A security engineer is reviewing the control baseline for a new cloud-hosted financial system. The system processes highly sensitive PII and is categorized as HIGH impact. Which NIST SP 800-53 baseline should serve as the STARTING POINT for control selection?
-
A
LOW baseline, then add controls based on threat modeling
-
B
MODERATE baseline, since most federal systems use it by default
-
C
HIGH baseline, tailored further based on system-specific risk factors
-
D
A custom baseline built from scratch without referencing existing baselines