Security Architecture

Step 2 — Choosing the Right Controls: Profile Selection and Control Tailoring

A profile is a starting point, not a finished control set — and tailoring is where most of the defensible judgment in an assessment actually happens

Security ArchitectureGovernment of CanadaRisk & Compliance

Categorization produced a level. This step turns that level into the specific list of controls the assessment will test.

Most teams treat it as a lookup: find the profile, copy the list, start. That is the one approach guaranteed to produce a control set that is wrong for the system — too heavy where the profile assumed things you do not have, too light where your threat or your contract adds obligations the profile never knew about.

Tailoring is not weakening a baseline. It is making a generic baseline true for a specific system — and writing down why.

Where Profiles Come From#

Name the actual artifacts:

SourceWhat it is
ITSP.10.033-01The Cyber Centre's suggested organizational security and privacy control and activity profile, Medium impact3
ITSG-33 Annex 4AThe older Protected B / Medium / Medium profile — superseded by ITSP.10.033-01, still published4
NIST SP 800-53BThe American baselines and overlays, if your framework is RMF6

ITSP.10.033 superseded ITSG-33 Annex 3A — the control catalogue — on 31 March 2026, and ITSP.10.033-01 states that it supersedes Annex 4A Profile 1, the Protected B / Medium / Medium profile, with effect from 2 April 2026.3 The Annex 4A pages remain published.5 Which profile your department actually uses varies; confirm it rather than assume. The catalogue-level differences are in ITSP.10.033 vs NIST SP 800-53.

What Tailoring Is#

NIST defines it precisely, and the definition is a checklist of the moves available to you:

The process by which security control baselines are modified by: identifying and designating common controls, applying scoping considerations on the applicability and implementation of baseline controls, selecting compensating security controls, assigning specific values to organization-defined security control parameters, supplementing baselines with additional security controls or control enhancements, and providing additional specification information for control implementation.

NIST SP 800-53 Rev. 5, via the NIST glossary

Six moves.1 Designate what is common or inherited. Scope out what does not apply. Substitute where the control cannot be met as written. Set the parameters. Add what the baseline lacks. Specify how it will be done. Most tailoring exercises use the second move and ignore the other five.

From baseline to tailored control set Three columns: the baseline profile, the tailored set, and the justification. AC-2 account management is kept. MP-6 media sanitization is removed because the system has no removable media. SC-8 transmission confidentiality is kept. AU-6 audit review has its frequency parameter set to weekly by security policy. SR-3 supply chain controls, not in the baseline, is added because the system is third-party hosted under a contract obligation. IA-5 authenticator management is kept. Every change carries a recorded reason. FROM BASELINE TO TAILORED CONTROL SET — EVERY CHANGE CARRIES A REASON BASELINE PROFILE TAILORED SET JUSTIFICATION AC-2 Account management KEPT AC-2 Account management MP-6 Media sanitization REMOVED MP-6 Media sanitization No removable media in this system SC-8 Transmission confidentiality KEPT SC-8 Transmission confidentiality AU-6 Audit review [frequency] PARAMETER AU-6 Audit review Set to weekly by security policy — (not in baseline) ADDED SR-3 Supply chain controls Third-party hosted; contract obligation IA-5 Authenticator management KEPT IA-5 Authenticator management
Figure 1: A baseline becoming a tailored set. Every change carries a reason, because the assessor in Step 4 and the authorizer in Step 7 will both ask.

Scroll sideways to see the full diagram →

Tailoring Down#

"Not applicable" is legitimate and frequently correct. A media protection control on a system with no removable media. A wireless control on a system with no wireless. A deployment-model control for a model you do not use.

It is also the most abused result in assessment. The test:

Tailoring Up#

The direction nobody does. Reasons to add controls or enhancements above the baseline:

  • A threat environment the generic profile did not assume
  • Legislation or a contract that imposes obligations the catalogue treats as optional
  • A previous incident that showed a baseline control was insufficient here
  • Canadian-specific enhancements — the 400-series in ITSP.10.033 is tailoring up at national scale5

A profile is a floor calibrated for a typical system. Yours is not typical in at least one way, and that way is usually where tailoring up belongs.

Control Parameters#

Many controls contain assignment and selection statements — a review frequency, a lockout threshold, a retention period — that the baseline leaves open on purpose.

An unfilled parameter makes a control unassessable. "Reviews occur at an organization-defined frequency" cannot be judged met or not met without the definition, so the assessor either invents one or asks in month four. Set them in Step 2, record where the value came from, and the assessment in Step 4 has a line to measure against.

Compensating Controls#

When the control as written cannot be implemented, a substitute has to meet the same objective, not merely sit adjacent to it.

A management, operational, and/or technical control employed by an organization in lieu of a recommended security control … that provides equivalent or comparable protection for an information system.

NIST SP 800-30 Rev. 1, via the NIST glossary

Equivalent or comparable.2 Require three things in the record: what the original control's intent was, how the substitute meets it, and what residual exposure remains. A compensating control without that third line is a gap wearing a label.

Recording the Justification#

The output of Step 2 is not the control list. It is the control list plus the reasoning.

  1. Control ID and titleWhat was decided about
  2. DecisionIn · out · modified · compensated · parameter set
  3. RationaleThe property of the system, obligation or threat that drove it
  4. Decided byA role, and a date

This record is assessment input in Step 4 and authorization input in Step 7. Without it, every decision is re-argued at assessment time by people who were not in the room when it was made.

Where CtrlFort Fits#

A tailoring record kept in a spreadsheet is accurate on the day it is made and fiction six months later — a control gets added in a workshop, a parameter changes in an email, and the spreadsheet is never told.

CtrlFort Assess holds the control set as the assessment's own structure. The framework and its controls are the objects the assessment is built on, and for every control, Control Intelligence carries the objective, the assessment criteria, the expected evidence and the assurance activities to perform — which is where a tailored requirement lives once it is decided, rather than in a file beside the work. Because requirements, controls, evidence and determinations are separate linked objects, CtrlFort can show an authorizer the chain from profile to result, and the assessment intelligence architecture keeps that chain consistent across every system assessed against the same profile.

The reasoning behind a tailoring decision is still a human's to write. What the platform does is make sure the control set the reasoning describes is the one the assessment actually runs against.

Final Thoughts#

The profile is what the catalogue assumed. The tailored set is what is true. The record of the difference is what makes the assessment defensible.

Previous: Step 1 — Security Categorization and Assessment Scoping · Next: Step 3 — Control Responses and Evidence Collection

Frequently Asked Questions#

What is the difference between a profile, a baseline and an overlay?#

A baseline is a generic control set for an impact level. A profile is the Canadian term for the same thing, sometimes pre-tailored for a context. An overlay is a NIST term for a documented set of modifications applied on top of a baseline for a particular technology or mission.

When is "not applicable" a legitimate result?#

When a property of the system removes what the control protects — no removable media, no wireless, no external users. It is never legitimate because the control is inconvenient, and the justification should name the property.

Who approves a tailoring decision?#

Security, with the system owner. The delivery team proposes; it should not be the only voice, because its incentives run toward a smaller control set. Record who approved each decision by role.

Do we have to use ITSP.10.033-01, or can we build our own profile?#

Departments can and do build their own, typically starting from a published profile and tailoring for their context. What matters is that the profile is derived from the categorization, the tailoring is justified, and the record of both exists.

References#

  1. Tailoring — glossary entry, citing NIST SP 800-53 Rev. 5 National Institute of Standards and Technology · https://csrc.nist.gov/glossary/term/tailoring
  2. Compensating Security Control — glossary entry, citing NIST SP 800-30 Rev. 1 National Institute of Standards and Technology · https://csrc.nist.gov/glossary/term/compensating_security_control
  3. ITSP.10.033-01 — Suggested organizational security and privacy control and activity profile, Medium impact Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/suggested-organizational-security-privacy-control-activity-profile-medium-impact-itsp10033-01
  4. ITSG-33 Annex 4A — Profile 1 (Protected B / Medium / Medium) Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/annex-4a-profile-1-protected-b-medium-integrity-medium-availability-itsg-33
  5. ITSP.10.033 — Security and privacy controls and assurance activities catalogue Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/cyber-security-privacy-risk-management/itsp10033
  6. NIST SP 800-53B — Control Baselines for Information Systems and Organizations National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/53/b/upd1/final
On this page

Zeeshan Mahmood

Security Assessment, Architecture & AI

Zeeshan is a security advisor and senior IT security risk analyst who works at the seam between assessment and design. He runs the full authorization lifecycle — security categorization, threat and risk assessment, control profile selection, and the evidence behind an authority to operate — and designs the solution, cloud and security architecture that has to survive it, from landing zones and network segmentation to Zero Trust and cross-domain solutions. His current focus includes AI security and the assessment of AI-enabled systems. He holds CISSP, CCSP, CISM, CKS and Azure Solutions Architect Expert, and leads assurance methodology at CtrlFort.

Run this framework against your own control library.

CtrlFort Assess maps cloud control profiles, ITSG-33 baselines and certification regimes to one shared evidence base — so a control you evidence once satisfies every obligation it maps to.