Scoping and Tailoring

When choosing to implement security frameworks, baselines, or standards, organizations may decide to implement only specific parts through the process of scoping and tailoring.

3 slides · 2 min read · Domain 2

Slide 1

Scoping is defined as limiting the general

Tailoring involves scoping the assessment procedures to match the characteristics of baseline recommendations by removing those that do not apply. We "scope" to | an organization's information system and ensure the baseline control applies to the its environment of operation more closely. The tailoring process gives enterprises environment as best as it can. Tailoring is defined as altering baseline control the flexibility needed to avoid complex recommendations to apply controls specific and costly assessments while meeting to the technology or environment. To scope the requirements established by applying and tailor, a thorough understanding of the a risk management framework. Adding environment and risks is necessary. assessment procedures or specific details, such as system- or platform-specific

Scoping guidance provides an enterprise information for selected controls, may be with specific terms and conditions on the necessary to address the organization's risk applicability and implementation of individual management needs. Such supplementation security controls. Several considerations decisions are made by the organization, can potentially impact how baseline security allowing flexibility in developing security controls are applied by the enterprise.

assessment plans based on the risk assessment results to determine the scope, rigor, and level of intensity of the assessments.

Recognize the value that scoping, tailoring, System security plans should and supplementation can bring to the clearly identify which security security architectures being planned and

controls employed scoping

assessed for the enterprise. The use of

guidance and include a description

scoping and tailoring to properly narrow of the type of considerations made. the focus of the architecture will ensure that the appropriate risks are identified and addressed based on requirements.

The application of scoping guidance must be

The use of supplementation helps the reviewed and approved by the authorizing architecture remain flexible over time and official for the information system in adapt to the enterprise's evolving needs question.

during and after full implementation.

Test this domain