CNSSI 1253 is the Committee on National Security Systems instruction that governs how federal agencies categorize National Security Systems and select the security controls that protect them. It covers two specific steps of the Risk Management Framework, Categorize and Select, and adapts the standard federal cybersecurity catalog to the stricter demands of classified, military, and intelligence environments. Everything else about running a National Security System, from implementation through monitoring, sits under other publications.
What Systems It Applies To
CNSSI 1253 only applies to systems that meet the statutory definition of a National Security System under 44 U.S.C. 3552. That statute captures information systems used by a federal agency, a contractor, or another organization on the agency’s behalf when the system involves intelligence or cryptologic activities, command and control of military forces, integral weapon-system functions, direct support of military or intelligence missions, or the handling of classified information protected under an Executive Order or Act of Congress.1Office of the Law Revision Counsel. 44 U.S.C. 3552 – Definitions The Department of Defense uses the same criteria through 10 U.S.C. 2315.2Legal Information Institute. 10 U.S.C. 2315 – National Security System
The statute carves out routine business systems. Payroll, finance, logistics, and personnel applications do not qualify as National Security Systems even when a defense agency operates them. Systems that fall outside the definition follow standard FISMA and NIST guidance instead. Systems that fall inside it face CNSSI 1253 and the broader CNSS policy framework, including CNSSP 22, which requires every organization owning or operating a National Security System to run a risk management program.3Committee on National Security Systems. CNSSP 22 – National Information Assurance Policy on Risk Management
How Categorization Works
Categorization under CNSSI 1253 uses the structure of FIPS 199. Each system is rated on three security objectives: confidentiality (preventing unauthorized disclosure), integrity (preventing unauthorized modification or destruction), and availability (keeping the system accessible when needed). Each objective gets its own rating of low, moderate, or high, based on how severe the consequences would be if that objective were compromised.4NIST. FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems
Low means limited harm. Moderate means serious harm to the mission, to assets, or to individuals. High means severe or catastrophic consequences: the kind that could cripple military readiness, expose intelligence sources, or endanger lives. CNSSI 1253 tightens the FIPS 199 definitions of moderate and high specifically for the national security context.5Committee on National Security Systems. CNSSI 1253 – Security Categorization and Control Selection for National Security Systems
No High Water Mark
This is where CNSSI 1253 diverges most sharply from standard federal practice. Under FIPS 200, a non-national-security system’s overall category is set at the highest impact level across the three objectives. High confidentiality with low integrity and low availability produces a high-impact system, full stop. That is the high water mark.
CNSSI 1253 rejects that approach. All three impact values stay separate. A system can be categorized as high confidentiality, moderate integrity, and low availability, and it will be treated as exactly that triple, not rolled up to high.5Committee on National Security Systems. CNSSI 1253 – Security Categorization and Control Selection for National Security Systems The granularity drives more precise control selection. A satellite communications system may need extreme confidentiality protections while tolerating moderate availability because backup channels exist. Forcing every objective up to the highest rating would trigger controls that address risks the system does not actually have.
Categorization begins at the information-type level. Agencies evaluate the worst-case impact if each type of information the system handles were disclosed, altered, or made unavailable. Those findings then aggregate to the system level, and because there is no high water mark, the aggregation preserves separate values for each objective.
How Controls Are Selected
CNSSI 1253 does not maintain its own catalog of security controls. It draws from NIST SP 800-53, the government-wide catalog covering access management, incident response, auditing, and every other security discipline. What CNSSI 1253 supplies is the baselines (the minimum sets of controls tied to each impact rating) and the parameter values calibrated for national security use. Where the two documents conflict, CNSSI 1253 controls for National Security Systems.6Committee on National Security Systems. CNSSI 1253 – Categorization and Control Selection for National Security Systems
Because the three impact values stay separate, the baseline is more targeted than the single-rating baselines used elsewhere in the federal government. Each impact level for each objective maps to a specific group of controls.
Baselines rarely address every risk a specific system faces. Overlays fill the gap. An overlay is a pre-built set of control adjustments for a particular technology, environment, or mission. It adds controls the baseline missed, removes ones that do not fit, and modifies others to match operational reality. CNSSI 1253 publishes several as independent attachments:
- Space Platform Overlay, for satellite and orbital systems
- Cross Domain Solution Overlay, for systems that move data between networks at different classification levels
- Intelligence Overlay, for intelligence community systems
- Classified Information Overlay, for any system processing classified data
- Privacy Overlay, for protections around personally identifiable information
Overlays are updated on their own schedules, so agencies check the CNSS site periodically for revisions.5Committee on National Security Systems. CNSSI 1253 – Security Categorization and Control Selection for National Security Systems
After overlays, security teams tailor the resulting control set to the specific system, documenting every addition, removal, or adjustment in the system security plan. That plan then becomes the authoritative record of what protections are in place and why. Weak tailoring documentation causes real problems at assessment, because assessors will test against exactly what the plan says.
Where CNSSI 1253 Stops
The Risk Management Framework has seven steps: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.7NIST. About the RMF CNSSI 1253 governs only Categorize and Select. Implementation, assessment, authorization, and continuous monitoring for National Security Systems run under other publications, primarily NIST SP 800-37 for the overall lifecycle and CNSSP 22 for the risk management program requirement. The instruction shapes what protections a system must have; it does not walk agencies through building, testing, authorizing, or watching them over time.
Revision 5 Additions
Revision 5 of the underlying NIST SP 800-53 catalog introduced two control families that CNSSI 1253 Revision 5 carried into the National Security System baselines.
Personally Identifiable Information
The Personally Identifiable Information Processing and Transparency family consolidated privacy protections that earlier revisions handled in scattered form. The controls require agencies to document the legal authority for processing personal data, restrict processing to identified purposes, provide notice, and manage consent. CNSSI 1253 Revision 5 added a privacy control baseline, acknowledging that defense and intelligence systems sometimes process personal information and need structured protections for it.8Department of Navy Chief Information Officer. Adoption of NIST SP 800-53 and CNSSI 1253 Revision 5
Supply Chain Risk Management
The Supply Chain Risk Management family addresses compromised hardware or software entering a system before deployment. Agencies must develop supply chain risk management plans, track component provenance, assess suppliers, and implement tamper detection. On a National Security System, where a single manipulated chip or firmware update can cause outsized damage, this family fills gaps that earlier revisions handled loosely.8Department of Navy Chief Information Officer. Adoption of NIST SP 800-53 and CNSSI 1253 Revision 5
Reciprocity Between Agencies
Part of the reason CNSSI 1253 is built on the same NIST foundation as the rest of the federal government is reciprocity: if one agency authorizes a system, another should be able to accept that authorization instead of starting over. CNSS worked with NIST specifically to make this possible.5Committee on National Security Systems. CNSSI 1253 – Security Categorization and Control Selection for National Security Systems In practice, reciprocity is aspirational more than automatic. Receiving agencies typically review the authorization package themselves, and differences in overlays or tailoring decisions between agencies can complicate acceptance. The shared control language and categorization methodology still make the process far more workable than it was when agencies operated on separate frameworks.