Risk Management Framework and Security Categorization

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall with Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/10

flashcard set

Earn XP

Description and Tags

This set of flashcards covers key vocabulary terms and definitions related to the Risk Management Framework and security categorization discussed in the lecture notes.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No study sessions yet.

11 Terms

1
New cards

Categorization

The process of classifying information and information systems based on their sensitivity and importance.

2
New cards

High Water Mark

The highest potential impact value assigned to each security objective for all security categories resident on an information system.

3
New cards

Sensitivity

A measure of the importance assigned to information that denotes its need for protection.

4
New cards

Criticality

A measure of the degree to which an organization depends on information for the success of a mission or business function.

5
New cards

Risk Management Framework (RMF)

A structured process to manage cybersecurity risk by implementing security controls through categorization, selection, implementation, assessment, authorization, and monitoring.

6
New cards

NIST SP 800-37

A publication that provides guidelines for applying the Risk Management Framework to federal information systems.

7
New cards

FIPS-199

Standards for Security Categorization of Federal Information and Information Systems used to determine the categorization of information types.

8
New cards

Potential Impact Levels

Levels used to describe the potential consequences of losing confidentiality, integrity, or availability of information.

9
New cards

System Security Plan (SSP)

A comprehensive document that outlines the security controls, roles, and responsibilities associated with an information system.

10
New cards

Continuous Monitoring Strategy

An ongoing process to ensure that the security controls remain effective over time.

11
New cards

Documentation

The process of formally recording all aspects of categorization, security controls, and risk assessments.