2.3 System Categorization Process & Impact Analysis (FIPS 199 / SP 800-60)

Key Takeaways

  • FIPS 199 establishes mandatory federal standards for categorizing information and information systems across three security objectives: Confidentiality, Integrity, and Availability.
  • Potential impact levels under FIPS 199 are strictly defined as Low (limited adverse effect), Moderate (serious adverse effect), and High (severe or catastrophic adverse effect).
  • NIST SP 800-60 Rev. 1 provides a systematic two-volume process to map specific government information types to provisional security categories and tailor them based on operational context.
  • The overall System Security Category is determined using the High-Water Mark (HWM) rule, where the system category equals the highest rating assigned across the three security objectives for all hosted information types.
  • Special data classifications, such as PII, Controlled Unclassified Information (CUI per NIST SP 800-171), and National Security Systems (CNSSI 1253), introduce specialized categorization baselines and non-watermark overlays.
Last updated: August 2026

System Categorization Process & Impact Analysis (FIPS 199 / SP 800-60)

Core Blueprint Focus: System categorization is the initial operational step (Step 1) of the NIST RMF. It dictates the entire baseline security and privacy control allocation (NIST SP 800-53 Rev. 5). Categorizing too low creates severe organizational vulnerability and non-compliance; categorizing too high wastes millions of dollars implementing unnecessary controls.

Categorization is governed primarily by two mandatory federal publications:

  1. FIPS Publication 199 (Standards for Security Categorization of Federal Information and Information Systems): Establishes the definitions of security objectives and potential impact levels.
  2. NIST SP 800-60 Rev. 1 (Guide for Mapping Types of Information and Information Systems to Security Categories, Volumes I & II): Provides the execution methodology and catalog of information types aligned with the Federal Enterprise Architecture (FEA).

The FIPS 199 Triad: Objectives & Impact Levels

FIPS 199 evaluates risk across the three fundamental pillars of information security, assigning an impact rating to each objective:

  • Confidentiality: Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. A loss of confidentiality is the unauthorized disclosure of information.
  • Integrity: Guarding against improper information modification or destruction, including ensuring information non-repudiation and authenticity. A loss of integrity is the unauthorized modification or destruction of information.
  • Availability: Ensuring timely and reliable access to and use of information. A loss of availability is the disruption of access to or use of information or an information system.

FIPS 199 Potential Impact Levels

FIPS 199 defines three precise, standardized levels of potential impact on organizational operations (mission, functions, image, or reputation), organizational assets, or individuals:

Impact LevelStatutory Definition (FIPS 199)Operational & Real-World Consequences
LOWThe loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.• Causes a minor degradation in mission capability to the point where the organization can perform primary functions, but effectiveness is noticeably reduced.<br>• Results in minor damage to organizational assets.<br>• Incurs minor financial loss.<br>• Results in minor harm to individuals (e.g., minor inconvenience, no financial distress, no physical injury).
MODERATEThe loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.• Causes a significant degradation in mission capability to the point where the organization can perform primary functions, but effectiveness is significantly reduced.<br>• Results in significant damage to organizational assets.<br>• Incurs significant financial loss.<br>• Results in significant harm to individuals that does not involve loss of life or serious life-threatening injuries (e.g., substantial financial loss, significant identity theft, severe privacy violation).
HIGHThe loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.• Causes a severe degradation in or total loss of mission capability to the point where the organization cannot perform one or more primary functions.<br>• Results in major damage to organizational assets.<br>• Incurs catastrophic financial loss.<br>• Results in severe harm to individuals involving loss of life or serious, life-threatening injuries, or complete destruction of personal livelihood.

NIST SP 800-60 Rev. 1 Categorization Methodology

NIST SP 800-60 Rev. 1 bridges abstract impact definitions and concrete operational data types through a four-step execution process:

+-----------------------------------------------------------------------------------+
|                     NIST SP 800-60 CATEGORIZATION METHODOLOGY                     |
|                                                                                   |
|  [ Step 1: Identify Info Types ]                                                  |
|  • Inventory all data processed, stored, transmitted (FEA Business Ref Model)     |
|                           |                                                       |
|                           v                                                       |
|  [ Step 2: Select Provisional Impact Levels ]                                     |
|  • Consult SP 800-60 Vol. II for baseline C-I-A values per info type              |
|                           |                                                       |
|                           v                                                       |
|  [ Step 3: Review & Adjust Provisional Levels ]                                   |
|  • Assess contextual factors: aggregation risk, mission criticality, public data   |
|                           |                                                       |
|                           v                                                       |
|  [ Step 4: Determine Overall System High-Water Mark ]                             |
|  • SC system = {(C, max), (I, max), (A, max)} => System Baseline Determination    |
+-----------------------------------------------------------------------------------+

Step 1: Identify Information Types

The system owner and security team inventory all distinct types of information input, stored, processed, or output by the system. NIST SP 800-60 Volume II maps these to standard government mission lines (e.g., C.2.4 Financial Management, C.3.5 Health Care Records, D.1.1 Human Resource Management, D.16.1 Information Security).

Step 2: Select Provisional Impact Levels

For each identified information type, the team looks up the baseline recommended provisional impact ratings in NIST SP 800-60 Vol. II. For example, Public Relations data may be provisionally rated as {(Confidentiality, Low), (Integrity, Moderate), (Availability, Low)}, whereas Payroll Information may be provisionally rated as {(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Moderate)}.

Step 3: Review and Adjust Provisional Impact Levels

Provisional ratings are not final. The organization must adjust levels based on specific contextual and environmental realities:

  • Aggregation Risk: Large aggregations of otherwise low-impact data records (e.g., millions of public employee directory records or non-sensitive log entries) can represent a high-value target when correlated, justifying an upward adjustment for Confidentiality.
  • Criticality to Mission Function: If a specific system's downtime will immediately ground national airspace or halt emergency first responder dispatch, the Availability rating must be adjusted upward to High.
  • Public Information Exception: For data intentionally published for public consumption (e.g., weather reports, public press releases), Confidentiality is explicitly designated as Not Applicable (NA) or Low, while Integrity often remains Moderate or High to prevent unauthorized defacement or disinformation.

Step 4: Determine the Overall System Security Category (High-Water Mark)

The security category of an information system is expressed as an ordered set containing the maximum impact rating for each security objective across all contained information types:

SCsystem={(Confidentiality,max(Ci)),(Integrity,max(Ii)),(Availability,max(Ai))}\text{SC}_{\text{system}} = \{ (\text{Confidentiality}, \max(C_i)), (\text{Integrity}, \max(I_i)), (\text{Availability}, \max(A_i)) \}


High-Water Mark Calculation Example

Consider an enterprise human resources and operational logistics system hosting three distinct information types:

Information TypeConfidentiality ImpactIntegrity ImpactAvailability Impact
1. Public Job PostingsLow (Publicly available)Moderate (Prevent tampering)Low (Short outage tolerable)
2. Employee PII & PayrollModerate (Privacy Act data)Moderate (Accurate disbursement)Moderate (Payroll deadlines)
3. Emergency Disaster DispatchLow (Unclassified operations)Moderate (Data accuracy)High (Life safety communication)
System High-Water MarkMODERATEMODERATEHIGH

In this scenario, the resulting system category is: SCHR-Logistics={(Confidentiality,MODERATE),(Integrity,MODERATE),(Availability,HIGH)}\text{SC}_{\text{HR-Logistics}} = \{ (\text{Confidentiality}, \text{MODERATE}), (\text{Integrity}, \text{MODERATE}), (\text{Availability}, \text{HIGH}) \}

Because the highest individual water mark across the entire triad is HIGH (driven by Availability), the system is classified as an overall FIPS 199 HIGH-impact system. Under NIST SP 800-53 Rev. 5, the initial baseline control selection will default to the High baseline, which can subsequently be tailored during RMF Step 2 (Select).


Special Data Classifications & Regulatory Overlays

When performing categorization, GRC practitioners must account for specific legal regimes and data classifications:

Personally Identifiable Information (PII) & Privacy

Under the Privacy Act of 1974 and OMB Circular A-130, systems maintaining PII must undergo a Privacy Threshold Analysis (PTA) and, if PII is confirmed, a full Privacy Impact Assessment (PIA). The potential harm to individuals from identity theft, financial ruin, or harassment must directly influence the FIPS 199 Confidentiality impact level.

Controlled Unclassified Information (CUI)

Governed by Executive Order 13556 and 32 CFR Part 2002, CUI is sensitive federal information requiring safeguarding and dissemination controls. Systems processing CUI (e.g., defense contractors subject to NIST SP 800-171 or CMMC) typically mandate a minimum baseline of FIPS 199 Moderate across Confidentiality and Integrity.

National Security Systems (NSS) & CNSSI 1253

Systems processing classified or national security information are governed by CNSSI 1253 (Security Categorization and Control Selection for National Security Systems). Unlike civilian NIST RMF systems, CNSSI 1253 does NOT use a single global high-water mark to select all controls. Instead, it selects controls independently for each objective (Confidentiality, Integrity, Availability), allowing precise control baseline mapping.


Categorization Traps & Critical Governance Rules

[!IMPORTANT] Categorization Represents Inherent Risk, NOT Residual Risk: A common mistake is attempting to downgrade a system's FIPS 199 categorization because the system has implemented strong firewalls, multifactor authentication, or encryption. Categorization reflects the inherent potential harm if the information or system were compromised, completely independent of whatever security controls are currently deployed.

[!WARNING] Over-Categorization Pitfall: Unjustifiably assigning a "High" categorization to a system whose true impact is Moderate inflates control implementation and assessment costs by 300% to 500%, requiring continuous monitoring tools, multi-site hardware failovers, and invasive physical controls that may be entirely disproportionate to actual mission risk.

Loading diagram...
FIPS 199 & NIST SP 800-60 Categorization Decision Tree
Test Your Knowledge

An emergency medical dispatch system stores publicly accessible hospital directory listings (Confidentiality: Low, Integrity: Moderate, Availability: Low) and real-time 911 telemetry data whose immediate failure would directly cause loss of human life (Confidentiality: Low, Integrity: High, Availability: High). What is the overall FIPS 199 security category and overall impact rating for this system?

A
B
C
D
Test Your Knowledge

Under FIPS 199, how is a 'MODERATE' potential impact level formally defined in terms of its effect on organizational operations, assets, or individuals?

A
B
C
D
Test Your Knowledge

An Information System Security Officer (ISSO) recommends lowering a system's FIPS 199 Confidentiality impact level from High to Low because the engineering team has installed an advanced cryptographic hardware module and next-generation firewalls. Why is this recommendation fundamentally flawed?

A
B
C
D