It’s easy to say a system is important. The more useful conversation is what would happen if its information got out, became unreliable, or wasn’t available when needed. Who gets hurt? What work stops? Categorize asks us to explain those consequences clearly enough that someone else can understand the impact levels we choose.
NIST’s Categorize guidance calls for a documented system description, an analysis of confidentiality, integrity, and availability impacts, and review and approval of the categorization decision by the authorizing official. NIST’s Categorize step describes the expected outcomes.
| Security objective | Low | Moderate | High |
|---|---|---|---|
| ConfidentialityUnauthorized disclosure | Limited adverse effect | Serious adverse effect | Severe or catastrophic adverse effect |
| IntegrityUnauthorized modification or destruction | Limited adverse effect | Serious adverse effect | Severe or catastrophic adverse effect |
| AvailabilityLoss of access or use | Limited adverse effect | Serious adverse effect | Severe or catastrophic adverse effect |
Document each impact level and its rationale. Use the categorization rules that apply to the system.
These impact descriptions follow FIPS 199. No category is assigned by this diagram.
Walk through the three kinds of loss
Confidentiality concerns unauthorized disclosure. Integrity concerns unauthorized modification or destruction. Availability concerns losing timely, reliable access to information or services. Keep the three conversations distinct long enough to understand what each loss would do.
A useful question for integrity is, “What decisions could someone make using information that looks right but isn’t?” For availability, ask when the loss starts causing harm and who feels it. For confidentiality, follow the consequences beyond the person who first sees the disclosure. The answers need to come from the actual mission and information, so leave the impact levels open until that analysis is done.
Bring the information owners into it
Identify the information types the system processes, stores, and transmits, then discuss the potential harm with the people responsible for them. Technical staff can explain what the system does. Mission and information owners help explain what a failure would mean to the organization and to others.
Look at the collection as well as the individual pieces. Bringing information together can change its sensitivity or importance. A service can also support another function whose consequences are easy to overlook. Document the reasoning and any adjustments using the categorization method that actually applies to the system.
Keep impact separate from confidence
Categorization asks about the potential consequences of loss. Confidence in an existing safeguard doesn’t replace that analysis. The likelihood of an event and the effectiveness of protections belong in the broader risk discussion; they don’t tell us, by themselves, what the loss would cost.
If two people choose different levels, ask them to describe the consequences they have in mind. They may be considering different information, timeframes, or dependencies. Resolve that difference in the rationale and obtain the required approval. Carry privacy concerns forward too: potential harms from processing personal information need attention beyond the security category alone.
How this applies on SAP networks
NIST gets us talking about the consequences of losing confidentiality, integrity, or availability. JSIG puts that analysis into practice for SAP systems through CNSSI 1253: determine the information and system impacts, identify applicable overlays, and involve the responsible officials in the categorization decision. The question to carry into that work is whether the chosen levels can be explained by the mission and information being protected. 2016 JSIG §2.3.1 gives the SAP-specific instructions for this step.
Let’s talk it through
Pick a question and compare how you’d approach it. Ask what information would change your answer.
- What consequence would persuade someone outside the technical team that our chosen impact level makes sense?
- Could combining information or depending on another service change the impact we first identified?
- If we disagree on a level, are we disagreeing about the harm, the scope, or how likely we think the event is?
What do we carry forward?
Carry the approved categorization and its reasoning into Select. Keep the explanation with the decision so a future change in information or mission can be compared with what we originally considered.
The Categorize section of Body of Evidence & Artifacts connects this work to the artifacts and body of evidence (BOE) you produce and maintain.