Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Cross-Framework Defense Map

PL-10 — Baseline Selection

Trace this SP 800-53 control to NIST CSF outcomes, CUI requirements, D3FEND defensive techniques, ATT&CK relationships, and related learning resources.

PL — Planning · NIST SP 800-53 Release 5.2.0

Open the complete control page →
NIST SP 800-53 control context

PL-10 — Baseline Selection

Control baselines are predefined sets of controls specifically assembled to address the protection needs of a group, organization, or community of interest. Controls are chosen for baselines to either satisfy mandates imposed by laws, executive orders, directives, regulations, policies, standards, and guidelines or address threats common to all users of the baseline under the assumptions specific to the baseline. Baselines represent a starting point for the protection of individuals’ privacy, information, and information systems with subsequent tailoring actions to manage risk in accordance with mission, business, or other constraints (see [PL-11](#pl-11) ). Federal control baselines are provided in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) . The selection of a control baseline is determined by the needs of stakeholders. Stakeholder needs consider mission and business require

Read the official statement, discussion, parameters, enhancements, and assessment methods →

Outcome layer

NIST CSF 2.0 informative references

These CSF Subcategories list this base control or one of its enhancements in the imported NIST informative reference.

No relationship is present in the currently imported source datasets.
CUI protection layer

NIST SP 800-171 and SP 800-172

SP 800-171 requirements sourcing this control

No relationship is present in the currently imported source datasets.

SP 800-172 enhanced requirements sourcing this control

No relationship is present in the currently imported source datasets.
Defensive engineering layer

MITRE D3FEND techniques

No relationship is present in the currently imported source datasets.
Adversary layer

MITRE ATT&CK relationships

Curated mitigation mappings

No relationship is present in the currently imported source datasets.

Inferred behavior relationships

Experimental: These relationships are inferred through D3FEND and must be validated against architecture, telemetry, and threat context.

No relationship is present in the currently imported source datasets.
Relationship boundaries

Use the map without overclaiming.

A CSF informative reference is not an equivalence statement. A source-control relationship is not proof of implementation. A D3FEND semantic relationship is not a product claim. An inferred ATT&CK link is a hypothesis for engineering analysis.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.