nerdexam
(ISC)2

CGRC · Question #603

Which of the following formulas was developed by FIPS 199 for categorization of an information type? Response:

The correct answer is B. SC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}. FIPS 199 establishes a standard for categorizing information types based on the potential impact to an organization's mission, functions, image, or reputation, agency assets, or individuals. The formula considers the impact levels (low, moderate, high) across the three security…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following formulas was developed by FIPS 199 for categorization of an information type? Response:

Options

  • ASC information type = {(confidentiality, controls), (integrity, controls), (authentication, controls)}
  • BSC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}
  • CSC information type = {(confidentiality, risk), (integrity, risk), (availability, risk)}
  • DSC information type = {(Authentication, impact), (integrity, impact), (availability, impact)}

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    86% (19)
  • D
    5% (1)

Why each option

FIPS 199 establishes a standard for categorizing information types based on the potential impact to an organization's mission, functions, image, or reputation, agency assets, or individuals. The formula considers the impact levels (low, moderate, high) across the three security objectives: confidentiality, integrity, and availability.

ASC information type = {(confidentiality, controls), (integrity, controls), (authentication, controls)}

This formula incorrectly uses 'controls' and 'authentication, controls' instead of 'impact' for all three security objectives specified by FIPS 199.

BSC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}Correct

FIPS 199 (Federal Information Processing Standards Publication 199) defines the security categorization of information systems based on the potential impact of a breach to confidentiality, integrity, and availability. The formula SC information type = {{(confidentiality, impact), (integrity, impact), (availability, impact)}} directly represents this standard where SC stands for Security Category and impact refers to the potential adverse effect.

CSC information type = {(confidentiality, risk), (integrity, risk), (availability, risk)}

This formula incorrectly uses 'risk' instead of 'impact' for all three security objectives, as FIPS 199 specifically focuses on impact levels.

DSC information type = {(Authentication, impact), (integrity, impact), (availability, impact)}

This formula incorrectly replaces 'confidentiality, impact' with 'Authentication, impact,' while FIPS 199 specifies confidentiality, integrity, and availability as the three core security objectives.

Concept tested: FIPS 199 information type categorization

Source: https://csrc.nist.gov/publications/detail/fips/199/final

Topics

#FIPS 199#Security categorization#CIA triad#Information impact

Community Discussion

No community discussion yet for this question.

Full CGRC Practice