An organization is implementing controls for a newly classified moderate-impact system. The security engineer notes that NIST SP 800-53 provides a baseline, but some controls seem unnecessary given the system's unique operating environment. What is the MOST appropriate next step?
-
A
Implement all baseline controls exactly as specified without modification
-
B
Tailor the control baseline by documenting justifications for any additions, removals, or modifications
-
C
Remove any controls that appear redundant and proceed to assessment
-
D
Request a waiver from the authorizing official to skip the tailoring process