CAP Security Categorization 2 — Questions and Answers
Question 1: What is the security categorization format specified in FIPS 199?
- SC = {(confidentiality, impact), (integrity, impact), (availability, impact)} (Correct answer)
- Risk = Threat × Vulnerability × Impact
- Category = (High/Moderate/Low)
- SC = [C+I+A] / 3
Correct answer: SC = {(confidentiality, impact), (integrity, impact), (availability, impact)}
FIPS 199 specifies the format as SC information type = {(confidentiality, impact level), (integrity, impact level), (availability, impact level)}.
Question 2: What triggers the need to recategorize a federal information system?
- Significant changes to the information processed, mission requirements, or operating environment (Correct answer)
- Annual FISMA reporting deadlines only
- A change in the system administrator
- The expiration of the ATO
Correct answer: Significant changes to the information processed, mission requirements, or operating environment
Recategorization is needed when the types of information processed, mission requirements, or operational context change significantly enough to alter the system's risk profile.
Question 3: Which role is primarily responsible for completing the security categorization of an information system?
- System Owner, in coordination with the ISSO and data owners (Correct answer)
- Authorizing Official alone
- Security Control Assessor independently
- Chief Information Officer without input from owners
Correct answer: System Owner, in coordination with the ISSO and data owners
The System Owner leads the categorization process in collaboration with the ISSO and information owners to ensure all data types are properly accounted for.
Question 4: What does a High categorization for Availability mean for a federal system?
- Loss of availability would have a severe or catastrophic adverse effect on operations, assets, or individuals (Correct answer)
- The system is classified at the Top Secret level
- The system requires 99.999% uptime by law
- The system is accessible to all federal employees
Correct answer: Loss of availability would have a severe or catastrophic adverse effect on operations, assets, or individuals
A High Availability impact means system downtime could cause severe harm to the organization's mission, finances, or national security.
Question 5: Which mission-based information type from NIST SP 800-60 typically receives a High Confidentiality categorization?
- Intelligence data and law enforcement sensitive information (Correct answer)
- Public outreach and communications data
- Facilities management information
- Training and education records for public programs
Correct answer: Intelligence data and law enforcement sensitive information
Information types like intelligence and law enforcement sensitive data typically warrant High confidentiality due to the severe harm from unauthorized disclosure.
Question 6: What FIPS standard defines the minimum security requirements based on the impact level determined by FIPS 199?
- FIPS 200 (Correct answer)
- FIPS 199
- FIPS 140-2
- FIPS 201
Correct answer: FIPS 200
FIPS 200 specifies the minimum security requirements for each impact level category established by FIPS 199.
What is the security categorization format specified in FIPS 199?