CGRC · Question #595
The process of determining the security category for information or an information system. Security categorization methodologies are described in CNSS Instruction 1253 for national security systems…
The correct answer is A. Security Categorization. The process of determining the security category for information or an information system, as described in FIPS 199 and CNSS Instruction 1253, is called Security Categorization.
Question
The process of determining the security category for information or an information system. Security categorization methodologies are described in CNSS Instruction 1253 for national security systems and in FIPS 199 for other than national security systems Response:
Options
- ASecurity Categorization
- BSecurity Category
- CSecurity Controls
- DAdequate Security
How the community answered
(48 responses)- A92% (44)
- B4% (2)
- C2% (1)
- D2% (1)
Why each option
The process of determining the security category for information or an information system, as described in FIPS 199 and CNSS Instruction 1253, is called Security Categorization.
Security Categorization is the systematic process of assigning an impact level (low, moderate, or high) to information and information systems based on the potential impact of a compromise on confidentiality, integrity, and availability, which directly aligns with the description provided.
Security Category is the *result* or output of the categorization process, not the process itself.
Security Controls are the safeguards implemented to protect systems and information, distinct from the process of determining their impact levels.
Adequate Security refers to the overall level of security needed, not the specific process of formally categorizing an information system.
Concept tested: NIST Information System Categorization
Source: https://www.nist.gov/system/files/documents/2017/04/04/fips199-final.pdf
Topics
Community Discussion
No community discussion yet for this question.