tailoring
Term · Cybersecurity · MLC-T-CYB-004244
1. The process by which security control baselines are modified by identifying and designating common controls; applying scoping considerations; selecting compensating controls; assigning specific values to agency-defined control parameters; supplementing baselines with additional controls or control enhancements; and providing additional specification information for control implementation. Note: The tailoring process may also be applied to privacy controls.
2. The process by which a security control baseline is modified based on: (i) the application of scoping guidance; (ii) the specification of compensating security controls, if needed; and (iii) the specification of organization-defined parameters in the security controls via explicit assignment and selection statements.
3. The process by which security control baselines are modified by identifying and designating common controls; applying scoping considerations; selecting compensating controls; assigning specific values to agency-defined control parameters; supplementing baselines with additional controls or control enhancements; and providing additional specification information for control implementation. The tailoring process may also be applied to privacy controls.
4. Similar in concept to tailoring baselines as described in SP 800-53, a cooperative process that modifies part of a set of assessment elements by: (i) changing the scope of the assessment or risk management level, (ii) adding or eliminating assessment elements, or (iii) modifying the attributes of an assessment element.
5. The process by which security control baselines are modified by: identifying and designating common controls, applying scoping considerations on the applicability and implementation of baseline controls, selecting compensating security controls, assigning specific values to organization-defined security control parameters, supplementing baselines with additional security controls or control enhancements, and providing additional specification information for control implementation.
6. The process by which security and privacy control baselines are modified by identifying and designating common controls, applying scoping considerations on the applicability and implementation of baseline controls, selecting compensating controls, assigning specific values to organization-defined control parameters, supplementing baselines with additional controls or control enhancements, and providing additional specification information for control implementation.
7. The process by which xALs and specified controls are modified by considering impacts on privacy, usability, and customer experience of the user population; considering specific threats to the organization; identifying and designating common controls; scoping considerations on the applicability and implementation of specified controls; selecting any compensating controls; assigning specific values to organization-defined security control parameters; supplementing xAL controls with additional controls or control enhancements; and specifying additional information for control implementation.
8. An element that specifies profiles to modify the behavior of a benchmark; the top-level element of a tailoring document.
9. The process by which a security control baseline is modified based on:
(i) the application of scoping guidance;
(ii) the specification of compensating security controls, if needed; and
(iii) the specification of organization-defined parameters in the security controls via explicit assignment and selection statements.
| Identifier | MLC-T-CYB-004244 |
|---|---|
| Field | Cybersecurity |
| References | CNSSI 4009-2022 from OMB Circular A-130 (2016); NIST SP 800-12 Rev. 1; NIST SP 800-137; NIST SP 800-30 Rev. 1; NIST SP 800-39; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-137A; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5 from NIST SP 800-53B; NIST SP 800-53B; NIST SP 800-63-4; NISTIR 7275 Rev. 4; NISTIR 8170; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-004244",
"term": "tailoring",
"field": "Cybersecurity",
"definition": "1. The process by which security control baselines are modified by identifying and designating common controls; applying scoping considerations; selecting compensating controls; assigning specific values to agency-defined control parameters; supplementing baselines with additional controls or control enhancements; and providing additional specification information for control implementation. Note: The tailoring process may also be applied to privacy controls.\n\n2. The process by which a security control baseline is modified based on: (i) the application of scoping guidance; (ii) the specification of compensating security controls, if needed; and (iii) the specification of organization-defined parameters in the security controls via explicit assignment and selection statements.\n\n3. The process by which security control baselines are modified by identifying and designating common controls; applying scoping considerations; selecting compensating controls; assigning specific values to agency-defined control parameters; supplementing baselines with additional controls or control enhancements; and providing additional specification information for control implementation. The tailoring process may also be applied to privacy controls.\n\n4. Similar in concept to tailoring baselines as described in SP 800-53, a cooperative process that modifies part of a set of assessment elements by: (i) changing the scope of the assessment or risk management level, (ii) adding or eliminating assessment elements, or (iii) modifying the attributes of an assessment element.\n\n5. The process by which security control baselines are modified by: identifying and designating common controls, applying scoping considerations on the applicability and implementation of baseline controls, selecting compensating security controls, assigning specific values to organization-defined security control parameters, supplementing baselines with additional security controls or control enhancements, and providing additional specification information for control implementation.\n\n6. The process by which security and privacy control baselines are modified by identifying and designating common controls, applying scoping considerations on the applicability and implementation of baseline controls, selecting compensating controls, assigning specific values to organization-defined control parameters, supplementing baselines with additional controls or control enhancements, and providing additional specification information for control implementation.\n\n7. The process by which xALs and specified controls are modified by considering impacts on privacy, usability, and customer experience of the user population; considering specific threats to the organization; identifying and designating common controls; scoping considerations on the applicability and implementation of specified controls; selecting any compensating controls; assigning specific values to organization-defined security control parameters; supplementing xAL controls with additional controls or control enhancements; and specifying additional information for control implementation.\n\n8. An element that specifies profiles to modify the behavior of a benchmark; the top-level element of a tailoring document.\n\n9. The process by which a security control baseline is modified based on:\n(i) the application of scoping guidance;\n(ii) the specification of compensating security controls, if needed; and\n(iii) the specification of organization-defined parameters in the security controls via explicit assignment and selection statements.",
"references": [
"CNSSI 4009-2022 from OMB Circular A-130 (2016)",
"NIST SP 800-12 Rev. 1; NIST SP 800-137; NIST SP 800-30 Rev. 1; NIST SP 800-39",
"NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016)",
"NIST SP 800-137A",
"NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5 from NIST SP 800-53B",
"NIST SP 800-53B",
"NIST SP 800-63-4",
"NISTIR 7275 Rev. 4",
"NISTIR 8170",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/tailoring/"
}
Record 4,244 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.