Study. uk . com
  1. Home
  2. All questions
  3. Question 178

CISSP study material · question 178 of 500

A programme presents its FIPS 199 categorisation as the completed risk assessment for a new system. Why is that claim wrong?

  1. Categorisation covers confidentiality alone and so cannot express risk.
  2. Categories are meant to be used together with threat and vulnerability information before risk is judged.
  3. Categorisation applies to information types, never to systems.
  4. Categorisation is only valid once the authorising official has signed it.
Show the answer

Answer: B. Categories are meant to be used together with threat and vulnerability information before risk is judged.

FIPS 199 states security categories are to be used in conjunction with vulnerability and threat information when assessing risk; the category by itself is not a risk assessment.

Source: NIST FIPS 199 (NIST) — FIPS 199 > 3. Categorization of Information and Information Systems

Challenge yourself on this topic → Study as cards