RMF Step 1: Cateogrize Flashcards

1
Q

Task 1-1

A

Categorize the information and information system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Task 1-2

A

Describe the information system (including the system boundary)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Task 1-3

A

Register - let organizational authority know what the system is used for, why it exists

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Sensitivity

A

how important the information is denotes the need for protection

information may have more sensitivity when combined,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Criticality

A

measure of the degree to which an organization needs the system for success of mission or business function

information may be more critical at a point in time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data Classification

A

Inventory and classification approach, what needs to be

  • public
  • internal use
  • restricted
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security Objective

A

CIA -

Confidentiality
Integrity
Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The docs used are

A

FIPs 199 and NIST 800-60

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

NIST 800-60 Volume 1 and 2 (both rev 1)

A

Volume 1, rev 1 - guide for mapping types of information and information systems to security categories

Volume 2, rev 1 - appendices to the guide for mapping types of information and information systems to security categories
*Recommended levels for each security objective (CIA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Categorization Process

A

1) Identify the Information System
2) Identify the Information Type
3) Select Provisional Impact Levels
4) Review Provisional Impact Levels
5) Adjust/Finalize Impact Levels
6) Assign System Security Cateogry
7) Security Categorization (FIPs 199)
8) FIPs 200 (control selection)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Three types of information types

A

1) Mission-Based Information Types
2) Services Delivery Support Information Types
3) Government Resource Mgmt Information Types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly