Study. uk . com
  1. Home
  2. All questions
  3. Question 176

CISSP study material · question 176 of 500

An analyst wants to record a system's confidentiality objective as not applicable because the system holds only public data. Why does FIPS 199 forbid this at system level?

  1. Not applicable is reserved for information types owned by another agency.
  2. A system's own processing functions and information always warrant at least low protection.
  3. Public data is still categorised moderate by default.
  4. The value is permitted only where the system is air-gapped.
Show the answer

Answer: B. A system's own processing functions and information always warrant at least low protection.

FIPS 199 states not applicable cannot be assigned to any objective for a system, recognising a low minimum impact because the system-level processing functions and information must be protected.

Source: NIST FIPS 199 (NIST) — FIPS 199 > Security Categorization Applied to Information Systems

Challenge yourself on this topic → Study as cards