CGRC Information System Categorization 2 — Questions and Answers
Question 1: When categorizing information types, if an information system processes both 'Moderate' confidentiality data and 'High' availability data, what is the system's overall security category?
- Moderate
- High (Correct answer)
- Low
- It depends on the number of information types
Correct answer: High
Using the high-water mark principle from FIPS 199, the overall security category is High because that is the highest impact level across all security objectives.
Question 2: Which document formally records the security categorization decision for an information system as part of the RMF process?
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
- Privacy Impact Assessment (PIA)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) formally documents the security categorization along with the system description, boundary, and selected controls.
Question 3: In the NIST SP 800-60 framework, information is grouped into what two broad categories?
- Classified and Unclassified
- Mission-based and Management support (Correct answer)
- Operational and Management
- Technical and Non-technical
Correct answer: Mission-based and Management support
NIST SP 800-60 groups government information into Mission-based information types and Management and Support information types.
Question 4: A system that stores Social Security Numbers and other PII is likely to receive a HIGH impact rating for which security objective above others?
- Availability
- Integrity
- Confidentiality (Correct answer)
- Accountability
Correct answer: Confidentiality
Personally Identifiable Information (PII) is primarily sensitive because unauthorized disclosure can cause serious harm, making Confidentiality the primary concern with a High impact rating.
Question 5: Which of the following best describes a 'HIGH' impact level under FIPS 199?
- Limited adverse effects on organizational operations or assets
- Serious adverse effects on organizational operations, assets, or individuals
- Severe or catastrophic adverse effects on organizational operations, assets, or individuals (Correct answer)
- No adverse effects on mission capabilities
Correct answer: Severe or catastrophic adverse effects on organizational operations, assets, or individuals
FIPS 199 defines a HIGH impact as one where a loss could be expected to have a severe or catastrophic adverse effect on organizational operations, assets, or individuals.
Question 6: What term does FIPS 199 use to describe the format for expressing a system's security category?
- SC = {confidentiality impact, integrity impact, availability impact}
- SC = {C:impact, I:impact, A:impact}
- SC (system) = {(confidentiality, impact), (integrity, impact), (availability, impact)} (Correct answer)
- SC = C/I/A
Correct answer: SC (system) = {(confidentiality, impact), (integrity, impact), (availability, impact)}
FIPS 199 expresses a security category as SC (information type) = {(confidentiality, impact level), (integrity, impact level), (availability, impact level)}.
Question 7: When should security categorization be revisited during the system lifecycle?
- Only during the initial Authorization process
- Whenever significant changes occur to the system or its operating environment (Correct answer)
- Once every five years regardless of system changes
- Only when the Authorizing Official requests a review
Correct answer: Whenever significant changes occur to the system or its operating environment
Security categorization should be reviewed and updated whenever significant changes occur to the system, the information it processes, or the operating environment.
When categorizing information types, if an information system processes both 'Moderate' confidentiality data and 'High' availability data, what is the system's overall security category?