nerdexam
(ISC)2

CAP · Question #199

According to FIPS Publication 199, what are the three levels of potential impact on organizations in the event of a compromise on confidentiality, integrity, and availability?

The correct answer is D. Low, Moderate, and High. FIPS Publication 199 (Standards for Security Categorization of Federal Information and Information Systems) defines three levels of potential impact that a security breach could have on an organization's operations, assets, or individuals: Low, Moderate, and High. These levels…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

According to FIPS Publication 199, what are the three levels of potential impact on organizations in the event of a compromise on confidentiality, integrity, and availability?

Options

  • AConfidential, Secret, and High
  • BMinimum, Moderate, and High
  • CLow, Normal, and High
  • DLow, Moderate, and High

How the community answered

(33 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    94% (31)

Explanation

FIPS Publication 199 (Standards for Security Categorization of Federal Information and Information Systems) defines three levels of potential impact that a security breach could have on an organization's operations, assets, or individuals: Low, Moderate, and High. These levels apply to each of the three security objectives - confidentiality, integrity, and availability. The categorization drives the selection of appropriate security controls under NIST SP 800-53. The other answer choices either use incorrect terminology ('Minimum' instead of 'Low,' 'Normal' instead of 'Moderate,' or include non-standard terms like 'Confidential' and 'Secret' which are data classification labels, not impact levels).

Topics

#FIPS 199#Impact Levels#CIA Triad

Community Discussion

No community discussion yet for this question.

Full CAP Practice