← All CAP Flashcard Decks

Security Categorization Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Security Categorization flashcards as text
  1. How does security categorization drive the selection of security control baselines in NIST SP 800-53?

    Answer: The impact level (Low/Moderate/High) maps directly to a corresponding control baseline in SP 800-53

    NIST SP 800-53 defines Low, Moderate, and High baselines that align with the system impact levels established through FIPS 199 categorization.

  2. What is the relationship between a Privacy Threshold Analysis (PTA) and security categorization?

    Answer: A PTA determines if PII is present in the system, which can affect the categorization of confidentiality

    A PTA identifies whether a system contains PII, and the presence of PII may elevate the Confidentiality impact level during categorization.

  3. A healthcare system processes patient records and payment data. Which security objective is most likely to have the highest impact level?

    Answer: Confidentiality

    Patient and payment records are highly sensitive, making unauthorized disclosure the greatest concern and driving a High Confidentiality impact.

  4. What does it mean to 'adjust' a recommended information type impact level from NIST SP 800-60?

    Answer: To raise or lower the recommended level based on the specific operational context and risk environment

    Agencies may adjust recommended impact levels up or down when local factors, mission context, or threat environment justify a different level than the default.

  5. Which OMB policy requires federal agencies to conduct security categorization of their information systems?

    Answer: OMB Circular A-130

    OMB Circular A-130 mandates that federal agencies categorize information systems and implement controls commensurate with risk.

  6. Why is it important to include ALL information types processed by a system when conducting FIPS 199 categorization?

    Answer: Because missing an information type could result in under-categorization and insufficient security controls

    Failing to account for all information types risks missing a high-impact type, leading to inadequate controls that leave the system vulnerable.