CGRC · Question #532
In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete…
The correct answer is B. High C. Low D. Moderate. FIPS 199, developed by NIST, defines a three-tiered system for categorizing information and information systems based on the potential impact of a security breach. These impact levels are Low, Moderate, and High.
Question
In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- AMedium
- BHigh
- CLow
- DModerate
How the community answered
(40 responses)- A8% (3)
- B93% (37)
Why each option
FIPS 199, developed by NIST, defines a three-tiered system for categorizing information and information systems based on the potential impact of a security breach. These impact levels are Low, Moderate, and High.
FIPS 199 does not use "Medium" as a defined impact level; instead, it uses "Moderate."
FIPS 199 defines a "High" impact level, indicating a severe or catastrophic adverse effect on organizational operations, assets, or individuals.
FIPS 199 defines a "Low" impact level, signifying a limited adverse effect on organizational operations, assets, or individuals.
FIPS 199 defines a "Moderate" impact level, denoting a serious adverse effect on organizational operations, assets, or individuals.
Concept tested: FIPS 199 security impact levels
Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
Topics
Community Discussion
No community discussion yet for this question.