Skip to main content
Category: Controls Management

Select

Simply put

To select means to choose something from a number or group, typically on the basis of fitness, preference, or quality. As an adjective, "select" can also describe something specially chosen or of superior quality. The term has no distinct GRC-specific meaning in the evidence provided here.

Formal definition

In general usage, "select" (verb) means to choose one or more items in preference to others from a larger set, commonly by criteria such as fitness or excellence; as an adjective it denotes items that are specially chosen or of superior quality. The evidence packet supplies only general-dictionary definitions and does not document a specialized governance, risk, and compliance meaning. Practitioners should note that "Select" is used as a formal phase name in some frameworks, for example, it is commonly cited as a step within the NIST Risk Management Framework concerning the selection of security controls, but that specific usage is not attested in the sources cited below and would require framework documentation to define precisely.

Why it matters

"Select" is primarily a general-language term meaning to choose from a larger set on the basis of fitness, preference, or quality, or as an adjective, to denote something specially chosen or of superior quality. The evidence available here supplies only general-dictionary definitions and does not, on its own, establish a specialized governance, risk, and compliance meaning. For a professional reference, the significance of the term is therefore mostly a matter of precision: practitioners should be careful not to read GRC-specific weight into a word that, in most contexts, is doing ordinary work.

Who it's relevant to

Compliance and policy writers
Those drafting policies, standards, and procedures should use "select" in its plain sense of choosing from options and avoid implying a specialized meaning unless a named framework phase is genuinely intended. Where a framework term such as a named 'Select' step is referenced, the writer should cite the framework directly rather than rely on general usage.
GRC framework practitioners
Practitioners working with structured frameworks may encounter "Select" as a formal phase name, for example in connection with selecting security controls within the NIST Risk Management Framework. They should confirm the precise definition against the applicable framework documentation, as that specialized usage is not established by the general sources underlying this entry.
Editors and reference readers
Readers consulting this glossary for a GRC-specific meaning should note that, based on the evidence provided here, "Select" carries only its general-language sense. Any framework-specific interpretation depends on the surrounding context and the issuing body's own text.

Inside Select

Select step (NIST RMF)
In the NIST Risk Management Framework, described in NIST Special Publication 800-37 (Revision 2), 'Select' is the formally named step in which an organization selects an initial set of security and privacy controls for an information system and its environment of operation. It follows the Categorize step and precedes the Implement step. NIST publications are issued by the U.S. National Institute of Standards and Technology and are most directly applicable to U.S. federal agencies and organizations within their scope.
Baseline control selection
Within the Select step, organizations commonly begin from a control baseline appropriate to the system's categorization and then tailor it. The catalog of controls from which selections are drawn is maintained separately (NIST SP 800-53). This entry does not reproduce specific control identifiers or catalog contents.
Tailoring
The process of adjusting a selected baseline to reflect the organization's specific conditions, such as applicable overlays, compensating controls, or scoping considerations. Tailoring is part of documenting selected controls but the precise tailoring guidance and any parameter values vary by organization and system.
Documentation of selected controls
The Select step commonly culminates in documenting the chosen controls, for example within a security and privacy plan. This entry does not specify document formats, templates, or tooling.

Common questions

Answers to the questions practitioners most commonly ask about Select.

Does 'Select' in a GRC context refer to segregation of duties or some access-control concept?
No. 'Select' is not a synonym for segregation of duties, nor is it primarily an access-control term in governance, risk, and compliance usage. Its most recognized specialized meaning is as the name of a phase within a risk management process framework. Conflating it with segregation of duties or user-provisioning concepts is a common error that should be avoided.
Is 'Select' just a generic English verb with no defined meaning in GRC frameworks?
Not entirely. While 'select' is of course an ordinary verb, it also has a formal, capitalized usage within the NIST Risk Management Framework, where 'Select' names one of the framework's defined steps. In that context it is a recognized phase name rather than an informal term, so practitioners should read it as a defined step when it appears within NIST RMF materials.
Where does the 'Select' step appear within the NIST Risk Management Framework?
In NIST's Risk Management Framework, as described in NIST SP 800-37 Revision 2 issued by the National Institute of Standards and Technology, 'Select' is one of the defined steps and concerns selecting the security and privacy controls appropriate to the system and its environment. It typically follows the categorization of the system. Note that this usage applies chiefly to U.S. federal information systems and organizations that adopt the framework voluntarily; it is not a universal GRC obligation across all jurisdictions.
How does the 'Select' step relate to the other steps in the framework?
Within the NIST RMF, 'Select' commonly follows categorization of the information system and precedes the implementation and assessment of the chosen controls. It is one step in a sequence rather than a standalone activity, and its output, a set of selected controls, feeds subsequent implementation and assessment work. Practitioners should treat it as part of an iterative lifecycle rather than a one-time event, as selections may be revisited as systems and risks change.
Who is typically responsible for carrying out the 'Select' step?
Responsibility varies by organization and jurisdiction, and the framework describes roles rather than prescribing a single job title. In practice, control selection is generally a management activity performed by those accountable for the system and its risk posture, often with input from security and privacy specialists. This is distinct from independent assurance functions, which evaluate rather than perform control selection; keeping that management-versus-assurance distinction clear supports objectivity.
What does this entry not cover regarding the 'Select' step?
This entry defines the term conceptually and does not provide implementation specifics, control catalog details, clause or control identifiers, tooling recommendations, or legal advice. It also does not address how selection requirements may differ across sectors or non-U.S. jurisdictions in detail. Practitioners should consult the applicable framework documentation and, where relevant, qualified legal or compliance advisors for authoritative and current requirements.

Common misconceptions

'Select' is a generic English verb with no defined meaning in GRC frameworks.
Within the NIST Risk Management Framework, as described in NIST SP 800-37 Revision 2, 'Select' is a formally named step of the framework referring specifically to selecting security and privacy controls. It is a recognized phase name in a core U.S. federal GRC framework, not merely a general term.
The Select step means controls are finalized and operating once chosen.
Selecting controls is distinct from implementing and assessing them. In the NIST RMF sequence, Select is followed by separate Implement and Assess steps. Choosing a control does not by itself provide assurance that it is in place or operating effectively; that determination belongs to later steps and to assessment activities.
The NIST RMF Select step applies universally to all organizations.
The NIST Risk Management Framework is issued by the U.S. National Institute of Standards and Technology and is most directly applicable to U.S. federal information systems and organizations within their scope. Other jurisdictions and sectors may use different frameworks, and applicability depends on context.

Best practices

When using the term 'Select' in a GRC context, clarify whether you mean the formally named step of the NIST Risk Management Framework (NIST SP 800-37 Rev. 2) or a general reference, to avoid ambiguity.
Base control selection on the system's prior categorization, drawing from an appropriate control baseline before tailoring rather than selecting controls in isolation.
Document the rationale for tailoring decisions, including any scoping, overlays, or compensating controls, so selections are traceable and defensible.
Treat selection as distinct from implementation and assessment; do not assume a selected control is operating until it has been implemented and independently assessed.
Confirm the applicability of the NIST RMF to your jurisdiction, sector, and organizational scope before adopting its steps, since other frameworks may govern your obligations.
Consult the current NIST publications directly for specific baselines, control identifiers, and tailoring guidance rather than relying on summarized definitions, as these details vary and are updated over time.
Promotional banner for the Penetration Report Template Kit