Baseline Tailoring PL-11
Planning · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PL-11 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Planning family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PL-11 (Baseline Tailoring) is the next step after PL-10: take the baseline you selected and adjust it to fit the system — adding, removing, or changing controls where the environment or risk calls for it — and record each change. It is a Planning control at the Low baseline.
What good looks like
- Start from the baseline you selected (PL-10) and adjust it to fit the real system.
- Add, remove, or change controls where the environment or risk justifies it.
- Base each change on risk, not convenience.
- Record every deviation and the reason behind it.
- Keep the tailored set in step with the system’s plan.
Framework mapping
How to move it toward Implemented
- Walk the selected baseline against the lab server and mark the controls that do not fit as-is.
- For each change, log the deviation — what you changed and the risk-based reason — in a dated tailoring record.
- Note any control you left out and why (for example, a service the server does not run), so the gap is a decision, not an oversight.
- Attach that tailoring record as hardening evidence on the asset, naming
PL-11in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.