Nist 800 60 System Categorization
18 community-sourced questions and answers. Free — no login.
Why was NIST 800-60 developed for?
To assist Federal government agencies to categorize information and information systems
What two potential security impacts does NIST 800-60 help by developing guidelines?
Information: Privacy, Proprietary, Financial, Sensitive Information Systems: Mission Critical, Support, Administrative
What system does NIST 800-60 not apply to?
All Federal Information Systems except "National Security Systems".
How does FISMA define a "National Security System"?
As any information system used or operated for the function of intelligence activities, and processing classified information.
How many documents were developed to contribute to the Federal Information Security Management Act (FISMA) of 2002?
A series of nine documents. They are structured, but flexible. Address selecting, specifying, employing, evaluating, and monitoring security controls.
What does the Federal Enterprise Architecture (FEA) define?
It defines Security Categorization starts with the identification of what information supports which government lines of business.
What does FIPS 199 help assist within an organization?
Helps ensure that each information system receives the appropriate management oversight and reflects the needs of the organization as a whole. Proper security resources are given and not under/over allocated.
What results of an incorrect information system impact analysis? (FIPS 199)
Can result in the agency either over protection the information system; thus wasting resources OR under protecting and placing important operations at risk.
How often should the categorization of the information or information system be revisited?
At least every three years or when a significant change occurs to the system or supporting lines of business.
For Step 1 (Categorize Information Systems) of the RMF process, what two documents assist with guiding?
FIPS 199 NIST SP 800-60
For Step 2 (Select Security Controls) of the RMF Process, what two documents assist with guiding?
FIPS 200 NIST SP 800-53
What is the output from Step 2 of the RMF Process (Select Security Controls)?
The System Security Plan (SSP) or Just SP
For Step 3 (Implement Security Controls) of the RMF process, what document assists with guiding?
NIST SP 800-70
For Step 4 (Assess Security Controls), of the RMF process, what document assists with guiding?
NIST SP 800-53A
What is the output for Step 4 - Assess Security Controls?
A Security Assessment Report
For Step 5 (Authorize Information Systems), of the RMF process, what document assists with guiding?
NIST SP 800-37
What is the output for Step 5 - Authorize Information Systems?
A Plan of Actions & Milestones (POA&M)
For Step 6 (Monitor Security State), of the RMF process, what two documents assist with guiding?
NIST SP 800-37 NIST SP 800-53A
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials