SP 800-171 Tailoring Criteria as applied to SP 800-53 derived controls
“Tailoring” is most recognized about the scoping of FedRamp [SP 800-53B], however tailoring criteria used for SP 800-171 (listed below) accomplishes a different objective to tailor requirements exclusive necessary for CUI further. For Federal Information Systems, the [FIPS 199] impact assessment applied to the control families within [FIPS 200] and further elaborated as the catalog of SP 800-53 resulting in three “Baselines,” represented in [SP 800-53B] as “privacy,” “high,” “moderate,” and “low.” The design of the NIST 171 leverages the “moderate” control set with additional tailoring to exclude Integrity and Availability elements except where these principles would remove the system’s capability to protect the Confidentiality of Information.
One might ask why only 79 out 306 [SP 800-53B] moderate baseline controls and enhancements rated as “CUI, the basic or derived security requirement is reflected in and is traceable to the security control, control enhancement, or specific elements of the control/enhancement.” The summary and discussion about the selection of derived controls are shown in Appendix E Tailoring Criteria [SP 800-171r2]. The action of Tailoring does not endorse the elimination of controls. Tailoring prioritizes requirements based upon their suitability to the protection of CUI on non-federal systems from unauthorized disclosure.
The 14 out of 17 [FIPS 200] requirements each have one or more Basic security requirements assigned to them, notated as a triptych 3.#.#. However, because FIPS 200 is a set of “minimum” requirements, these are often insufficient to protect at the required “Moderate” impact level for covered defense information (CDI). Accordingly, when the Basic Requirement does not fully meet the “Moderate” requirement, related controls from the “Moderate” baseline in SP 800-53 are specified and identified in SP 800-171 as Derived Requirements (i.e., derived from SP 800-53).
All SP 800-171 requirements are required, expressed as Basic or Derived. DoD and Under Secretary of Defense for Acquisition and Sustainment OUSD(A&S) dictate each supplier’s required assessment level. For those organizations rated Level 1, compliance is achieved via annual Self-Reported SPRS, requiring a score for cybersecurity and adoption as sufficient to thwart cyber-attacks. The assessment aligns with all practices for organizations designated as Level 2 SP 800-171. Section 2.2 of SP 800-171 details the Basic Requirements from FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, and the Derived requirements shaped from NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. Tailoring notation for CUI is as follows.
TAILORING SYMBOL TAILORING CRITERIA
- NCO not directly related to protecting the confidentiality of CUI.
- FED is uniquely federal, primarily the responsibility of the federal government.
- NFO is expected to be routinely satisfied by nonfederal organizations without specification.
- CUI, the basic or derived security requirement is reflected in and is traceable to the security control, control enhancement, or specific elements of the control/enhancement.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics