nerdexam
(ISC)2

CGRC · Question #280

Can a value of not applicable be assigned to any security objective in the context of establishing a security category for an information system. Response:

The correct answer is A. NO. A "not applicable" value cannot be assigned to any security objective (Confidentiality, Integrity, Availability) when establishing a security category for an information system, as all three must be addressed.

Scope of the System

Question

Can a value of not applicable be assigned to any security objective in the context of establishing a security category for an information system. Response:

Options

  • ANO
  • BYes

How the community answered

(18 responses)
  • A
    89% (16)
  • B
    11% (2)

Why each option

A "not applicable" value cannot be assigned to any security objective (Confidentiality, Integrity, Availability) when establishing a security category for an information system, as all three must be addressed.

ANOCorrect

According to FIPS 199, all three security objectives-Confidentiality, Integrity, and Availability-must be considered and assigned an impact level (Low, Moderate, or High) when establishing a security category for an information system. It is not permissible to assign "not applicable" to any of these objectives, as they represent fundamental aspects of information security that must always be evaluated.

BYes

Assigning "Yes" would imply that one or more of the core security objectives (Confidentiality, Integrity, Availability) could be deemed irrelevant for an information system, which contradicts established federal information security categorization standards like FIPS 199.

Concept tested: FIPS 199 security categorization principles

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#Security Categorization#Security Objectives#Information System Classification

Community Discussion

No community discussion yet for this question.

Full CGRC Practice