Unit 1 - FIPS PUB 199 Flashcards

1
Q

What is the purpose of FIPS Publication 199?

A

To develop standards for categorizing information and information systems based on security objectives and risk levels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Under which acts was FIPS Publication 199 established?

A

E-Government Act of 2002 and Federal Information Security Management Act of 2002.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the three security objectives defined by FISMA?

A
  • Confidentiality
  • Integrity
  • Availability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does a loss of confidentiality entail?

A

The unauthorized disclosure of information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does a loss of integrity refer to?

A

The unauthorized modification or destruction of information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define availability in the context of information security.

A

Ensuring timely and reliable access to and use of information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is considered a LOW potential impact on organizations?

A

Limited adverse effect on organizational operations, assets, or individuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What constitutes a HIGH potential impact as defined in FIPS Publication 199?

A

Severe or catastrophic adverse effect on organizational operations, assets, or individuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Fill in the blank: The potential impact is ______ if the loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect.

A

MODERATE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the significance of security categorization for information types?

A

It determines the potential impact for each security objective associated with the information type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How is the security category of an information type expressed?

A

SC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)}

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the acceptable values for potential impact in information systems?

A
  • LOW
  • MODERATE
  • HIGH
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or False: The value of not applicable can be assigned to any security objective for an information system.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What must be considered when determining the security category of an information system?

A

The security categories of all information types resident on the information system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the term ‘high water mark’ refer to in security categorization?

A

The highest values assigned to the respective security objectives from among the security categories for each type of information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is an example of a security category for public information?

A

SC public information = {(confidentiality, NA), (integrity, MODERATE), (availability, MODERATE)}

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the role of NIST in relation to FIPS Publications?

A

To provide leadership, technical guidance, and coordination in the development of standards and guidelines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Fill in the blank: These standards are effective upon approval by the _______.

A

Secretary of Commerce

19
Q

What types of organizations may consider using FIPS standards?

A
  • State governments
  • Local governments
  • Tribal governments
  • Private sector organizations
20
Q

What defines an information type?

A

A specific category of information defined by an organization or law.

21
Q

How does FIPS Publication 199 categorize information systems?

A

Based on the potential impact on confidentiality, integrity, and availability.

22
Q

What is the purpose of the security categorization standards?

A

To promote effective management and oversight of information security programs.

23
Q

What does the term ‘potential impact’ refer to?

A

The expected effect on an organization from a breach of security.

24
Q

True or False: The security categorization framework is only applicable to federal information systems.

25
Q

What is the potential impact of a loss of availability?

A

Disruption of access to or use of information or an information system.

26
Q

What is the purpose of FIPS Publication 199?

A

Standards for Security Categorization of Federal Information and Information Systems

27
Q

What does SCADA stand for?

A

Supervisory Control and Data Acquisition

28
Q

What are the potential impacts assessed for SCADA system sensor data?

A

Confidentiality: NA, Integrity: HIGH, Availability: HIGH

29
Q

What are the potential impacts assessed for SCADA system administrative information?

A

Confidentiality: LOW, Integrity: LOW, Availability: LOW

30
Q

What is the initial security category for the SCADA system?

A

Confidentiality: LOW, Integrity: HIGH, Availability: HIGH

31
Q

What change did management make to the confidentiality impact of the SCADA system?

A

Increased from LOW to MODERATE

32
Q

What is the final security category of the SCADA system after management’s adjustment?

A

Confidentiality: MODERATE, Integrity: HIGH, Availability: HIGH

33
Q

Define the potential impact of confidentiality at ‘LOW.’

A

The unauthorized disclosure of information could be expected to have a limited adverse effect

34
Q

Define the potential impact of integrity at ‘HIGH.’

A

The unauthorized modification or destruction of information could be expected to have a severe or catastrophic adverse effect

35
Q

What does availability ensure?

A

Timely and reliable access to and use of information

36
Q

What is the definition of information security?

A

The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction

37
Q

Fill in the blank: The term _______ refers to a specific category of information.

A

Information Type

38
Q

True or False: The National Security System includes information systems not involved in intelligence activities.

39
Q

What is the definition of security category?

A

The characterization of information or an information system based on an assessment of the potential impact

40
Q

List the three security objectives.

A
  • Confidentiality
  • Integrity
  • Availability
41
Q

What are security controls?

A

The management, operational, and technical controls prescribed for an information system

42
Q

What does the term ‘information technology’ encompass?

A

Any equipment or interconnected system or subsystem of equipment used in data management

43
Q

What is the significance of the term ‘executive agency’?

A

Refers to departments specified in U.S. law responsible for various governmental functions