FIPS 199 System Categorization: Getting the First Step Right | MS Capital Resource Library
RMF · Categorization

FIPS 199 System Categorization: Getting the First Step Right

6 min read · Updated [Date]

Key Takeaways

  • FIPS 199 categorization is the first real decision point in RMF — everything downstream inherits it.
  • Confidentiality, Integrity, and Availability are rated independently. The system's overall category is the highest of the three — never an average.
  • The most expensive mistake isn't picking the wrong level. It's picking one with no documented reasoning behind it.
Executive Summary

Every authorized system starts with a categorization decision — Low, Moderate, or High — based on how much damage a loss of confidentiality, integrity, or availability would actually cause. This decision sets the control baseline, the SSP scope, and the assessment timeline for everything that follows. The organizations that struggle later are almost never the ones that categorized High when they should have categorized Low, or vice versa — they're the ones that made the call quickly, didn't document why, and can't defend it when an assessor asks six months later.

Busy executives can stop here. The full guide below is for the team doing the categorization work.

The Full Guide

Every authorization effort has a moment where the real timeline gets set — not at kickoff, not at the assessment, but at categorization. FIPS 199 asks a deceptively simple question: how bad would it be if this system's confidentiality, integrity, or availability were compromised? The answer determines your control baseline, shapes your SSP, and quietly sets the ceiling or floor for how much work is ahead of you.

What FIPS 199 Actually Measures

FIPS 199 categorizes a system against three security objectives — the CIA triad:

  • Confidentiality — preventing unauthorized disclosure of information
  • Integrity — ensuring data hasn't been altered or corrupted
  • Availability — ensuring the system is accessible when it needs to be

Each objective gets its own impact rating: Low, Moderate, or High.

The High Water Mark Rule

The system's overall categorization is the highest of the three ratings. A single High rating anywhere makes the whole system High, regardless of how the other two objectives score. Averaging, or picking "mostly Moderate," isn't how this works.

The Process, Step by Step

  • Identify the information types the system actually handles, using NIST SP 800-60 as the reference — not the system's general function, the actual information moving through it.
  • Assign impact levels to each CIA objective, for each information type, independently.
  • Determine the overall impact level — the highest rating across every information type and every objective.
  • Document the reasoning — not just the final level, but why it was chosen.

That fourth step is where most of the real damage happens later. A categorization without documented justification is a categorization nobody can defend when an assessor asks "why Moderate, not High?"

A Concrete Comparison

Public Informational Website

No login, no personal data. Reasonably lands at Low across all three objectives.

Medical Records System

High confidentiality, high integrity, moderate availability — landing the whole system at High, driven by the highest of the three.

Same exercise, very different outcomes, because the information — not the system's general purpose — is what drives the rating.

Where Teams Get This Wrong

  • Categorizing by system type, not information type. "It's an internal tool" isn't a categorization — what data does it actually touch?
  • Underestimating availability. Non-customer-facing doesn't mean low-impact.
  • Copy-paste categorization. Reusing last year's answer without re-examining what's changed.
  • No documented justification. The level survives; the reasoning behind it doesn't.

Why This Ripples Forward

Your FIPS 199 categorization feeds directly into control baseline selection, SSP scope and structure, and how your risk assessments and POA&M get sized. Get it wrong, and you're either over-building controls the system never needed, or discovering mid-assessment that you've under-built the ones it did.

Where to Go From Here

The honest test: can you point to the specific information type behind each of your C, I, and A ratings — individually — and explain why? If the answer is "not really," that's worth fixing before anything downstream gets built on top of it.

Choose Your Next Step

Doing This Yourself

Download the Worksheet

Self-serve categorization, guided step by step, with the official NIST references built in.

Get the Template
Want an Expert

Talk to MS Capital

Have someone who's carried the accountability for this call before get it right the first time.

Book a Discovery Call
MS Capital, LLC