What Volume I: Guide for Mapping Types of Information and Information Systems to Security Categories requires
This guideline has been developed to assist Federal government agencies to categorize information and information systems. The guideline’s objective is to facilitate application of appropriate levels of information security according to a range of levels of impact or consequences that might result from the unauthorized disclosure, modification, or use of the information or information system. It addresses the Federal Information Security Management Act (FISMA) direction to develop guidelines recommending the types of information and information systems to be included in each category of potential security impact. This guideline applies to all Federal information systems other than national security systems. This publication is intended to serve a diverse federal audience of information system and information security professionals including individuals with oversight responsibilities (e.g., chief information officers), organizational officials (e.g., mission and business area owners), individuals with development responsibilities, and individuals with implementation and operational responsibilities. It provides a structured, yet flexible framework for satisfying the requirements of FISMA. Security categorization is the key first step in the Risk Management Framework because of its effect on all other steps, from the selection of security controls to the level of effort in assessing security control effectiveness.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf
SHA-256 integrity: 281a981daf48018f2a23a76c3b36960a29e077d8aae969ee10526a0bcbf1cef9
Primary Citations — 7 traced to source
- {"citation":"Executive Summary","text":"This guideline assumes that the user is familiar with Standards for Security Categorization of Federal Information and Information Systems (Federal Information Processing Standard [FIPS] 199)."}
- {"citation":"Section 1.1: Purpose and Applicability","text":"This guideline is intended to help agencies consistently map security impact levels to types of: (i) information (e.g., privacy, medical, proprietary, financial, contractor sensitive, trade secret, investigation); and (ii) information systems (e.g., mission critical, mission support, administrative)."}
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.