nerdexam
(ISC)2

CGRC · Question #336

According to FIPS Publication 199, what are the three levels of potential impact on organizations in the event of a compromise on confidentiality, integrity, and availability? Response:

The correct answer is D. Low, Moderate, and High. FIPS Publication 199 establishes three standard impact levels - Low, Moderate, and High - to categorize the potential impact on organizations should the confidentiality, integrity, or availability of their information systems be compromised.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

According to FIPS Publication 199, what are the three levels of potential impact on organizations in the event of a compromise on confidentiality, integrity, and availability? Response:

Options

  • AConfidential, Secret, and High
  • BMinimum, Moderate, and High
  • CLow, Normal, and High
  • DLow, Moderate, and High

How the community answered

(67 responses)
  • A
    6% (4)
  • B
    1% (1)
  • C
    3% (2)
  • D
    90% (60)

Why each option

FIPS Publication 199 establishes three standard impact levels - Low, Moderate, and High - to categorize the potential impact on organizations should the confidentiality, integrity, or availability of their information systems be compromised.

AConfidential, Secret, and High

"Confidential" and "Secret" are classification levels for national security information, not impact levels defined by FIPS 199 for C-I-A.

BMinimum, Moderate, and High

"Minimum" is not an impact level defined in FIPS 199; the correct lowest impact level is Low.

CLow, Normal, and High

"Normal" is not an impact level defined in FIPS 199; the correct intermediate impact level is Moderate.

DLow, Moderate, and HighCorrect

FIPS Publication 199, "Standards for Security Categorization of Federal Information and Information Systems," specifically defines the three levels of potential impact on an organization in the event of a compromise to confidentiality, integrity, or availability as Low, Moderate, and High. These levels are fundamental for categorizing information systems within the NIST Risk Management Framework.

Concept tested: FIPS 199 impact levels

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#FIPS 199#Impact Levels#CIA Triad#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice