emphasizing a common point of confusion: tailoring is one step within control selection and does not by itself constitute assessment or authorization. Completing a tailored control set does not mean the controls have been assessed as effective, nor does it produce an Authority to Operate. Treating a well-documented tailoring effort as if it were compliance or authorization is a mistake an experienced practitioner would flag, because the tailored baseline still has to be implemented, assessed, and authorized, and then maintained under continuous monitoring.

Who it's relevant to

Information System Security Managers and system owners
Practitioners responsible for selecting and documenting controls for a system perform much of the tailoring work directly. They apply scoping considerations, designate common controls, and adjust the baseline to fit their system and environment, and they must document the risk-based rationale for each tailoring decision so it can withstand later review.
Authorizing officials
Because tailoring shapes the control set that ultimately supports a risk decision, authorizing officials rely on the documented tailoring rationale to understand what was added, removed, or modified and why. They should recognize that a tailored baseline is not the same as an assessed or authorized system; tailoring feeds the authorization decision but does not replace assessment or continuous monitoring.
Assessors and auditors
Those evaluating a system need to understand which controls were tailored and the basis for those decisions in order to assess whether the resulting set is appropriate. Tailoring documentation, particularly the risk assessment that informed it under NIST SP 800-37, is central to determining whether removed or modified controls were justified rather than dropped for convenience.
Compliance officers and government contractors
Personnel managing compliance obligations should treat tailoring as one step within control selection, not as evidence of compliance or authorization on its own. Since baselines and tailoring guidance differ by applicable revision and by agency-specific implementation, they should confirm the specific tailoring requirements and available actions against the current authoritative NIST publications for their environment.

Inside Control Tailoring

Baseline Selection
The starting point for tailoring, in which an initial control set is chosen. Under NIST SP 800-53 and the RMF process, baselines are generally associated with the security categorization of the system (for example low, moderate, or high impact per FIPS 199 and the guidance in NIST SP 800-53B). Tailoring begins from this selected baseline rather than from a blank slate.
Applying Overlays
The use of specialized, pre-defined sets of tailoring decisions developed for a particular community of interest, technology, or environment (for example a CUI overlay or a national security systems overlay). Overlays supplement or adjust a baseline and are typically documented so that the rationale is repeatable across similar systems.
Scoping Considerations
Determining whether a control or control element is applicable given the system's technology, operational environment, or physical and mandatory factors. Scoping may result in controls being marked not applicable when they cannot logically apply to the system as implemented.
Compensating Controls
Alternative controls selected when a baseline control cannot be implemented as written but the underlying security objective must still be met. Their use generally requires documented justification and, in most implementations, approval by the authorizing official or designated authority.
Assignment and Selection Parameters
The organization-defined values that must be specified for many controls (for example frequencies, thresholds, or permitted options). Completing these parameters is a core tailoring activity that turns a generic control statement into an organization-specific requirement.
Documentation of Rationale
The recorded justification for each tailoring decision, commonly captured in artifacts such as the security plan. This documentation supports assessment and the authorization decision by making the reasoning traceable and reviewable.

Common questions

Answers to the questions practitioners most commonly ask about Control Tailoring.

Does tailoring a control baseline mean I can remove any controls I find inconvenient?
No. Tailoring is a structured, documented process for adjusting a baseline to fit the system's actual mission, environment, and risk conditions, not a mechanism for discarding controls simply because they are burdensome. Actions such as removing or downgrading a control generally require documented justification and acceptance by the authorizing official, and organizations should confirm the specific tailoring rules and approval expectations against the applicable revision of the governing NIST guidance and any agency- or DoD-specific policy.
If I tailor out a control, does that mean the underlying risk no longer exists?
No. Tailoring adjusts which controls apply and how, but it does not eliminate the underlying risk. Removing or modifying a control is a risk decision that generally must be justified, documented, and accepted by the appropriate official, and in many cases compensating measures or explicit risk acceptance are expected. Readers should verify the documentation and acceptance requirements in the current authoritative guidance applicable to their system type.
Where should tailoring decisions be documented so they are traceable during assessment and authorization?
Tailoring decisions are generally captured in the security or system documentation, such as the security plan, so that assessors and the authorizing official can trace each adjustment to its justification. The specific artifacts, formats, and level of detail can vary by agency and by the applicable revision of the governing guidance, so confirm the required documentation location and content against your organization's current policy and the authoritative source.
Who has the authority to approve tailoring decisions?
Tailoring decisions are typically proposed by the system owner or security team and require review and acceptance by the authorizing official, since these choices affect the residual risk the official accepts at authorization. Exact roles, delegation, and approval workflows can differ across federal civilian, DoD, and other environments, so verify the responsible parties and approval chain against your applicable policy and governing publication.
How does tailoring relate to the selection of a control baseline?
Tailoring is generally applied after an initial baseline is selected, refining that starting point to reflect the system's specific conditions rather than replacing the baseline selection step. The relationship between baseline selection and tailoring, including any scoping or supplementation guidance, is defined in the applicable revision of the governing NIST guidance, which readers should consult for the current process.
Should tailoring be treated as a one-time activity completed before authorization?
Not necessarily. Because a system's environment, mission, and risk posture can change, tailoring decisions may need to be revisited over the system's life cycle, particularly in the context of continuous monitoring and reauthorization. Organizations should confirm how and when tailoring is reviewed under their applicable process, since the specific triggers and cadence can vary by agency and revision of the guidance.

Common misconceptions

Tailoring is a way to remove controls that are inconvenient or costly to implement.
Tailoring is a structured, risk-based process for adjusting a baseline to fit the system's categorization, environment, and mission, not a mechanism for arbitrarily dropping controls. Removing or modifying a control generally requires documented rationale and, in most implementations, review and approval by the authorizing official. Cost or inconvenience alone is not an accepted basis, and tailoring decisions remain subject to assessment.
Once controls are tailored and approved, the tailored set is fixed for the life of the system.
Tailoring decisions are revisited as the system, threat environment, and applicable guidance change. Because an ATO is time-bound and subject to continuous monitoring, changes to the system or its environment can require re-evaluating prior tailoring decisions. Baselines and control catalogs also evolve across revisions, so tailoring should be treated as a maintained artifact rather than a one-time task.
A compensating control is simply a note explaining why a control was skipped.
A compensating control is an alternative safeguard intended to satisfy the same security objective as the control it replaces, not merely an explanation for non-implementation. Its selection generally requires documented justification demonstrating equivalent protection and, in most implementations, formal approval before it is accepted for authorization purposes.

Best practices

Begin tailoring from the correct baseline by first confirming the system's security categorization, since the appropriate starting control set depends on the impact level and any applicable overlay.
Document the rationale for every tailoring decision in the security plan or equivalent artifact so that scoping, parameter selections, and compensating controls are traceable during assessment and authorization.
Apply relevant overlays consistently for systems handling particular information types or operating in particular environments, and verify that the overlay you use matches the system's actual scope and applicable authority.
Route significant tailoring decisions, especially compensating controls and control removals, through the authorizing official or designated approver rather than treating them as team-level judgments.
Revisit tailoring decisions when the system, its environment, or the underlying guidance changes, and integrate this review into continuous monitoring rather than treating the tailored set as permanent.
Verify tailoring against the current authoritative text of the applicable publication and revision before relying on it, since control catalogs, baselines, and parameter expectations change across revisions and may be subject to agency-specific interpretation.