Security Categorization Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security Categorization flashcards as text
What is the security categorization format specified in FIPS 199?
Answer: SC = {(confidentiality, impact), (integrity, impact), (availability, impact)}
FIPS 199 specifies the format as SC information type = {(confidentiality, impact level), (integrity, impact level), (availability, impact level)}.
What triggers the need to recategorize a federal information system?
Answer: Significant changes to the information processed, mission requirements, or operating environment
Recategorization is needed when the types of information processed, mission requirements, or operational context change significantly enough to alter the system's risk profile.
Which role is primarily responsible for completing the security categorization of an information system?
Answer: System Owner, in coordination with the ISSO and data owners
The System Owner leads the categorization process in collaboration with the ISSO and information owners to ensure all data types are properly accounted for.
What does a High categorization for Availability mean for a federal system?
Answer: Loss of availability would have a severe or catastrophic adverse effect on operations, assets, or individuals
A High Availability impact means system downtime could cause severe harm to the organization's mission, finances, or national security.
Which mission-based information type from NIST SP 800-60 typically receives a High Confidentiality categorization?
Answer: Intelligence data and law enforcement sensitive information
Information types like intelligence and law enforcement sensitive data typically warrant High confidentiality due to the severe harm from unauthorized disclosure.
What FIPS standard defines the minimum security requirements based on the impact level determined by FIPS 199?
Answer: FIPS 200
FIPS 200 specifies the minimum security requirements for each impact level category established by FIPS 199.