NIST Issues Draft Guidance on Security and Privacy Control Baselines – SP 800-53B

Sheppard Mullin Richter & Hampton LLP

NIST’s news draft guidance, Special Publication 800-53B, Control Baselines for Information Systems and Organizations, provides important information on selecting both security and privacy control baselines for the Federal Government. These control baselines are from NIST Special Publication 800-53 and have been moved to this separate publication “so the SP 800-53 [can] serve as a consolidated catalog of security and privacy controls regardless of how those controls [are] used by different communities of interest.”   The new guidance addresses federal information systems and is applicable to information systems used or operated by an agency, a contractor on behalf of an agency, or another organization on behalf of an agency.

This guidance provides security control baselines for low, moderate, and high-impact systems and an initial privacy baseline for meeting and managing privacy risks that arise from processing personally identifiable information. These control baselines are organized and mapped out to 20 control families from SP 800-53 (Revision 5), including Personally Identifiable Information Processing and Transparency and Supply Chain Risk Management. It also outlines a tailoring process in which companies can align their controls to more closely address the specific security and privacy requirements required by their specific circumstances. The goal of this process is to provide cost-effective solutions to support organizational missions and business needs along with adequate security and privacy protections commensurate with risk.

Companies can tailor the control baselines through use of common controls, applying scoping considerations, selecting compensating controls, assigning control parameter values, supplementing control baselines, or providing specification information for control implementation.

When making tailoring decisions, companies need to address every control in the selected baseline and document the rationale of the tailoring decisions. In particular, if a control is determined not to be needed, the rationale must be recorded in the system and in the security plans, which must be subsequently approved by responsible individuals within the company.

NIST is soliciting comments on this draft guidance through the end of the public comment period on September 11, 2020.

Putting it Into Practice: Federal contractors should pay close attention to these guidelines as these new security and privacy baselines will be applied to any federal information system used or operated by a contractor on behalf of an agency, or another organization on behalf of an agency. Companies in the private sector should pay attention as well, as NIST guidance is often used as a basis for industry standards in security and privacy.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Sheppard Mullin Richter & Hampton LLP | Attorney Advertising

Written by:

Sheppard Mullin Richter & Hampton LLP

Sheppard Mullin Richter & Hampton LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide

This website uses cookies to improve user experience, track anonymous site usage, store authorization tokens and permit sharing on social media networks. By continuing to browse this website you accept the use of cookies. Click here to read more about how we use cookies.