nerdexam
(ISC)2

CISSP · Question #196

What is the process called when impact values are assigned to the security objectives for information types?

The correct answer is D. System security categorization. System security categorization is the formal NIST process of assigning impact values (low, moderate, high) to security objectives (confidentiality, integrity, availability) for information types and systems.

Submitted by tunde_lagos· Mar 5, 2026Security and Risk Management

Question

What is the process called when impact values are assigned to the security objectives for information types?

Options

  • AQualitative analysis
  • BQuantitative analysis
  • CRemediation
  • DSystem security categorization

How the community answered

(17 responses)
  • A
    6% (1)
  • D
    94% (16)

Why each option

System security categorization is the formal NIST process of assigning impact values (low, moderate, high) to security objectives (confidentiality, integrity, availability) for information types and systems.

AQualitative analysis

Qualitative analysis is a risk assessment method that uses descriptive scales and subjective judgment to evaluate risk, not a process specifically focused on assigning impact values to security objectives for information types.

BQuantitative analysis

Quantitative analysis assigns numerical or monetary values to risks and assets for cost-benefit calculations, which is a broader risk assessment technique rather than the structured process of categorizing information types by security impact levels.

CRemediation

Remediation refers to the process of fixing or mitigating identified vulnerabilities or security deficiencies, not the assignment of impact values to security objectives.

DSystem security categorizationCorrect

System security categorization, defined in FIPS 199 and NIST SP 800-60, is the specific process of determining the potential impact (low, moderate, or high) on confidentiality, integrity, and availability for each information type processed by a system. This categorization drives the selection of appropriate security controls under the NIST Risk Management Framework. The overall system security category is determined by the highest impact value across all security objectives and information types.

Concept tested: FIPS 199 system security categorization of information types

Source: https://csrc.nist.gov/publications/detail/fips/199/final

Topics

#Security categorization#Impact assessment#Risk management

Community Discussion

No community discussion yet for this question.

Full CISSP Practice