CGRC Information System Categorization 5 — Questions and Answers
Question 1: During categorization, an agency cannot find a matching information type in NIST SP 800-60 Volume II for a new emerging technology platform. What should the agency do?
- Default the system to High impact across all objectives
- Use the closest analogous information type and document the rationale (Correct answer)
- Skip categorization until NIST updates SP 800-60
- Assign Low impact since no predefined type exists
Correct answer: Use the closest analogous information type and document the rationale
NIST SP 800-60 recommends selecting the closest analogous information type and documenting the justification when an exact match does not exist.
Question 2: What document formally records the outcome of the system categorization process and is included in the system security plan?
- Security impact analysis report
- FIPS 199 system security categorization form (Correct answer)
- Plan of action and milestones (POA&M)
- Privacy impact assessment (PIA)
Correct answer: FIPS 199 system security categorization form
The FIPS 199 categorization form documents the security category determination and is incorporated into the system security plan as formal evidence.
Question 3: Which scenario represents an integrity impact of High under FIPS 199?
- Unauthorized disclosure of a public-facing website's content
- Incorrect modification of electronic health records leading to patient harm (Correct answer)
- Temporary unavailability of a low-priority reporting tool
- Disclosure of internal meeting schedules to unauthorized staff
Correct answer: Incorrect modification of electronic health records leading to patient harm
High integrity impact occurs when unauthorized modification could have severe or catastrophic consequences, such as patient harm from corrupted medical records.
Question 4: An organization is categorizing a system that transmits sensitive law enforcement information across agency networks. Which security objective is most likely to be rated High?
- Availability
- Confidentiality (Correct answer)
- Integrity
- Accountability
Correct answer: Confidentiality
Sensitive law enforcement information, if disclosed to unauthorized parties, could jeopardize investigations and personal safety, warranting a High confidentiality impact.
Question 5: How does NIST SP 800-60 handle information types that are common across multiple government mission areas, such as financial management?
- Each agency independently assigns impact levels with no recommended defaults
- Volume I provides a common mission area taxonomy with suggested impact levels (Correct answer)
- These types default to High across all objectives due to their broad use
- They are excluded from categorization and managed under separate OMB guidance
Correct answer: Volume I provides a common mission area taxonomy with suggested impact levels
NIST SP 800-60 Volume I categorizes information types into mission areas and provides recommended impact levels that agencies can adopt or adjust with justification.
Question 6: A system owner wants to adjust the recommended impact level from NIST SP 800-60 downward based on the specific mission context. What is required to make this adjustment?
- No justification is needed since the system owner has full authority
- Approval from the system administrator and ISSO
- Documentation of the rationale and concurrence from the authorizing official (Correct answer)
- A formal waiver request submitted to NIST
Correct answer: Documentation of the rationale and concurrence from the authorizing official
Adjustments to recommended impact levels must be justified with documented rationale and reviewed by the authorizing official as part of the categorization decision.
Question 7: Which of the following best describes the relationship between information system categorization and the selection of security controls in the RMF?
- Categorization occurs after control selection to validate the chosen baseline
- Categorization determines the initial control baseline from which controls are selected and tailored (Correct answer)
- Control selection is independent of categorization and based solely on threat assessments
- Categorization applies only to data classification and does not influence control selection
Correct answer: Categorization determines the initial control baseline from which controls are selected and tailored
In the RMF, the security category established in Step 1 directly drives the selection of the appropriate control baseline (Low, Moderate, or High) in Step 2.
During categorization, an agency cannot find a matching information type in NIST SP 800-60 Volume II for a new emerging technology platform.
What should the agency do?