CAP System Categorization & Impact Level Determination — Questions and Answers
Question 1: According to FIPS 199, which of the following correctly defines the 'HIGH' impact level for a security objective?
- The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, assets, or individuals. (Correct answer)
- The loss could be expected to have a limited adverse effect on organizational operations.
- The loss could be expected to have a serious adverse effect but one that does not result in loss of life.
- The loss would have no measurable effect on the organization's mission.
Correct answer: The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, assets, or individuals.
FIPS 199 defines HIGH impact as an expected severe or catastrophic effect, including loss of life, major financial loss, or inability to perform primary missions. LOW = limited effect; MODERATE = serious but not catastrophic.
Question 2: An information system processes both MODERATE-confidentiality data and HIGH-integrity data. According to the 'high-water mark' principle in FIPS 199, what is the overall system categorization?
- MODERATE, because most data is at the moderate level.
- HIGH, because the highest individual impact level determines the overall categorization. (Correct answer)
- LOW, because the average of the three objectives is used.
- It depends on the authorizing official's discretion.
Correct answer: HIGH, because the highest individual impact level determines the overall categorization.
FIPS 199 requires using the 'high-water mark' — the overall system categorization equals the highest impact rating across all security objectives (confidentiality, integrity, availability). One HIGH rating makes the whole system HIGH.
Question 3: Which NIST publication provides guidance for mapping information types to security impact levels during the categorization step of the RMF?
- NIST SP 800-37
- NIST SP 800-53
- NIST SP 800-60 (Correct answer)
- NIST SP 800-137
Correct answer: NIST SP 800-60
NIST SP 800-60 ('Guide for Mapping Types of Information and Information Systems to Security Categories') is the companion to FIPS 199 and provides the taxonomy of information types with recommended impact levels for each.
Question 4: During system categorization, a hospital's patient-monitoring system that, if unavailable, could result in patient death would most likely have which availability impact rating?
- LOW
- MODERATE
- HIGH (Correct answer)
- CRITICAL — a fourth tier used for life-safety systems
Correct answer: HIGH
A system whose unavailability could directly cause loss of human life meets the FIPS 199 definition of HIGH impact (severe or catastrophic adverse effect on individuals). There is no fourth 'CRITICAL' tier in FIPS 199.
Question 5: Who is ultimately responsible for signing the system categorization decision in a federal agency's RMF process?
- The Information System Security Officer (ISSO)
- The System Owner (Correct answer)
- The Authorizing Official (AO)
- The Chief Information Officer (CIO)
Correct answer: The System Owner
NIST SP 800-37 assigns the System Owner the responsibility for categorizing the information system and documenting the result in the Security Plan. The AO reviews and approves authorization decisions, but categorization is the System Owner's formal responsibility.
Question 6: Which of the following is a correct statement about the relationship between FIPS 199 and FIPS 200?
- FIPS 199 establishes security categorization; FIPS 200 specifies minimum security requirements based on that categorization. (Correct answer)
- FIPS 199 selects security controls; FIPS 200 categorizes information systems.
- Both publications serve the same purpose and are interchangeable.
- FIPS 200 is voluntary guidance while FIPS 199 is mandatory for federal agencies.
Correct answer: FIPS 199 establishes security categorization; FIPS 200 specifies minimum security requirements based on that categorization.
FIPS 199 defines the standards for categorizing information and information systems, while FIPS 200 specifies the minimum security requirements (tied to impact levels) that federal agencies must meet. They work sequentially: categorize first (199), then apply minimum requirements (200).
According to FIPS 199, which of the following correctly defines the 'HIGH' impact level for a security objective?