Purpose: Select, tailor, and document the controls necessary to protect the system and organization commensurate with risk
Outcomes:
FIPS 200, Minimum Security Requirements for Federal Information and Information Systems
NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations
NIST SP 800-53B, Control Baselines for Information Systems and Organizations
Security and Privacy: general security & privacy, privacy, risk management, security measurement, security programs & operations
Laws and Regulations: E-Government Act, Federal Information Security Modernization Act