CATEGORIZATION PHASE 1

  • Categorization starts withĀ a kick offĀ meeting (Security Analyst, ISSO, AO, System Owner and Information Owner)
  • System is categorized based onĀ information typeĀ (Process, Store or Transmit)
  • FIPS 199-Overall system categorization is based on the high watermark of theĀ CIA-Low, Moderate or High.Ā SP 800-60
  • Initial Risk Assessment Report –Identifies threat, Vulnerability, Impact level and Recommendation. SP 800-30
  • PTA –To determine if system deals with PII. PTA is positive if PII is collected if not PTA is negative. SP 800-122
  • PIAĀ is conducted if PTA is positive-Identify risk for collecting PII and controls in place to protect the PII. PIA applies to system (Federal Facilitated Market Place website) and SORN applies to program (e.g. Obamacare-the Affordable Care Act). Federal Facilitated Market Place website is one of the numerous systems that support the Obamacare. SP 800-122
  • TPWA:Ā OMBĀ Memorandum 10-23 requires that agencies assess third-party Websites and applications to ensure privacy before using them. Example CMS page on Facebook. CMS needs to complete TPWA on Facebook before creating a Facebook page
  • SORNĀ is generally required when a group of records maintained by aĀ federal system contains PIIĀ and that PII is retrieved by information unique (name, address, email address, telephone number, social security number, etc.) to the individual whose PII is being retrieved(SORN identifies purpose for collecting PII, ensuring accuracy and how the PII is protected). SORN applies toĀ ProgramsĀ (e.g. Obamacare) not systems.
  • OMB Number:Ā The Paperwork Reduction Act mandates that all federal government agencies receive approval from OMB—in the form of a “control number”—before promulgating a paper form, website, survey or electronic submission that will impose an information collection burden on the general public. This only applies if the agency is collecting the information directly from the public not from another agency or system.
  • E-authenticationĀ is applicable when system is accessible remotely. This identify the appropriate authentication mechanism base on risk-Ā single multifactor etc… SP 800-63.

CATEGORIZATION PHASE 1 – SmartThink LLC

CATEGORIZATION PHASE 1

  • Categorization starts withĀ a kick offĀ meeting (Security Analyst, ISSO, AO, System Owner and Information Owner)
  • System is categorized based onĀ information typeĀ (Process, Store or Transmit)
  • FIPS 199-Overall system categorization is based on the high watermark of theĀ CIA-Low, Moderate or High.Ā SP 800-60
  • Initial Risk Assessment Report –Identifies threat, Vulnerability, Impact level and Recommendation. SP 800-30
  • PTA –To determine if system deals with PII. PTA is positive if PII is collected if not PTA is negative. SP 800-122
  • PIAĀ is conducted if PTA is positive-Identify risk for collecting PII and controls in place to protect the PII. PIA applies to system (Federal Facilitated Market Place website) and SORN applies to program (e.g. Obamacare-the Affordable Care Act). Federal Facilitated Market Place website is one of the numerous systems that support the Obamacare. SP 800-122
  • TPWA:Ā OMBĀ Memorandum 10-23 requires that agencies assess third-party Websites and applications to ensure privacy before using them. Example CMS page on Facebook. CMS needs to complete TPWA on Facebook before creating a Facebook page
  • SORNĀ is generally required when a group of records maintained by aĀ federal system contains PIIĀ and that PII is retrieved by information unique (name, address, email address, telephone number, social security number, etc.) to the individual whose PII is being retrieved(SORN identifies purpose for collecting PII, ensuring accuracy and how the PII is protected). SORN applies toĀ ProgramsĀ (e.g. Obamacare) not systems.
  • OMB Number:Ā The Paperwork Reduction Act mandates that all federal government agencies receive approval from OMB—in the form of a “control number”—before promulgating a paper form, website, survey or electronic submission that will impose an information collection burden on the general public. This only applies if the agency is collecting the information directly from the public not from another agency or system.
  • E-authenticationĀ is applicable when system is accessible remotely. This identify the appropriate authentication mechanism base on risk-Ā single multifactor etc… SP 800-63.

CATEGORIZATION PHASE 1 – SmartThink LLC

Categorization Phase 1

Lesson Progress
0% Complete

Federal information systems are categorized base on the information the systems processstore, or transmit.

Information processed, stored and transmitted by a system is classified based on the impact level (Low, Moderate or High) assigned to the security objectives-Confidentiality, Integrity and Availability (CIA)

The highest impact level (Low, Moderate and High) of the CIA becomes the overall classification of the system-High water mark

Systems are categorized based on information type
Two NIST publications are used to guide in this process

  • NIST SP 800-60            
  • FIPS 199

FIPSĀ 199

The categorization process starts with a kick off meeting involving the following people:

  • System Owner (SO)
  • Security Control Assessor/ C&A Analyst
  • Information System Security Officer (ISSO)
  • Information Owner/Data owner
  • Authorizing Official
  • System Developers
  • System Admin

Sample Kick off meeting email/Agenda

First deliverable/Artifact -FIPS 199/System categorization
Links: