NIST SP 800-37 NISTSP37-3: RMF Select Step: Security and Privacy Control Selection
Execute the Select step per NIST SP 800-37 Rev 2 Chapter 3 Step 3. Select an initial set of security and privacy controls from NIST SP 800-53 Rev 5 (or successor) commensurate with the system categorisation, then tailor the baseline (adding, removing, scoping, parameterising, supplementing with overlays for sectoral or mission-specific requirements). Tasks include (S-1) select control baselines per FIPS 200 + SP 800-53B (Low/Moderate/High), (S-2) tailor controls (designating common, system-specific, hybrid), (S-3) allocate controls to specific implementation responsibilities, (S-4) document control selections in the System Security and Privacy Plan (SSPP), (S-5) develop continuous monitoring strategy aligned with control selections, (S-6) review and approve SSPP. Apply overlays (e.g. FedRAMP, CNSSI 1253, IRS Pub 1075) where required by mission, regulation, or contract.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 89 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33