← All CAP Flashcard Decks

Security Categorization Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Security Categorization flashcards as text
  1. Which FIPS publication establishes the standards for categorizing federal information and information systems?

    Answer: FIPS 199

    FIPS 199 defines the standards for security categorization of federal information and information systems.

  2. What are the three potential impact levels defined by FIPS 199?

    Answer: Low, Moderate, High

    FIPS 199 defines Low, Moderate, and High as the three potential impact levels for each security objective.

  3. What NIST publication provides detailed guidance on mapping information types to security categories?

    Answer: NIST SP 800-60

    NIST SP 800-60 provides a guide for mapping types of information and information systems to security categories.

  4. How is the overall security category of an information system determined when multiple information types are present?

    Answer: By using the high-water mark — the highest impact value across all information types and objectives

    The high-water mark principle means the system's overall category is set to the highest impact level found among all information types for each security objective.

  5. A system is categorized as SC = {Confidentiality: High, Integrity: Moderate, Availability: Low}. What is the overall system impact level?

    Answer: High

    The overall system impact level is determined by the highest value across all three security objectives, which is High in this case.

  6. Which document should the system owner consult when determining information types for categorization?

    Answer: NIST SP 800-60 Volume II

    NIST SP 800-60 Volume II contains the tables that map federal information types to recommended security impact levels.