When implementing frameworks like NIST SP 800-53, organisations adapt baseline controls through two distinct phases: scoping and tailoring. The CISSP exam frequently tests whether candidates understand the difference.
Key Insight
Scoping is a binary yes or no decision about whether a control applies to your environment. Tailoring comes after, customising how the applicable controls are implemented. No mainframes? Scope out the mainframe controls. Need stronger passwords? Tailor the password policy.
Think Like a Manager
Sequence matters. Ask “does this control apply?” before “how should we implement it?” Scoping eliminates irrelevant controls first, then tailoring adjusts the rest. It is the same discipline that runs through all of Domain 1: establish what is in scope before spending effort on how, just as RPO, RTO, WRT and MTD are set from business impact before any recovery technology is chosen.
Quick Comparison
| Aspect | Scoping | Tailoring |
|---|---|---|
| Decision | Binary (yes or no) | Parameter adjustment |
| Question | Does this apply? | How do we implement it? |
| Order | First | Second |
| Example | Removing ICS controls (no ICS exists) | Changing password length to 16 characters |
Exam distractors often confuse scoping with risk prioritisation or documentation. Remember: scoping is purely about environmental applicability.
Distinctions this fine are where near misses happen on exam day. Our CISSP practice tests drill scoping vs tailoring and dozens of similar pairings until they are automatic.