CISSP · Question #196
What is the process called when impact values are assigned to the security objectives for information types?
The correct answer is D. System security categorization. System security categorization is the formal NIST process of assigning impact values (low, moderate, high) to security objectives (confidentiality, integrity, availability) for information types and systems.
Question
What is the process called when impact values are assigned to the security objectives for information types?
Options
- AQualitative analysis
- BQuantitative analysis
- CRemediation
- DSystem security categorization
How the community answered
(17 responses)- A6% (1)
- D94% (16)
Why each option
System security categorization is the formal NIST process of assigning impact values (low, moderate, high) to security objectives (confidentiality, integrity, availability) for information types and systems.
Qualitative analysis is a risk assessment method that uses descriptive scales and subjective judgment to evaluate risk, not a process specifically focused on assigning impact values to security objectives for information types.
Quantitative analysis assigns numerical or monetary values to risks and assets for cost-benefit calculations, which is a broader risk assessment technique rather than the structured process of categorizing information types by security impact levels.
Remediation refers to the process of fixing or mitigating identified vulnerabilities or security deficiencies, not the assignment of impact values to security objectives.
System security categorization, defined in FIPS 199 and NIST SP 800-60, is the specific process of determining the potential impact (low, moderate, or high) on confidentiality, integrity, and availability for each information type processed by a system. This categorization drives the selection of appropriate security controls under the NIST Risk Management Framework. The overall system security category is determined by the highest impact value across all security objectives and information types.
Concept tested: FIPS 199 system security categorization of information types
Source: https://csrc.nist.gov/publications/detail/fips/199/final
Topics
Community Discussion
No community discussion yet for this question.