CGRC · Question #603
Which of the following formulas was developed by FIPS 199 for categorization of an information type? Response:
The correct answer is B. SC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}. FIPS 199 establishes a standard for categorizing information types based on the potential impact to an organization's mission, functions, image, or reputation, agency assets, or individuals. The formula considers the impact levels (low, moderate, high) across the three security…
Question
Which of the following formulas was developed by FIPS 199 for categorization of an information type? Response:
Options
- ASC information type = {(confidentiality, controls), (integrity, controls), (authentication, controls)}
- BSC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}
- CSC information type = {(confidentiality, risk), (integrity, risk), (availability, risk)}
- DSC information type = {(Authentication, impact), (integrity, impact), (availability, impact)}
How the community answered
(22 responses)- A9% (2)
- B86% (19)
- D5% (1)
Why each option
FIPS 199 establishes a standard for categorizing information types based on the potential impact to an organization's mission, functions, image, or reputation, agency assets, or individuals. The formula considers the impact levels (low, moderate, high) across the three security objectives: confidentiality, integrity, and availability.
This formula incorrectly uses 'controls' and 'authentication, controls' instead of 'impact' for all three security objectives specified by FIPS 199.
FIPS 199 (Federal Information Processing Standards Publication 199) defines the security categorization of information systems based on the potential impact of a breach to confidentiality, integrity, and availability. The formula SC information type = {{(confidentiality, impact), (integrity, impact), (availability, impact)}} directly represents this standard where SC stands for Security Category and impact refers to the potential adverse effect.
This formula incorrectly uses 'risk' instead of 'impact' for all three security objectives, as FIPS 199 specifically focuses on impact levels.
This formula incorrectly replaces 'confidentiality, impact' with 'Authentication, impact,' while FIPS 199 specifies confidentiality, integrity, and availability as the three core security objectives.
Concept tested: FIPS 199 information type categorization
Source: https://csrc.nist.gov/publications/detail/fips/199/final
Topics
Community Discussion
No community discussion yet for this question.