Control Baseline Selection
Control baseline selection is the practice of choosing a pre-defined set of security and privacy controls as a starting point for protecting an information system. Rather than building a control set from scratch, an organization picks a baseline matched to how sensitive or critical the system is, then adjusts it to fit its specific circumstances. This gives teams a consistent, repeatable foundation for managing information security and privacy risk.
Control baseline selection is the baseline control selection approach described in NIST guidance, in which practitioners select a pre-defined set of controls (a control baseline) assembled to address a defined level of protection. Under NIST SP 800-53B, there are three security control baselines corresponding to low-, moderate-, and high-impact system categorizations, along with a privacy baseline for systems subject to privacy considerations. The selected baseline is not applied verbatim; it is subsequently tailored (per NIST SP 800-53 control PL-11) by identifying and designating common controls, applying scoping considerations, and selecting compensating controls as needed to reflect the organization's risk environment and operational context. This NIST-oriented approach is distinct from the SOC 2 Trust Services Criteria and from ISO/IEC 27001 Annex A control selection via a Statement of Applicability, though the underlying concept of risk-informed control selection is broadly analogous.
Why it matters
Control baseline selection matters because it gives organizations a disciplined, repeatable starting point for managing information security and privacy risk rather than assembling a control set from scratch. By matching a pre-defined baseline to how sensitive or critical a system is, teams can achieve consistency across systems and reduce the risk of overlooking foundational safeguards. Under NIST SP 800-53B, the three security baselines corresponding to low-, moderate-, and high-impact categorizations provide a structured way to align the rigor of controls with the consequences of a compromise.
The practice also matters because a baseline is only a starting point, not a finished control set. NIST guidance expects the selected baseline to be tailored to the organization's actual risk environment and operational context. Applying a baseline verbatim without designating common controls, applying scoping considerations, or selecting compensating controls can leave a control set poorly fitted to the system it is meant to protect. The value of baseline selection therefore comes from combining a sound starting point with thoughtful, risk-informed adjustment.
For teams working across multiple frameworks, it is worth noting that this NIST-oriented approach is distinct from the SOC 2 Trust Services Criteria and from ISO/IEC 27001 Annex A control selection via a Statement of Applicability. The underlying concept of risk-informed control selection is broadly analogous across these frameworks, but the specific baselines, control catalogs, and selection mechanisms differ, and satisfying one approach does not automatically satisfy another.
Who it's relevant to
Inside Control Baseline Selection
Common questions
Answers to the questions practitioners most commonly ask about Control Baseline Selection.