During control selection for a federal information system, a security team identifies a required control from NIST SP 800-53 that is technically unfeasible due to legacy hardware constraints. What is the MOST appropriate next step according to the RMF?
-
A
Remove the control from the security plan entirely
-
B
Document a control tailoring decision and identify a compensating control
-
C
Escalate the issue to the Inspector General
-
D
Defer implementation until new hardware is procured in the next fiscal cycle without documentation