Baseline Selection PL-10
Planning · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PL-10 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Planning family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PL-10 (Baseline Selection) is short: pick a control baseline for the system. A baseline is a starting set of controls chosen to match how important the system is and the risk it carries. Choosing it on purpose — and writing down why — is the whole control. It sits at the Low baseline.
What good looks like
- Pick a starting baseline of controls that fits the system’s risk and importance.
- Base the choice on the system’s security categorization (Low, Moderate, or High).
- Use a recognized baseline — for example, a published benchmark or the SP 800-53 Low, Moderate, or High set.
- Write down which baseline you chose, and why.
- Revisit the choice when the system’s risk or role changes.
Framework mapping
How to move it toward Implemented
- Decide the server’s categorization (Low, Moderate, or High) based on the data it holds and what it does.
- Choose a concrete baseline to build against — the CIS (Center for Internet Security) Benchmark for the server’s operating system, or the SP 800-53 Moderate set — and name it in the plan.
- Record the choice and the reason in a dated document, so the starting point is clear before you begin hardening.
- Attach that baseline-selection record as hardening evidence on the asset, naming
PL-10in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.