CGRC Information System Categorization 4 — Questions and Answers
Question 1: An organization discovers that a system initially categorized as Moderate has begun processing information that could affect national security if breached. What action is required?
- Maintain the current categorization until the next annual review
- Recategorize the system upward to reflect the new information type (Correct answer)
- Document the change and notify the ISSO without formal recategorization
- Apply compensating controls without changing the baseline
Correct answer: Recategorize the system upward to reflect the new information type
NIST SP 800-60 requires recategorization whenever the nature or sensitivity of the information processed changes significantly.
Question 2: Under FIPS 199, which factor determines the security category of an information system when multiple information types are processed?
- The average impact level across all information types
- The lowest impact level among all information types
- The highest impact level (high-water mark) among all information types (Correct answer)
- The impact level assigned by the system owner
Correct answer: The highest impact level (high-water mark) among all information types
FIPS 199 uses the high-water mark principle: the overall system category is the highest impact level found across all information types and security objectives.
Question 3: A state agency processes federal grant data subject to CUI requirements alongside routine administrative records. How should the categorization be determined?
- Categorize based only on the federal grant data since it is the most sensitive
- Create separate system boundaries for each information type
- Apply the high-water mark across all information types processed (Correct answer)
- Default to Moderate because CUI is typically Moderate impact
Correct answer: Apply the high-water mark across all information types processed
FIPS 199 mandates applying the high-water mark across all information types regardless of their origin or regulatory label.
Question 4: Which NIST publication maps federal information and information system types to security impact levels to support the categorization process?
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-60 (Correct answer)
- NIST SP 800-30
Correct answer: NIST SP 800-60
NIST SP 800-60 provides the mapping of information types to recommended security impact levels for confidentiality, integrity, and availability.
Question 5: An organization is categorizing a financial payment processing system. Unavailability of this system for even one hour would result in significant monetary losses and reputational damage. Which availability impact level is most appropriate?
- Low
- Moderate
- High (Correct answer)
- Critical
Correct answer: High
High availability impact is appropriate when loss of availability would result in severe financial or operational consequences to the organization.
Question 6: In the RMF, who bears ultimate responsibility for accepting the risk associated with an information system's security categorization and resulting control selection?
- System owner
- Information system security officer (ISSO)
- Authorizing official (AO) (Correct answer)
- Chief information officer (CIO)
Correct answer: Authorizing official (AO)
The authorizing official is responsible for accepting residual risk and granting an authorization to operate based on the categorization and implemented controls.
Question 7: A system is used solely for internal employee scheduling with no PII, no financial data, and minimal operational impact if unavailable for up to 24 hours. What is the likely categorization?
- High for all three security objectives
- Low for all three security objectives (Correct answer)
- Moderate confidentiality, Low integrity, Low availability
- Low confidentiality, Moderate integrity, High availability
Correct answer: Low for all three security objectives
When the potential impact of compromise or loss is limited and no sensitive information types are involved, a Low categorization across all objectives is appropriate.
An organization discovers that a system initially categorized as Moderate has begun processing information that could affect national security if breached.
What action is required?