CGRC · Question #504
What is the four-step security categorization process? Response:
The correct answer is A. 1. Identify Information Types. The first step in the four-step security categorization process is to identify the information types handled by the system.
Question
What is the four-step security categorization process? Response:
Options
- A
- Identify Information Types
- B
- Review Provisional Impact Levels And Adjust/Finalize Information Impact Levels
- C
- Select Provisional Impact Levels For The Information Types
- D
- Identify Information Types
How the community answered
(48 responses)- A88% (42)
- B6% (3)
- C2% (1)
- D4% (2)
Why each option
The first step in the four-step security categorization process is to identify the information types handled by the system.
The security categorization process, as defined by NIST, begins with identifying the various types of information (e.g., PII, financial, medical) that an information system processes, stores, or transmits. This initial step is crucial for accurately assessing potential impact levels later on.
Reviewing provisional impact levels is a later step, occurring after initial impact levels have been selected.
Selecting provisional impact levels is the second step, following the identification of information types.
This choice is a duplicate of option A, confirming it as the correct first step.
Concept tested: NIST Security Categorization Process - Step 1
Source: https://csrc.nist.gov/publications/detail/fips/199/final
Topics
Community Discussion
No community discussion yet for this question.