- Home
- All questions
- Question 176
CISSP study material · question 176 of 500
An analyst wants to record a system's confidentiality objective as not applicable because the system holds only public data. Why does FIPS 199 forbid this at system level?
Show the answer
Answer: B. A system's own processing functions and information always warrant at least low protection.
FIPS 199 states not applicable cannot be assigned to any objective for a system, recognising a low minimum impact because the system-level processing functions and information must be protected.
Source: NIST FIPS 199 (NIST) — FIPS 199 > Security Categorization Applied to Information Systems