The security categorization framework described in FIPS 199 uses ratings in which three categories?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

The security categorization framework described in FIPS 199 uses ratings in which three categories?

Explanation:
FIPS 199 uses the CIA triad—Confidentiality, Integrity, and Availability—as the three ratings for security categorization. For each information type, the framework assesses how severe the impact would be if confidentiality is compromised, if integrity is compromised, or if availability is disrupted, usually assigning impact levels of low, moderate, or high. This approach centers on protecting data from unauthorized disclosure, ensuring data accuracy and trustworthiness, and maintaining access to information and systems when needed. Privacy and authentication are important security concepts, but they are not the three ratings defined by FIPS 199.

FIPS 199 uses the CIA triad—Confidentiality, Integrity, and Availability—as the three ratings for security categorization. For each information type, the framework assesses how severe the impact would be if confidentiality is compromised, if integrity is compromised, or if availability is disrupted, usually assigning impact levels of low, moderate, or high. This approach centers on protecting data from unauthorized disclosure, ensuring data accuracy and trustworthiness, and maintaining access to information and systems when needed. Privacy and authentication are important security concepts, but they are not the three ratings defined by FIPS 199.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy