Skip to main content
Category: NIST Standards & Publications

NIST SP 800-53B

Also known as: SP 800-53B, Control Baselines for Information Systems and Organizations, NIST 800-53B
Simply put

NIST SP 800-53B is a companion publication issued by the National Institute of Standards and Technology (NIST) that provides pre-defined sets, called baselines, of security and privacy controls for federal information systems. It groups controls according to how much impact a system failure or compromise would have, offering separate baselines for low-impact, moderate-impact, and high-impact systems, along with a privacy baseline. These baselines give organizations a starting point they can tailor rather than selecting controls from scratch.

Formal definition

NIST SP 800-53B, maintained by NIST, establishes control baselines drawn from the catalog of security and privacy controls in NIST SP 800-53 (Revision 5 in the current evidence). It defines three security control baselines corresponding to system impact levels (low-impact, moderate-impact, and high-impact) and a privacy control baseline. As of the applicable revision, SP 800-53B serves as the baseline-selection companion to SP 800-53, which contains the underlying control catalog; the two should not be conflated, as SP 800-53 provides the controls while SP 800-53B specifies which controls constitute each baseline. Baselines are intended as starting points subject to organizational and system-specific tailoring, and practitioners should verify the current authoritative text, as baselines and impact-level assignments may change across revisions and agency tailoring.

Why it matters

Selecting security and privacy controls from the full NIST SP 800-53 catalog would be impractical for most organizations, because the catalog contains a large number of controls spanning many control families. NIST SP 800-53B addresses this by providing pre-defined baselines that give organizations a vetted starting point aligned to the potential impact of a system's compromise. This matters because it reduces the risk of overlooking essential controls or inconsistently applying protections across systems of similar sensitivity, and it supports repeatable, defensible control-selection decisions during processes such as the Risk Management Framework.

The baselines are organized around system impact levels, low, moderate, and high, so that the rigor of the control set scales with the consequences of a failure or compromise. For federal agencies and their contractors, this alignment between impact and baseline is central to consistent risk-based decision-making. A misunderstanding here can carry real consequences: treating a baseline as a complete, static solution rather than a tailorable starting point can leave a system either over-controlled and burdensome or under-protected for its actual risk profile.

It is important to recognize the limits of what a baseline provides. Meeting a baseline is not the same as being secure, and it is not the same as achieving an authorization to operate. Baselines represent a starting point that must be tailored to the organization and system, and control baselines and impact-level assignments may change across revisions and agency-specific tailoring. Practitioners should confirm requirements against the current authoritative NIST text and any applicable agency guidance rather than relying on a baseline as a fixed checklist.

Who it's relevant to

Information System Security Managers and Security Control Assessors
ISSMs and assessors use SP 800-53B to establish the starting control set for a system based on its impact level and to understand which controls a moderate- or high-impact system is generally expected to implement before tailoring. Assessors should remember that confirming baseline coverage supports, but does not by itself constitute, an authorization decision.
Authorizing Officials
AOs rely on the baseline-to-impact-level alignment in SP 800-53B when weighing risk-based decisions about a system. Because a baseline is a tailorable starting point rather than a fixed requirement, AOs should treat baseline conformance as one input into a broader risk determination and confirm that any tailoring is documented and justified.
Government Contractors Supporting Federal Systems
Contractors building or operating federal information systems use SP 800-53B baselines to scope the controls appropriate to a system's impact level. Contractors should verify contractual requirements and current agency tailoring separately, since this publication provides baseline selection guidance and does not resolve contractual or agency-specific implementation specifics.
Privacy Program Staff
Privacy officers and program staff can use the privacy control baseline in SP 800-53B and its role as an optional tool for identifying collaboration between security and privacy programs. This helps coordinate privacy protections alongside security controls, though the degree of collaboration and applicable controls should be confirmed against the current authoritative text.

Inside SP 800-53B

Control Baselines
NIST SP 800-53B provides the security and privacy control baselines that correspond to the controls catalog in NIST SP 800-53. These baselines are pre-defined sets of controls selected as a starting point for a given system categorization.
Low, Moderate, and High Security Baselines
The publication generally organizes security control baselines according to the impact level of the system (low-impact, moderate-impact, and high-impact), aligning with the impact categorization concepts used in the risk management process. Practitioners should verify the specific control allocations against the current revision.
Privacy Control Baseline
In addition to the security baselines, SP 800-53B includes a privacy control baseline intended to support the protection of individual privacy, reflecting the integration of privacy controls into the broader control catalog.
Tailoring Guidance
The document generally describes tailoring concepts, allowing organizations to adjust a baseline to their specific mission, operating environment, and risk tolerance rather than adopting a baseline verbatim.
Relationship to NIST SP 800-53
SP 800-53B functions as a companion to NIST SP 800-53. The catalog of controls resides in SP 800-53, while the baselines and their allocation reside in SP 800-53B; the two are maintained by NIST and are intended to be used together.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-53B.

Is NIST SP 800-53B the same thing as NIST SP 800-53?
No. NIST SP 800-53 is the catalog of security and privacy controls maintained by NIST, while NIST SP 800-53B is the companion publication that provides the control baselines (low, moderate, and high impact) and the privacy baseline drawn from that catalog. In earlier revisions, the baselines were included as an appendix within SP 800-53 itself; NIST later separated the baseline guidance into SP 800-53B. Treat them as related but distinct documents, and confirm which revision applies to your system, since baseline content can change across revisions.
Does applying a NIST SP 800-53B baseline mean my system is compliant and secure?
Not by itself. Selecting a baseline from SP 800-53B is a starting point in the control selection process, not evidence of compliance or security. Baselines are generally intended to be tailored to the system's specific mission, environment, and risk, and controls must actually be implemented, assessed, and authorized. Compliance with a control baseline and effective security are not equivalent, and a baseline selection does not substitute for assessment under the applicable authorization process. Verify implementation and assessment requirements against the current governing guidance.
How does the impact level determine which SP 800-53B baseline applies to my system?
In most implementations, the system's security categorization, commonly derived using FIPS 199 and related NIST guidance, drives the selection of a low, moderate, or high baseline from SP 800-53B. The highest impact value across confidentiality, integrity, and availability generally determines the baseline. Because agency tailoring and overlays can adjust the resulting control set, confirm your categorization approach and any agency-specific requirements against the current authoritative sources before finalizing the baseline.
Can I tailor the controls in a SP 800-53B baseline?
Generally yes. Baselines are intended to be tailored to reflect the specific operating environment, mission, and risk. Tailoring can include applying scoping considerations, adding compensating controls, and using overlays. However, tailoring decisions typically must be documented and justified, and some programs or agencies constrain how much a baseline may be reduced. Confirm the tailoring rules that apply to your program, as defense, federal civilian, and national security systems may impose different expectations.
How does the SP 800-53B privacy baseline relate to the security baselines?
SP 800-53B includes a privacy control baseline in addition to the low, moderate, and high security baselines. The privacy baseline addresses controls relevant to the processing of personally identifiable information and is generally selected based on privacy risk rather than solely on the security impact level. Security and privacy baselines are complementary and may both apply to a given system. Review the current publication to determine how the privacy baseline is intended to be selected and integrated with the security baselines for your context.
Does using a SP 800-53B baseline satisfy FedRAMP or DoD authorization requirements automatically?
No. FedRAMP and DoD authorizations build upon NIST control baselines but add their own requirements, tailoring, and processes. FedRAMP defines its own baselines and authorization procedures managed by the FedRAMP PMO, and a FedRAMP authorization does not automatically satisfy DoD requirements. DoD systems authorized under the RMF may apply additional overlays and impact-level considerations. Do not assume that selecting an SP 800-53B baseline meets any specific program's authorization obligations; verify each program's current requirements against its official guidance.

Common misconceptions

NIST SP 800-53B contains the actual security and privacy controls.
SP 800-53B provides the control baselines and tailoring guidance, not the control catalog itself. The catalog of controls is maintained in NIST SP 800-53. The two are distinct but complementary publications, both issued by NIST.
A baseline should be implemented exactly as published without modification.
Baselines are intended as a starting point. SP 800-53B generally supports tailoring so organizations can adjust the baseline to their mission, environment, and risk tolerance. Adopting a baseline verbatim without considering tailoring is not the intended use.
Applying an 800-53B baseline is the same as achieving authorization or compliance.
Selecting and implementing a baseline is one input to the broader risk management and authorization process. Compliance and an Authority to Operate depend on assessment, authorization, and continuous monitoring activities that are separate from baseline selection. Compliance with a baseline is not equivalent to being secure or authorized.

Best practices

Use NIST SP 800-53B together with the NIST SP 800-53 control catalog rather than in isolation, since the baselines reference controls defined in the catalog.
Select the applicable baseline (low, moderate, or high) based on the system's impact categorization, and document the rationale for the chosen impact level.
Apply tailoring deliberately, recording any additions, removals, or adjustments to baseline controls along with the mission, environment, and risk justifications supporting each decision.
Evaluate whether the privacy control baseline applies to your system, particularly where personally identifiable information is processed, and coordinate with privacy stakeholders.
Confirm you are working from the current revision of both SP 800-53B and SP 800-53, since baseline allocations and control content can change across revisions.
Treat baseline selection as one step within the overall risk management and authorization workflow, and pair it with assessment and continuous monitoring rather than assuming baseline adoption alone satisfies compliance.