Control Tailoring
Control tailoring is the process of adjusting a starting set of security controls (a baseline) so it fits the specific system and environment where it will be used. Rather than applying every control exactly as written, an organization modifies the baseline based on its actual risks, operations, and conditions. This generally helps ensure the resulting controls are appropriate and relevant rather than one-size-fits-all.
Control tailoring is the process by which security control baselines are modified to fit a specific system and its environment of operation. As described in the NIST glossary and associated guidance, this generally includes identifying and designating common controls, applying scoping considerations, and selecting or adjusting controls to reflect organizational context, which may involve adding, enhancing, or otherwise modifying baseline controls. Under NIST SP 800-37 (RMF Task S-2), organizations use risk assessments to inform and guide the tailoring process. Note that tailoring is one step within control selection and does not by itself constitute assessment or authorization; readers should verify specific procedures against the current authoritative NIST publications, since baselines and tailoring guidance vary by applicable revision and agency-specific implementation.
Why it matters
Control tailoring is what keeps a security control baseline from becoming an unwieldy, poorly fitting checklist. A baseline is only a starting point; it is selected to address a broad class of systems at a given impact level, not the particular mission, architecture, and threat environment of any single system. Without tailoring, organizations tend to either apply controls that do not fit their environment or overlook the scoping and common-control decisions that make a control set both defensible and manageable. Tailoring is the mechanism that connects the generic baseline to the actual risk posture of the system.
Because tailoring decisions shape which controls are ultimately implemented, they carry weight well beyond the selection step. Overly aggressive tailoring that removes or weakens controls without a documented risk basis can leave real gaps, while insufficient tailoring can burden a system with controls that do not apply to it. Under NIST SP 800-37, tailoring is expected to be driven by risk assessment rather than convenience, which is what allows an authorizing official and assessors to understand and accept the rationale behind the resulting control set.
It is worth emphasizing a common point of confusion: tailoring is one step within control selection and does not by itself constitute assessment or authorization. Completing a tailored control set does not mean the controls have been assessed as effective, nor does it produce an Authority to Operate. Treating a well-documented tailoring effort as if it were compliance or authorization is a mistake an experienced practitioner would flag, because the tailored baseline still has to be implemented, assessed, and authorized, and then maintained under continuous monitoring.
Who it's relevant to
Inside Control Tailoring
Common questions
Answers to the questions practitioners most commonly ask about Control Tailoring.