nerdexam
(ISC)2

CSSLP · Question #43

FIPS 199 defines the three levels of potential impact on organizations. Which of the following potential impact levels shows limited adverse effects on organizational operations, organizational assets

The correct answer is B. Low. FIPS 199 defines impact levels for information systems, and a "Low" impact level signifies limited adverse effects on organizational operations, assets, or individuals. This classification helps in determining appropriate security controls.

Secure Software Concepts

Question

FIPS 199 defines the three levels of potential impact on organizations. Which of the following potential impact levels shows limited adverse effects on organizational operations, organizational assets, or individuals?

Options

  • AModerate
  • BLow
  • CMedium
  • DHigh

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    93% (25)
  • C
    4% (1)

Why each option

FIPS 199 defines impact levels for information systems, and a "Low" impact level signifies limited adverse effects on organizational operations, assets, or individuals. This classification helps in determining appropriate security controls.

AModerate

Moderate impact indicates serious adverse effects, not limited.

BLowCorrect

According to FIPS 199, a "Low" impact level is characterized by limited adverse effects on organizational operations, organizational assets, or individuals if a breach of security occurs. This means the loss of confidentiality, integrity, or availability would cause only a minor detrimental impact.

CMedium

Medium is not a standard FIPS 199 impact level; FIPS 199 uses Low, Moderate, and High.

DHigh

High impact indicates severe or catastrophic adverse effects, far beyond limited.

Concept tested: FIPS 199 impact levels

Source: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf

Topics

#FIPS 199#Impact Levels#Risk Assessment#Security Categorization

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice