Categorize
Select
Implement
Assess
Authorize
Monitor
Categorize
Select
Implement
Assess
Authorize
Monitor
 NIST SP 800-53
Data Type
Data
Description Data Sensitivity
Data Type Confidentiality Integrity Availability
Personal Identity and Authentication Moderate Moderate Moderate
Help Desk Services Low Low Low
Budget & Finance Moderate Moderate Low
Accounting Low Moderate Low
Space Operations Low High High
High Watermark Moderate High High
Overall High Watermark High
NSTISSI No. 1000
NIST SP 800-18 Rev 1
Appendix A:
Sample Information System Security Plan Template
NSTISSI No. 1000
Plan Initiation
Plan
Development
Plan
Implementation
Plan
Maintenance
Recertification
or Retirement
System 1
Subsystem A
Subsystem B
Subsystem C
Information Criteria Security Impact
Confidentiality Low / Moderate / High
Integrity Low / Moderate / High
Availability Low / Moderate / High
Based on: NIST SP 800-60 and FIPS Pub 199
Common
Controls
System-
specific
Controls
Hybrid
Controls
NIST SP 800-37 Rev 1
“Compensating security controls are the management,
operational, or technical controls used by an agency in
lieu of prescribed controls in the low, moderate, or high
security control baselines, which provide equivalent or
comparable protection for an information system.”
Source: NIST SP 800-100 § 8.4.4
1
• Select controls from 800-53
2
• Complete and convincing rationale
3
• Assess and formally accept risk
1
• Agency has developed on documented common controls
2
• Agency has assigned responsibility of the common control
3
• Systems owners should be made aware
4
• Expert in the common control consulted
5
• Agency, Campus or Center Common Control
Source: NIST SP 800-100 § 8.4.1
Criteria Rating
Confidentiality Moderate
Availability Low
Integrity Low
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls
Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls

Understanding the Risk Management Framework & (ISC)2 CAP Module 7: Select Controls