System Categorization & Impact Level Determination Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 System Categorization & Impact Level Determination flashcards as text
According to FIPS 199, which of the following correctly defines the 'HIGH' impact level for a security objective?
Answer: The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, assets, or individuals.
FIPS 199 defines HIGH impact as an expected severe or catastrophic effect, including loss of life, major financial loss, or inability to perform primary missions. LOW = limited effect; MODERATE = serious but not catastrophic.
An information system processes both MODERATE-confidentiality data and HIGH-integrity data. According to the 'high-water mark' principle in FIPS 199, what is the overall system categorization?
Answer: HIGH, because the highest individual impact level determines the overall categorization.
FIPS 199 requires using the 'high-water mark' — the overall system categorization equals the highest impact rating across all security objectives (confidentiality, integrity, availability). One HIGH rating makes the whole system HIGH.
Which NIST publication provides guidance for mapping information types to security impact levels during the categorization step of the RMF?
Answer: NIST SP 800-60
NIST SP 800-60 ('Guide for Mapping Types of Information and Information Systems to Security Categories') is the companion to FIPS 199 and provides the taxonomy of information types with recommended impact levels for each.
During system categorization, a hospital's patient-monitoring system that, if unavailable, could result in patient death would most likely have which availability impact rating?
Answer: HIGH
A system whose unavailability could directly cause loss of human life meets the FIPS 199 definition of HIGH impact (severe or catastrophic adverse effect on individuals). There is no fourth 'CRITICAL' tier in FIPS 199.
Who is ultimately responsible for signing the system categorization decision in a federal agency's RMF process?
Answer: The System Owner
NIST SP 800-37 assigns the System Owner the responsibility for categorizing the information system and documenting the result in the Security Plan. The AO reviews and approves authorization decisions, but categorization is the System Owner's formal responsibility.
Which of the following is a correct statement about the relationship between FIPS 199 and FIPS 200?
Answer: FIPS 199 establishes security categorization; FIPS 200 specifies minimum security requirements based on that categorization.
FIPS 199 defines the standards for categorizing information and information systems, while FIPS 200 specifies the minimum security requirements (tied to impact levels) that federal agencies must meet. They work sequentially: categorize first (199), then apply minimum requirements (200).