2.2 Identifying Information Types with NIST SP 800-60

Key Takeaways

  • Categorization operates on information types, not on the system as a whole, so a complete and defensible inventory of types is the mandatory input to FIPS 199.
  • NIST SP 800-60 Volume I gives the method and Volume II supplies provisional confidentiality, integrity, and availability impact levels for each catalogued information type.
  • Provisional impact levels are a starting point that must be adjusted for mission context, aggregation, time-criticality, and public availability, with every adjustment justified in writing.
  • Information types divide into mission-based types drawn from lines of business and management/support types that appear in nearly every system.
  • Aggregation can raise an impact level above every individual component type, which is the single most commonly missed adjustment on the exam.
Last updated: August 2026

Identifying Information Types with NIST SP 800-60

FIPS 199 does not categorize systems directly. It categorizes information types, then derives the system category from them. That sequencing is why identifying information types is a distinct blueprint task, and why a system whose type inventory is incomplete cannot produce a defensible categorization no matter how carefully the high-water mark is later computed.


1. What Counts as an Information Type

An information type is a specific category of information — defined by law, executive order, directive, policy, or organizational mission — that shares a common set of protection requirements. "Database records" is not an information type. "Payroll and benefits information" is.

NIST SP 800-60 Rev. 1 splits the guidance across two volumes, and the exam expects you to know which does what:

VolumeTitleContains
Volume IGuide for Mapping Types of Information and Information Systems to Security CategoriesThe methodology — how to identify types, assign impact, and adjust
Volume IIAppendices to Guide for Mapping Types…The catalog — hundreds of named information types with provisional C, I, and A impact levels plus the rationale for each

[!IMPORTANT] A recurring exam distractor treats Volume II's ratings as binding. They are explicitly provisional. NIST supplies them so organizations start from a defensible reference point, not so they skip analysis. The system owner is responsible for the final rating, and the rationale for accepting or adjusting each provisional value belongs in the categorization documentation.

Two Families of Information Types

Mission-based information types derive from what the organization exists to do, organized around lines of business — disaster management, law enforcement, health care delivery, revenue collection, education. These vary sharply between organizations, and their impact levels vary with them: "inspection and auditing information" carries very different consequences at a food-safety agency than at a licensing board.

Management and support information types appear in nearly every organization regardless of mission — human resources, payroll, procurement, facilities, IT infrastructure management, public affairs, records retention. Because they are ubiquitous, their provisional ratings in Volume II are stable and reusable across systems, which makes them an efficient starting point.

Almost every real system holds both families. A grants-management platform holds mission-based grant information and management-based financial and personnel information. Missing the second family is a common cause of under-categorization.


2. The Identification Procedure

  1. Document the system's purpose and functionality (blueprint task 2.1) — you cannot enumerate data types without knowing what the system does.
  2. Walk the data flow. For every input, datastore, interface, report, log, backup, and export, ask what information it carries. Interfaces and backups are where undocumented types hide.
  3. Name each type using SP 800-60 Volume II terminology wherever a match exists, and define any organization-specific type explicitly.
  4. Record the processing relationship — is the type processed, stored, or transmitted? The blueprint uses all three verbs deliberately: a system that merely transmits a type still bears protection obligations for it.
  5. Retrieve the provisional C/I/A levels from Volume II for each type.
  6. Adjust for context and document the justification.
  7. Apply the high-water mark across all types to derive the system security category.

Special Categories That Change the Analysis

  • Personally Identifiable Information (PII) triggers privacy obligations that run parallel to security categorization — a Privacy Threshold Analysis, potentially a Privacy Impact Assessment, and privacy control selection that is not driven by the security high-water mark.
  • Controlled Unclassified Information (CUI) is governed by the NARA CUI Registry under 32 CFR Part 2002, which defines categories such as Export Control, Critical Infrastructure, and Privacy. CUI designation drives marking, dissemination, and — in the defense supply chain — CMMC obligations.
  • National Security Information moves the system out of the FIPS 199 / SP 800-53B track entirely and into CNSSI 1253, which categorizes C, I, and A independently instead of using a single high-water mark.

3. Adjusting Provisional Impact Levels

Volume I identifies special factors that legitimately move a provisional rating up or down. These are the exam's favourite territory because they require judgment rather than lookup.

FactorDirectionExample
AggregationUpIndividually innocuous personnel fields combine into a re-identifying dossier, raising confidentiality from Low to Moderate or High.
Time-criticalityUpRoutine inspection data is Low for availability — unless it feeds a real-time safety interlock, where minutes of outage cause harm.
Public availabilityDownInformation already lawfully published cannot be harmed by disclosure, so confidentiality is genuinely Low. Integrity often stays high: a defaced public advisory still misleads the public.
Mission dependencyUpA type that appears minor in isolation may be the sole input to a critical downstream process.
Regulatory designationUpStatutory protection (Privacy Act, HIPAA, tax return information under 26 U.S.C. § 6103) sets a floor regardless of volume.

Aggregation Is the Classic Trap

The aggregation effect states that a collection of information may warrant a higher impact level than any individual element within it. A single employee's duty station is unremarkable. The duty stations of every field officer in a division, downloadable as one file, is an operational-security exposure. Exam scenarios frequently describe a consolidated data warehouse or reporting system built from several Low-impact feeds and ask for the categorization — the correct answer usually reflects an upward adjustment for aggregation, not a mechanical high-water mark of the inputs.

[!NOTE] Downward adjustments carry the heavier burden of proof. Raising a level is conservative and rarely challenged. Lowering one requires documented justification that survives assessor scrutiny, and it must rest on the inherent nature of the information — never on the strength of implemented controls. "We encrypt it, so confidentiality is Low" is invalid reasoning; categorization measures potential impact if compromise occurs, independent of safeguards.


4. Documenting the Result

The categorization record must show, for each information type: its name and definition, whether it is processed, stored, or transmitted, its provisional C/I/A levels with the Volume II reference, the adjusted levels, and the written rationale for every adjustment. The system security category and overall impact level follow from that table.

This documentation is reviewed and approved by the Information System Owner in coordination with the Information Owner/Steward, with Senior Agency Official for Privacy involvement wherever PII is present, and is ultimately accepted by the Authorizing Official. Because the entire control baseline is derived from this single artifact, an assessor who finds an undocumented or unjustified information type has found a defect that invalidates everything downstream — the baseline, the SSP, and the assessment scope alike.

Loading diagram...
From Information Types to System Security Category
Test Your Knowledge

An agency consolidates six separate Low-impact regional inspection feeds into a single national reporting warehouse that allows analysts to query the complete history of every inspected facility. Under NIST SP 800-60, what categorization outcome should the system owner most likely document?

A
B
C
D
Test Your Knowledge

Which statement correctly describes the role of the impact levels published in NIST SP 800-60 Volume II?

A
B
C
D
Test Your Knowledge

A system owner proposes lowering an information type's confidentiality impact from Moderate to Low on the grounds that the data is already published on the agency's public website. How should the assessor evaluate this proposed adjustment?

A
B
C
D