Step 2 — Choosing the Right Controls: Profile Selection and Control Tailoring
A profile is a starting point, not a finished control set — and tailoring is where most of the defensible judgment in an assessment actually happens
Categorization produced a level. This step turns that level into the specific list of controls the assessment will test.
Most teams treat it as a lookup: find the profile, copy the list, start. That is the one approach guaranteed to produce a control set that is wrong for the system — too heavy where the profile assumed things you do not have, too light where your threat or your contract adds obligations the profile never knew about.
Tailoring is not weakening a baseline. It is making a generic baseline true for a specific system — and writing down why.
Where Profiles Come From#
Name the actual artifacts:
| Source | What it is |
|---|---|
| ITSP.10.033-01 | The Cyber Centre's suggested organizational security and privacy control and activity profile, Medium impact3 |
| ITSG-33 Annex 4A | The older Protected B / Medium / Medium profile — superseded by ITSP.10.033-01, still published4 |
| NIST SP 800-53B | The American baselines and overlays, if your framework is RMF6 |
ITSP.10.033 superseded ITSG-33 Annex 3A — the control catalogue — on 31 March 2026, and ITSP.10.033-01 states that it supersedes Annex 4A Profile 1, the Protected B / Medium / Medium profile, with effect from 2 April 2026.3 The Annex 4A pages remain published.5 Which profile your department actually uses varies; confirm it rather than assume. The catalogue-level differences are in ITSP.10.033 vs NIST SP 800-53.
What Tailoring Is#
NIST defines it precisely, and the definition is a checklist of the moves available to you:
The process by which security control baselines are modified by: identifying and designating common controls, applying scoping considerations on the applicability and implementation of baseline controls, selecting compensating security controls, assigning specific values to organization-defined security control parameters, supplementing baselines with additional security controls or control enhancements, and providing additional specification information for control implementation.
NIST SP 800-53 Rev. 5, via the NIST glossarySix moves.1 Designate what is common or inherited. Scope out what does not apply. Substitute where the control cannot be met as written. Set the parameters. Add what the baseline lacks. Specify how it will be done. Most tailoring exercises use the second move and ignore the other five.
Scroll sideways to see the full diagram →
Tailoring Down#
"Not applicable" is legitimate and frequently correct. A media protection control on a system with no removable media. A wireless control on a system with no wireless. A deployment-model control for a model you do not use.
It is also the most abused result in assessment. The test:
Tailoring Up#
The direction nobody does. Reasons to add controls or enhancements above the baseline:
- A threat environment the generic profile did not assume
- Legislation or a contract that imposes obligations the catalogue treats as optional
- A previous incident that showed a baseline control was insufficient here
- Canadian-specific enhancements — the 400-series in ITSP.10.033 is tailoring up at national scale5
A profile is a floor calibrated for a typical system. Yours is not typical in at least one way, and that way is usually where tailoring up belongs.
Control Parameters#
Many controls contain assignment and selection statements — a review frequency, a lockout threshold, a retention period — that the baseline leaves open on purpose.
An unfilled parameter makes a control unassessable. "Reviews occur at an organization-defined frequency" cannot be judged met or not met without the definition, so the assessor either invents one or asks in month four. Set them in Step 2, record where the value came from, and the assessment in Step 4 has a line to measure against.
Compensating Controls#
When the control as written cannot be implemented, a substitute has to meet the same objective, not merely sit adjacent to it.
A management, operational, and/or technical control employed by an organization in lieu of a recommended security control … that provides equivalent or comparable protection for an information system.
NIST SP 800-30 Rev. 1, via the NIST glossaryEquivalent or comparable.2 Require three things in the record: what the original control's intent was, how the substitute meets it, and what residual exposure remains. A compensating control without that third line is a gap wearing a label.
Recording the Justification#
The output of Step 2 is not the control list. It is the control list plus the reasoning.
- Control ID and titleWhat was decided about
- DecisionIn · out · modified · compensated · parameter set
- RationaleThe property of the system, obligation or threat that drove it
- Decided byA role, and a date
This record is assessment input in Step 4 and authorization input in Step 7. Without it, every decision is re-argued at assessment time by people who were not in the room when it was made.
Where CtrlFort Fits#
A tailoring record kept in a spreadsheet is accurate on the day it is made and fiction six months later — a control gets added in a workshop, a parameter changes in an email, and the spreadsheet is never told.
CtrlFort Assess holds the control set as the assessment's own structure. The framework and its controls are the objects the assessment is built on, and for every control, Control Intelligence carries the objective, the assessment criteria, the expected evidence and the assurance activities to perform — which is where a tailored requirement lives once it is decided, rather than in a file beside the work. Because requirements, controls, evidence and determinations are separate linked objects, CtrlFort can show an authorizer the chain from profile to result, and the assessment intelligence architecture keeps that chain consistent across every system assessed against the same profile.
The reasoning behind a tailoring decision is still a human's to write. What the platform does is make sure the control set the reasoning describes is the one the assessment actually runs against.
Final Thoughts#
The profile is what the catalogue assumed. The tailored set is what is true. The record of the difference is what makes the assessment defensible.
Previous: Step 1 — Security Categorization and Assessment Scoping · Next: Step 3 — Control Responses and Evidence Collection
Frequently Asked Questions#
What is the difference between a profile, a baseline and an overlay?#
A baseline is a generic control set for an impact level. A profile is the Canadian term for the same thing, sometimes pre-tailored for a context. An overlay is a NIST term for a documented set of modifications applied on top of a baseline for a particular technology or mission.
When is "not applicable" a legitimate result?#
When a property of the system removes what the control protects — no removable media, no wireless, no external users. It is never legitimate because the control is inconvenient, and the justification should name the property.
Who approves a tailoring decision?#
Security, with the system owner. The delivery team proposes; it should not be the only voice, because its incentives run toward a smaller control set. Record who approved each decision by role.
Do we have to use ITSP.10.033-01, or can we build our own profile?#
Departments can and do build their own, typically starting from a published profile and tailoring for their context. What matters is that the profile is derived from the categorization, the tailoring is justified, and the record of both exists.
References#
- Tailoring — glossary entry, citing NIST SP 800-53 Rev. 5 ↩National Institute of Standards and Technology · https://csrc.nist.gov/glossary/term/tailoring
- Compensating Security Control — glossary entry, citing NIST SP 800-30 Rev. 1 ↩National Institute of Standards and Technology · https://csrc.nist.gov/glossary/term/compensating_security_control
- ITSP.10.033-01 — Suggested organizational security and privacy control and activity profile, Medium impact ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/suggested-organizational-security-privacy-control-activity-profile-medium-impact-itsp10033-01
- ITSG-33 Annex 4A — Profile 1 (Protected B / Medium / Medium) ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/annex-4a-profile-1-protected-b-medium-integrity-medium-availability-itsg-33
- ITSP.10.033 — Security and privacy controls and assurance activities catalogue ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033
- NIST SP 800-53B — Control Baselines for Information Systems and Organizations ↩National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/53/b/upd1/final