CAP Security Categorization 1 — Questions and Answers
Question 1: Which FIPS publication establishes the standards for categorizing federal information and information systems?
- FIPS 199 (Correct answer)
- FIPS 200
- FIPS 140-2
- FIPS 201
Correct answer: FIPS 199
FIPS 199 defines the standards for security categorization of federal information and information systems.
Question 2: What are the three potential impact levels defined by FIPS 199?
- Low, Moderate, High (Correct answer)
- Level 1, Level 2, Level 3
- Critical, Important, Minor
- Green, Yellow, Red
Correct answer: Low, Moderate, High
FIPS 199 defines Low, Moderate, and High as the three potential impact levels for each security objective.
Question 3: What NIST publication provides detailed guidance on mapping information types to security categories?
- NIST SP 800-60 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-39
Correct answer: NIST SP 800-60
NIST SP 800-60 provides a guide for mapping types of information and information systems to security categories.
Question 4: How is the overall security category of an information system determined when multiple information types are present?
- By using the high-water mark — the highest impact value across all information types and objectives (Correct answer)
- By averaging the impact values of all information types
- By using the lowest impact value to minimize security requirements
- By a vote among the system owner, ISSO, and AO
Correct answer: By using the high-water mark — the highest impact value across all information types and objectives
The high-water mark principle means the system's overall category is set to the highest impact level found among all information types for each security objective.
Question 5: A system is categorized as SC = {Confidentiality: High, Integrity: Moderate, Availability: Low}. What is the overall system impact level?
- High (Correct answer)
- Moderate
- Low
- Critical
Correct answer: High
The overall system impact level is determined by the highest value across all three security objectives, which is High in this case.
Question 6: Which document should the system owner consult when determining information types for categorization?
- NIST SP 800-60 Volume II (Correct answer)
- NIST SP 800-53 Appendix
- FIPS 200
- OMB Circular A-130
Correct answer: NIST SP 800-60 Volume II
NIST SP 800-60 Volume II contains the tables that map federal information types to recommended security impact levels.
Which FIPS publication establishes the standards for categorizing federal information and information systems?