CGRC · Question #34
The security category of information 1 is determined to be: Confidentiality, low; Integrity, moderate; and availability, Moderate. The security category for information 2 is determined to be…
The correct answer is D. Security Category information type = (confidentiality, LOW), (integrity, MODERATE), (availability. To determine the overall security category, the highest impact level for each security objective (confidentiality, integrity, availability) across all information types is selected.
Question
The security category of information 1 is determined to be: Confidentiality, low; Integrity, moderate; and availability, Moderate. The security category for information 2 is determined to be:
confidentiality, Not Applicable, Integrity, Low; and availability, Moderate. What is the overall security category? Response:
Options
- ASecurity Category information type = (confidentiality, NOT APPLICABLE), (integrity, LOW),
- BSecurity Category information type = (confidentiality, LOW), (integrity, LOW), (availability,
- CSecurity Category information type = (confidentiality, NOT APPLICABLE), (integrity, MODERATE),
- DSecurity Category information type = (confidentiality, LOW), (integrity, MODERATE), (availability,
How the community answered
(50 responses)- A4% (2)
- B14% (7)
- C6% (3)
- D76% (38)
Why each option
To determine the overall security category, the highest impact level for each security objective (confidentiality, integrity, availability) across all information types is selected.
This choice incorrectly sets confidentiality to 'NOT APPLICABLE' when Information 1 has a 'LOW' impact for confidentiality.
This choice incorrectly sets integrity to 'LOW' when Information 1 has a 'MODERATE' impact for integrity.
This choice incorrectly sets confidentiality to 'NOT APPLICABLE' when Information 1 has a 'LOW' impact for confidentiality.
When combining security categories for multiple information types, the overall category for each security objective (confidentiality, integrity, availability) is determined by selecting the highest impact level assigned across all types. For confidentiality, Information 1 is 'low' and Information 2 is 'Not Applicable', so the highest is 'low'. For integrity, Information 1 is 'moderate' and Information 2 is 'low', so the highest is 'moderate'. For availability, both are 'moderate', so the highest is 'moderate'. This results in an overall category of (confidentiality, LOW), (integrity, MODERATE), (availability, MODERATE).
Concept tested: Information system security categorization (NIST)
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf
Topics
Community Discussion
No community discussion yet for this question.