Articles

Classifying information: impact levels before labels

The impact level is the decision; the label only carries it to the object it governs.

Reading: 5 minCybersecurity Governance

Article cover: Classifying information: impact levels before labels

Classification is a governance decision about information, taken before any control is chosen. FIPS 199 asks what the potential impact of a loss would be for a named information type and returns a level; a system boundary, a control baseline and a priority then consume that answer. Labelling and marking are where the decision reaches the object it governs, and a label that no rule reads decides nothing.

From information type to impact level

FIPS 199 defines three potential-impact levels, assessed one security objective at a time: a loss is LOW where it “could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals”, MODERATE where the effect would be serious, and HIGH where it would be “severe or catastrophic” (lines 170–204). The answer is written as a triple, SC information type = {(confidentiality, impact), (integrity, impact), (availability, impact)} (line 224), and it belongs to an information type, not to information in general. A system’s category is the “highest values (i.e., high water mark)” found among the types it holds (line 265). The properties and their losses are the L1 sheet’s subject; here they are the input.

information type  (a named class of information)
      ↓  impact analysis, one objective at a time
potential impact level   LOW | MODERATE | HIGH     (per information type)
      ↓  security category
SC = {(confidentiality, impact), (integrity, impact), (availability, impact)}
      ↓  high-water mark across the types one system holds
system category  →  baseline, boundary, inventory mapping, priority
      ↓
label, marking: the decision bound to the object it governs

A decision needs a rationale and an approver

RA-2 in SP 800-53r5 does not ask for a feeling about sensitivity; it asks for a record. The control requires “Categorize the system and information it processes, stores, and transmits”, “Document the security categorization results, including supporting rationale, in the security plan for the system” and “Verify that the authorizing official or authorizing official designated representative reviews and approves the security categorization decision” (lines 15807–15813) — two of the three are about the trail, not the level. The discussion names who takes part: categorisation is “an organization-wide activity” involving system owners, mission and business owners and information owners or stewards (lines 15824–15827).

Provisional first, then reviewed

NIST SP 800-60 Rev. 1 Vol. I is the route to a starting level per information type. In Step 2 an organisation “establish[es] provisional impact levels based on the identified information types in Step 1” — the levels for each objective, “before any adjustments are made” (lines 1024–1028). Step 3 has it review and adjust those levels and “document all adjustments to the impact levels and provide the rationale or justification” (lines 1237–1243). The level is not a property of the words on the page: in the guideline’s own example, contract information carries a moderate confidentiality impact “during the life of the contract” and a low one “when the contract is completed” (lines 1259–1261).

What the categorisation decides

The category is an input to records the organisation already keeps. RA-2 states that categorisation processes “facilitate the development of inventories of information assets and, along with CM-8, mappings to specific system components” (line 15831). SP 800-18r1 puts it earlier: before a security plan exists, the information “resident within that system must be categorized based on a FIPS 199 impact analysis”, and “The FIPS 199 impact levels must be considered when the system boundaries are drawn and when selecting the initial set of security controls (i.e., control baseline)” (lines 523–529). FIPS 200 states the sequence: categorisation “is the first step in the risk management process”, before controls are selected (lines 383–390). CSF 2.0 asks for the same outcome in one subcategory: “Assets are prioritized based on classification, criticality, resources, and impact on the mission” (ID.AM-05, lines 877–878).

How the decision reaches the object

A level recorded in a plan governs nothing on its own. SP 800-53r5 names the two mechanisms that carry the decision to the object: “Labeling refers to the association of attributes with the subjects and objects represented by the internal data structures within systems”, and this “facilitates system-based enforcement”; “Marking” is “the association of attributes with objects in a human-readable form”, and it “enables manual, procedural, or process-based enforcement” (AC-16, lines 3974–3985). Both are bindings: a value attached to something, read by a rule — a reading of those two sentences, not their wording. The MP-3 control in SP 800-53r5 then requires media to carry “the distribution limitations, handling caveats, and applicable security markings (if any)” (line 11763).

What classification does not decide

FIPS 199 categorises information types and systems; it prescribes no label scheme. The vocabulary AC-16 offers — “top secret, secret, confidential, controlled unclassified” — is described there as “classification of information in accordance with legal and compliance requirements” (line 3976), and MP-3 sends controlled unclassified information to 32 CFR 2002: that wording comes from legal regimes, not from a ladder the standards define. A scheme such as public, internal, secret is an organisational choice, and no source here standardises one. Nor is a level fixed for life: RA-2 has the categorisation “revisited throughout the system development life cycle” (line 15833).

Level and prerequisites

L2 — operational: how the classification decision is taken, recorded and carried to the object, without the impact-assessment methodology. Prerequisites: the L1 sheets on confidentiality, integrity and availability (the three properties and their losses) and on assets, processes, data and dependencies (what is classified).

Where to go next

References

  • NIST — FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems (February 2004) — https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf — the three potential-impact levels and their adverse-effect wording, the security category of an information type, and the high-water mark for a system.
  • NIST — SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations — https://doi.org/10.6028/NIST.SP.800-53r5 — RA-2 Security Categorization (statement, roles, inventory mapping), AC-16 Security and Privacy Attributes (labelling and marking) and MP-3 Media Marking.
  • NIST — SP 800-60 Rev. 1 Vol. I, Guide for Mapping Types of Information and Information Systems to Security Categories (August 2008) — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf — Step 2 provisional impact levels, Step 3 review and adjustment with documented rationale, and the life-cycle example.
  • NIST — SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Systems (February 2006) — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf — categorisation before boundary drawing and control-baseline selection.
  • NIST — FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems (March 2006) — https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf — categorisation as the first step in the risk management process and the three control baselines.
  • NIST — The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29, 26 February 2024) — https://doi.org/10.6028/NIST.CSWP.29 — ID.AM-05, assets prioritised on classification, criticality, resources and mission impact.