2.4 Impact and Risk Determination Under Non-Federal Frameworks

Key Takeaways

  • The CGRC blueprint requires impact determination 'based on the selected framework', so the FIPS 199 high-water mark is only one of several valid methods.
  • ISO/IEC 27001 requires the organization to define its own risk criteria and risk acceptance criteria rather than supplying prescribed impact levels.
  • A GDPR Data Protection Impact Assessment is legally mandatory in the three circumstances listed in Article 35(3) and must include the four elements in Article 35(7).
  • PCI DSS replaces impact levels with scoping: obligations follow the cardholder data environment and connected systems, and validation method follows merchant or service provider level.
  • CMMC assigns levels by data type — Federal Contract Information versus Controlled Unclassified Information — rather than by a computed impact rating.
Last updated: August 2026

Impact and Risk Determination Under Non-Federal Frameworks

The CGRC blueprint phrases task 2.2 carefully: the risk impact level is determined "based on the selected framework." Candidates who assume every scenario is a federal RMF scenario will misanswer any item set in a commercial, international, or contractual context. This section covers what replaces FIPS 199 when the governing regime is something else.


1. Why the Method Changes With the Framework

FIPS 199 is unusual: it prescribes three fixed impact levels, a fixed set of objectives, and a fixed combination rule. Most other frameworks do the opposite — they require the organization to define its own criteria and then apply them consistently.

FrameworkWhat Determines "Impact"Output
NIST RMF / FIPS 199Prescribed Low/Moderate/High per C, I, A; high-water markSystem security category → SP 800-53B baseline
ISO/IEC 27001 + 27005Organization-defined risk criteria and acceptance criteriaRisk treatment plan + Statement of Applicability
GDPRRisk to the rights and freedoms of natural personsDPIA; possibly prior consultation with the supervisory authority
PCI DSSScope of the cardholder data environment; merchant/service provider levelApplicable requirements + validation method (SAQ or ROC)
CMMCType of data handled (FCI vs. CUI)CMMC Level 1, 2, or 3
FedRAMPFIPS 199 category of the cloud serviceLow, Moderate, High, or Li-SaaS baseline

[!IMPORTANT] Notice the pivot. NIST asks "how bad would compromise be for the organization?" GDPR asks "how bad would processing be for the individual?" These can point in opposite directions: a marketing analytics platform may be trivially Low-impact to the organization while creating high risk to data subjects. Reading the exam item for whose harm is being measured resolves most confusion here.


2. ISO/IEC 27001 and ISO/IEC 27005

ISO/IEC 27001 does not tell you what "high risk" means. Clause 6.1.2 requires the organization to establish and maintain information security risk criteria, including risk acceptance criteria and criteria for performing assessments, and then to apply them so results are consistent, valid, and comparable. ISO/IEC 27005 supplies the supporting guidance for doing that.

The process runs: establish context and criteria → risk identificationrisk analysis (estimate consequence and likelihood) → risk evaluation (compare against criteria and prioritize) → risk treatment (modify, retain, avoid, or share) → obtain risk owner approval of the treatment plan and acceptance of residual risk.

Two ISO artifacts have no NIST equivalent and are examinable:

  • The Statement of Applicability (SoA) lists every Annex A control, states whether it is applicable, gives the justification for inclusion or exclusion, and records implementation status. It is the central certification artifact — roughly the ISO analogue of the control-selection portion of an SSP.
  • The risk owner is a named individual accountable for a specific risk, who must approve its treatment and accept the residual risk. Functionally parallel to the Authorizing Official, but scoped per risk rather than per system.

ISO/IEC 27002:2022 provides the implementation guidance, reorganized into 93 controls across four themes — Organizational (37), People (8), Physical (14), and Technological (34) — replacing the previous 114 controls in 14 clauses.


3. The GDPR Data Protection Impact Assessment

A DPIA is not discretionary. Article 35(1) requires one whenever processing is "likely to result in a high risk to the rights and freedoms of natural persons." Article 35(3) makes it mandatory in three specific cases:

  1. Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where decisions produce legal effects or similarly significantly affect the individual.
  2. Large-scale processing of special categories of data (Article 9 — health, biometrics, race, religion, sexual orientation, political opinions) or of criminal conviction and offence data (Article 10).
  3. Systematic monitoring of a publicly accessible area on a large scale — the CCTV and public-space analytics case.

Article 35(7) fixes the minimum content: a systematic description of the processing and its purposes; an assessment of necessity and proportionality; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks, including safeguards and demonstrations of compliance.

Article 36 adds the escalation rule that exam items like to test: if the DPIA indicates the processing would result in a high residual risk in the absence of mitigating measures, the controller must consult the supervisory authority before processing begins. The Data Protection Officer advises on the DPIA where one is designated.

DPIAPrivacy Impact Assessment (US federal)
Required by GDPR Article 35Required by the E-Government Act of 2002 § 208
Measures risk to individuals' rights and freedomsAnalyzes handling of PII in information systems
May require prior consultation with a supervisory authorityReviewed by the SAOP; generally published
Applies to controllers regardless of sectorApplies to US federal agencies

4. PCI DSS: Scoping Instead of Impact Levels

PCI DSS has no impact ratings at all. Two different questions replace them.

What is in scope? The cardholder data environment (CDE) comprises the people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data — plus all connected-to and security-impacting systems. Because scope is the primary cost driver, network segmentation that isolates the CDE is the highest-value architectural decision available; segmentation is not required by the standard, but without it the entire network is in scope.

How is compliance validated? Validation method follows the entity's merchant level (driven by annual transaction volume) or service provider level: higher-volume entities require a Report on Compliance (ROC) produced with a Qualified Security Assessor, while lower volumes may use a Self-Assessment Questionnaire (SAQ) of the type matching their acceptance channel.

The current version is PCI DSS v4.0.1, released June 2024. The requirements originally published as future-dated best practices in v4.0 became mandatory on 31 March 2025, so the whole standard now applies. PCI DSS binds through card-brand contracts rather than statute — no less enforceable, but enforced through fines, increased transaction costs, and loss of card-acceptance privileges.


5. CMMC: Level Follows the Data

CMMC assigns requirements by what data the contractor handles, not by a computed impact score:

LevelDataRequirementsAssessment
Level 1Federal Contract Information (FCI)15 basic safeguarding requirements (FAR 52.204-21)Annual self-assessment
Level 2Controlled Unclassified Information (CUI)The 110 requirements of NIST SP 800-171Self-assessment or C3PAO certification, depending on the contract
Level 3CUI with heightened threat exposureLevel 2 plus selected NIST SP 800-172 enhancementsGovernment-led (DIBCAC) assessment

The CMMC Program rule at 32 CFR Part 170 took effect 16 December 2024, and the acquisition rule adding CMMC clauses to contracts at 48 CFR took effect 10 November 2025, introducing requirements into solicitations through a phased rollout. The practical governance consequence is that a CGRC professional supporting a defense supplier determines obligations by asking which data types flow under the contract — the same information-type analysis from the previous section, applied to a contractual rather than statutory framework.

Loading diagram...
Selecting the Correct Impact Determination Method by Framework
Test Your Knowledge

A European transit authority plans to deploy large-scale automated facial recognition across publicly accessible station concourses. Under the GDPR, what is the controller's obligation before processing begins?

A
B
C
D
Test Your Knowledge

How does ISO/IEC 27001 establish what constitutes an unacceptable level of risk for a certified organization?

A
B
C
D
Test Your Knowledge

A retailer wants to reduce the cost of its PCI DSS assessment. Which architectural decision most directly reduces the number of systems subject to the standard's requirements?

A
B
C
D