Ratio Corp is implementing a suite of security controls from NIST SP 800-53 in its information system. The security team has identified that some of the controls require significant configuration or customization to meet organizational needs. What is the best course of action?