{
  "node_id": "nist-sp-800-53b-control-baselines",
  "title": "Control Baselines for Information Systems and Organizations",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2020-12-10",
  "bluf": "This publication provides security and privacy control baselines for the Federal Government. It establishes three security control baselines, one for each system impact level-low-impact, moderate-impact, and high-impact-as well as a privacy baseline that is applied to systems irrespective of impact level. These control baselines serve as a starting point for organizations in the security and privacy control selection process. The document provides tailoring guidance and a set of working assumptions that help guide and inform the control selection process, allowing organizations to customize their security and privacy control baselines to protect their critical and essential operations and assets.\n\nThe guidance is applicable to any organization that processes, stores, or transmits information, including federal, state, local, and tribal governments, as well as private sector organizations. For federal information systems, implementation of a minimum set of controls selected from NIST SP 800-53 is mandatory in accordance with the Federal Information Security Modernization Act (FISMA) and OMB Circular A-130. The core obligation involves categorizing systems by impact level, selecting the appropriate predefined control baseline, and then applying a tailoring process to align the controls more closely with specific organizational mission needs and risk assessments. This proactive and systematic approach helps ensure systems are sufficiently trustworthy and resilient to support the economic and national security interests of the United States.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "fips-199-security-categorization",
    "nist-sp-800-30-risk-assessment"
  ],
  "primary_citations_count": 8
}