CGRC · Question #319
FIPS 199, Standards for Security Categorization of Federal Systems defines which 3 Security Categories? Response:
The correct answer is A. Confidentiality, Integrity, Availability. FIPS 199 defines Confidentiality, Integrity, and Availability as the three security categories for assessing the potential impact of information and information system compromise.
Question
FIPS 199, Standards for Security Categorization of Federal Systems defines which 3 Security Categories? Response:
Options
- AConfidentiality, Integrity, Availability
- BArchitectural descriptions & Organizational
- CSensitivity, Criticality, availability
- DFamiliarity, Sensitivity, Criticality
How the community answered
(26 responses)- A88% (23)
- B8% (2)
- D4% (1)
Why each option
FIPS 199 defines Confidentiality, Integrity, and Availability as the three security categories for assessing the potential impact of information and information system compromise.
FIPS 199, 'Standards for Security Categorization of Federal Information and Information Systems,' mandates the use of Confidentiality, Integrity, and Availability (CIA) as the three fundamental security objectives. These objectives form the basis for determining the potential impact (low, moderate, high) if information or information systems are compromised in terms of these categories.
Architectural descriptions and Organizational are elements of system documentation or structure, not the security categories defined by FIPS 199.
Sensitivity and Criticality are related concepts in information security but are not the fundamental security categories defined in FIPS 199; Availability is correct, but not in this combination.
Familiarity, Sensitivity, and Criticality are not the FIPS 199 security categories for impact assessment.
Concept tested: FIPS 199 Security Categories (CIA Triad)
Source: https://csrc.nist.gov/publications/detail/fips/199/final
Topics
Community Discussion
No community discussion yet for this question.