nerdexam
(ISC)2

CGRC · Question #34

The security category of information 1 is determined to be: Confidentiality, low; Integrity, moderate; and availability, Moderate. The security category for information 2 is determined to be…

The correct answer is D. Security Category information type = (confidentiality, LOW), (integrity, MODERATE), (availability. To determine the overall security category, the highest impact level for each security objective (confidentiality, integrity, availability) across all information types is selected.

Scope of the System

Question

The security category of information 1 is determined to be: Confidentiality, low; Integrity, moderate; and availability, Moderate. The security category for information 2 is determined to be:

confidentiality, Not Applicable, Integrity, Low; and availability, Moderate. What is the overall security category? Response:

Options

  • ASecurity Category information type = (confidentiality, NOT APPLICABLE), (integrity, LOW),
  • BSecurity Category information type = (confidentiality, LOW), (integrity, LOW), (availability,
  • CSecurity Category information type = (confidentiality, NOT APPLICABLE), (integrity, MODERATE),
  • DSecurity Category information type = (confidentiality, LOW), (integrity, MODERATE), (availability,

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    14% (7)
  • C
    6% (3)
  • D
    76% (38)

Why each option

To determine the overall security category, the highest impact level for each security objective (confidentiality, integrity, availability) across all information types is selected.

ASecurity Category information type = (confidentiality, NOT APPLICABLE), (integrity, LOW),

This choice incorrectly sets confidentiality to 'NOT APPLICABLE' when Information 1 has a 'LOW' impact for confidentiality.

BSecurity Category information type = (confidentiality, LOW), (integrity, LOW), (availability,

This choice incorrectly sets integrity to 'LOW' when Information 1 has a 'MODERATE' impact for integrity.

CSecurity Category information type = (confidentiality, NOT APPLICABLE), (integrity, MODERATE),

This choice incorrectly sets confidentiality to 'NOT APPLICABLE' when Information 1 has a 'LOW' impact for confidentiality.

DSecurity Category information type = (confidentiality, LOW), (integrity, MODERATE), (availability,Correct

When combining security categories for multiple information types, the overall category for each security objective (confidentiality, integrity, availability) is determined by selecting the highest impact level assigned across all types. For confidentiality, Information 1 is 'low' and Information 2 is 'Not Applicable', so the highest is 'low'. For integrity, Information 1 is 'moderate' and Information 2 is 'low', so the highest is 'moderate'. For availability, both are 'moderate', so the highest is 'moderate'. This results in an overall category of (confidentiality, LOW), (integrity, MODERATE), (availability, MODERATE).

Concept tested: Information system security categorization (NIST)

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf

Topics

#Security Categorization#CIA Triad#Information Classification#FIPS 199

Community Discussion

No community discussion yet for this question.

Full CGRC Practice