nerdexam
(ISC)2

CGRC · Question #532

In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete…

The correct answer is B. High C. Low D. Moderate. FIPS 199, developed by NIST, defines a three-tiered system for categorizing information and information systems based on the potential impact of a security breach. These impact levels are Low, Moderate, and High.

Scope of the System

Question

In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • AMedium
  • BHigh
  • CLow
  • DModerate

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    93% (37)

Why each option

FIPS 199, developed by NIST, defines a three-tiered system for categorizing information and information systems based on the potential impact of a security breach. These impact levels are Low, Moderate, and High.

AMedium

FIPS 199 does not use "Medium" as a defined impact level; instead, it uses "Moderate."

BHighCorrect

FIPS 199 defines a "High" impact level, indicating a severe or catastrophic adverse effect on organizational operations, assets, or individuals.

CLowCorrect

FIPS 199 defines a "Low" impact level, signifying a limited adverse effect on organizational operations, assets, or individuals.

DModerateCorrect

FIPS 199 defines a "Moderate" impact level, denoting a serious adverse effect on organizational operations, assets, or individuals.

Concept tested: FIPS 199 security impact levels

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#NIST FIPS 199#Impact Levels#Information System Categorization#Risk Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice