CGRC · Question #664
What is the process of determining the security category for information or an information system per methodologies described in CNSS instruction 1253 for national security systems and in FIPS 199…
The correct answer is C. Security Categorization. The question asks for the specific process of assigning a security category to information or an information system, guided by CNSS 1253 and FIPS 199.
Question
What is the process of determining the security category for information or an information system per methodologies described in CNSS instruction 1253 for national security systems and in FIPS 199 for other than national security systems? Response:
Options
- AInformation Type
- BCategorization
- CSecurity Categorization
- DImpact Level
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- C92% (35)
Why each option
The question asks for the specific process of assigning a security category to information or an information system, guided by CNSS 1253 and FIPS 199.
"Information Type" refers to a classification of data (e.g., PII, classified), but not the process of assigning security impact.
"Categorization" is too general; "Security Categorization" is the precise term for this specific process in cybersecurity frameworks.
Security categorization is the formal process, as defined by standards like FIPS 199 and CNSS 1253, for determining the potential impact on an organization or its individuals should a loss of confidentiality, integrity, or availability occur to information or an information system. This process assigns a security category (e.g., Low, Moderate, High) based on these potential impacts.
"Impact Level" is the result or an aspect of security categorization, indicating the degree of potential harm (e.g., Low, Moderate, High), but not the process itself.
Concept tested: Information System Security Categorization
Source: https://csrc.nist.gov/publications/detail/fips/199/final
Topics
Community Discussion
No community discussion yet for this question.