CGRC Information System Categorization 1 β Questions and Answers
Question 1: Which NIST publication provides the primary guidance for categorizing federal information and information systems?
- NIST SP 800-53
- NIST SP 800-37
- FIPS 199 (Correct answer)
- FIPS 200
Correct answer: FIPS 199
FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems) is the primary standard that defines security categories for federal information and systems.
Question 2: In the NIST RMF, information system categorization is which step of the framework?
- Step 1 β Prepare
- Step 2 β Categorize (Correct answer)
- Step 3 β Select
- Step 4 β Implement
Correct answer: Step 2 β Categorize
Categorize is Step 2 of the NIST RMF, occurring after the Prepare step and before the Select step.
Question 3: FIPS 199 defines the security category of an information system based on which three security objectives?
- Availability, Authenticity, and Integrity
- Confidentiality, Integrity, and Availability (Correct answer)
- Accountability, Integrity, and Availability
- Confidentiality, Non-repudiation, and Availability
Correct answer: Confidentiality, Integrity, and Availability
FIPS 199 uses Confidentiality, Integrity, and Availability (CIA) as the three security objectives for determining an information system's security category.
Question 4: When applying FIPS 199, what are the three potential impact levels for each security objective?
- Negligible, Moderate, Severe
- Low, Medium, High
- Low, Moderate, High (Correct answer)
- Minor, Major, Critical
Correct answer: Low, Moderate, High
FIPS 199 defines Low, Moderate, and High as the three potential impact levels for each of the three security objectives.
Question 5: The overall security category of an information system in FIPS 199 is determined by applying which rule to the impact levels of each security objective?
- Average of all impact values
- High-water mark (highest impact level) (Correct answer)
- Low-water mark (lowest impact level)
- Median impact level across objectives
Correct answer: High-water mark (highest impact level)
FIPS 199 uses the high-water mark principle, meaning the overall system categorization is the highest impact level assigned to any individual security objective.
Question 6: Which NIST publication provides supplemental guidance on how to determine the security category of information types and systems per FIPS 199?
- NIST SP 800-60 (Correct answer)
- NIST SP 800-53A
- NIST SP 800-137
- NIST SP 800-39
Correct answer: NIST SP 800-60
NIST SP 800-60 (Guide for Mapping Types of Information and Information Systems to Security Categories) supplements FIPS 199 by providing mappings for categorizing specific information types.
Question 7: Who is ultimately responsible for approving the security categorization of an information system according to the NIST RMF?
- Information System Security Officer (ISSO)
- Authorizing Official (AO)
- System Owner (Correct answer)
- Senior Agency Information Security Officer (SAISO)
Correct answer: System Owner
The System Owner is responsible for categorizing the information system and ensuring the categorization is reviewed and approved by senior officials, with the AO ultimately concurring.
Which NIST publication provides the primary guidance for categorizing federal information and information systems?