Quick-reference card
| Field | Value |
|---|---|
| Control ID | PL-11 |
| Control Name | Baseline Tailoring |
| Framework | NIST SP 800-53, Revision 5 |
| Control Family | Planning |
| Baselines | LOW MODERATE HIGH |
| Relevance | Organization (First Party) |
| Risk Severity | Low |
What this control requires
PL-11 requires organizations to tailor their selected security and privacy control baselines to reflect their specific mission, operating environment, and risk conditions. Rather than accepting a baseline as a fixed checklist, you must apply a defined set of tailoring actions that customize controls to match how your systems actually operate and what threats they actually face.
Those tailoring actions include identifying and designating common controls, applying scoping considerations to exclude controls that don’t apply, selecting compensating controls where a baseline control isn’t feasible, assigning organization-specific values to control parameters, and supplementing the baseline with additional controls where risk warrants it. The output is a tailored baseline documented in your system security plan with a clear rationale for every modification.
In practice, tailoring is where the work of risk management becomes specific. A system categorized at the moderate impact level inherits a standard set of controls from SP 800-53B, but the operating environment, the data types processed, and the threat landscape all vary between systems even within the same organization. Tailoring bridges the gap between a generic baseline and a security plan that addresses your organization’s actual risk posture.
SP 800-53B provides the authoritative tailoring guidance, and FISMA, the Privacy Act, and OMB A-130 set the legal and policy requirements that constrain how far tailoring decisions can go. You can’t arbitrarily remove controls. Every modification must be defensible, documented, and tied to a risk-based rationale that an assessor can evaluate independently.
Why it matters
Untailored baselines create two problems. First, they waste resources by requiring controls that don’t apply to your system’s architecture or operating context. Second, they leave gaps where the baseline doesn’t account for threats specific to your environment. Both outcomes undermine the credibility of your security program during audits and assessments.
Failure to maintain this control introduces audit risk and may result in certification findings or regulatory gaps. Assessors expect documented justification for every tailoring decision. When that rationale is missing, the entire control baseline comes into question, because there’s no evidence the organization evaluated whether the inherited controls actually address its risk profile.
Organizations operating under evolving NIST frameworks face increasing scrutiny on how baselines align with continuous risk assessment. Tailoring isn’t a one-time exercise. As system boundaries change, new integrations are added, and the threat landscape shifts, your tailoring rationale needs to evolve with it.
The consequence for federal agencies is concrete. An authorization to operate depends on documented evidence that control selection reflects actual system conditions. Without a tailoring rationale, authorizing officials lack the information needed to make a risk-informed decision, and the entire authorization package stalls.
For private organizations adopting NIST SP 800-53 voluntarily or through contractual obligations, the same principle applies. An untailored baseline signals to auditors and customers that your security program is performative rather than risk-driven. Tailoring is the mechanism that transforms a generic control catalog into a security plan grounded in your operational reality.
What attackers exploit
- Inherited controls with no operational backing. When controls exist on paper but were never scoped to the actual system, attackers find gaps between documented posture and deployed defenses.
- Missing compensating controls. Organizations that remove baseline controls without implementing compensating alternatives create predictable blind spots.
- Stale tailoring decisions. Baselines tailored once and never revisited fail to account for new threat vectors, system changes, or updated vulnerability intelligence.
- Over-scoped exclusions. Broadly excluding control families through scoping considerations without granular analysis removes protections that may have been relevant to specific system components.
- Undocumented parameter assignments. Vague or missing parameter values leave security thresholds undefined, making it impossible to verify whether controls are operating at the intended strength.
How to implement
For your organization
The core challenge with PL-11 isn’t the concept of tailoring. It’s producing a documented, defensible rationale that holds up under assessment. Most organizations either skip tailoring entirely and inherit the full baseline without evaluating applicability, or they tailor informally without capturing why specific decisions were made.
Start with the outputs of your security categorization (RA-02) and baseline selection (PL-10). These two controls feed directly into tailoring. You need to know the system’s impact level, the information types it processes, and which baseline you selected before you can meaningfully customize it.
Step 1: Identify common controls. Review your organization’s common control catalog. Controls provided at the organizational level, such as physical security or personnel screening, don’t need to be re-implemented at the system level. Document which controls are inherited and from which common control provider.
Step 2: Apply scoping considerations. Evaluate each baseline control against your system’s architecture, technology stack, and operational context. Controls related to technologies you don’t use, such as wireless networking controls for an air-gapped system, can be scoped out. Document the specific reason each exclusion is justified.
Step 3: Select compensating controls. Where a baseline control can’t be implemented as written due to technical constraints, operational limitations, or cost, identify a compensating control that provides equivalent protection. The compensating control must address the same threat or vulnerability the original control was designed to mitigate.
Step 4: Assign parameter values. Many controls include organization-defined parameters, such as frequency of review, session timeout thresholds, or retention periods. Assign specific values based on your risk tolerance and operational requirements. Avoid leaving parameters as “to be determined.”
Step 5: Supplement the baseline. Based on your risk assessment (RA-03) and any applicable overlays, determine whether additional controls beyond the baseline are needed. Threat intelligence, criticality analysis, and regulatory requirements may drive supplementation.
Step 6: Document the tailoring rationale. For every tailoring action, record the decision, the justification, and any supporting evidence. This rationale is the primary artifact assessors review. Store it alongside the system security plan and maintain it through plan reviews.
Common tooling categories include governance, risk, and compliance (GRC) platforms for tracking tailoring decisions, configuration management databases for verifying control implementation, and risk assessment tools that feed tailoring analysis.
Common mistakes:
- Treating tailoring as a one-time activity rather than updating it when the system or threat environment changes
- Removing controls without documenting a compensating alternative or a risk acceptance decision
- Assigning generic parameter values copied from templates rather than values grounded in operational context
- Failing to coordinate tailoring decisions with the authorizing official or risk executive
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Tailoring policy and rationale | Baseline tailoring rationale document defining each tailoring action applied, the justification, and approval authority |
| System categorization and baseline records | Security categorization decision, selected federal or organization-approved baselines, and overlay selections |
| System security and privacy plans | System security plan and privacy plan documenting tailored control sets, parameter assignments, and common control designations |
| Risk and criticality analysis | Risk assessments, business impact analysis, and criticality analysis supporting tailoring decisions |
| Stakeholder and contractual requirements | Stakeholder needs analysis, list of security and privacy requirements allocated to the system, and contractual requirements allocated to external providers |
| Design and component documentation | System design documentation and component information used to apply scoping considerations |
| Review and update records | Records of system security and privacy plan reviews and updates that reflect tailoring changes over time |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| (No cross-framework mappings available for this control) |
Related controls
- PL-10 — Baseline Selection: provides the starting baseline that PL-11 tailoring actions customize for the specific system and environment.
- RA-02 — Security Categorization: establishes the system impact level that determines which baseline is selected and subsequently tailored.
- RA-03 — Risk Assessment: identifies threats and vulnerabilities that drive supplementation and compensating control decisions during tailoring.
- RA-09 — Criticality Analysis: informs tailoring decisions by identifying system components and functions that require additional protection beyond the baseline.
- SA-08 — Security and Privacy Engineering Principles: provides design principles that shape how tailored controls are implemented within the system architecture.
Frequently asked questions
What is NIST SP 800-53 PL-11?
PL-11 is the NIST SP 800-53 control that requires organizations to tailor their selected security and privacy control baselines using defined tailoring actions. Those actions include applying scoping considerations, selecting compensating controls, assigning values to control parameters, and documenting a tailoring rationale for every modification. The control applies at low, moderate, and high impact baselines, making it a universal requirement for any system subject to NIST SP 800-53.
What happens if PL-11 is not implemented?
Without PL-11, your organization operates on an untailored baseline that likely includes controls irrelevant to your system while missing controls your specific threat environment demands. Assessors will flag the absence of a documented tailoring rationale as a finding, because there’s no evidence that baseline controls were evaluated against actual operating conditions. This gap can delay or prevent authorization to operate and undermines the credibility of your broader compliance program.
How do you audit PL-11?
Auditors verify PL-11 by reviewing the baseline tailoring rationale alongside the system security plan to confirm that each tailoring action is documented and justified. They check that common control designations align with organizational common control catalogs, that scoping exclusions reference specific architectural or operational conditions, that compensating controls map to the threats the original controls addressed, and that organization-defined parameter assignments reflect documented risk decisions. The assessment objective is confirming that the selected control baseline has been tailored by applying the specified tailoring actions.
How do you tailor a NIST 800-53 baseline?
You tailor a NIST 800-53 baseline by applying six defined actions to the controls inherited from your selected impact level. First, identify which controls are provided as common controls by your organization. Then apply scoping considerations to exclude controls that don’t match your system’s technology or operating model. Select compensating controls where baseline controls aren’t feasible. Assign specific values to all organization-defined parameters. Supplement the baseline with additional controls where risk assessment results warrant it. Document every decision in a tailoring rationale that accompanies your system security plan. SP 800-53B provides the authoritative guidance for each of these tailoring actions.