Every authorized system starts with a categorization decision — Low, Moderate, or High — based on how much damage a loss of confidentiality, integrity, or availability would actually cause. This decision sets the control baseline, the SSP scope, and the assessment timeline for everything that follows. The organizations that struggle later are almost never the ones that categorized High when they should have categorized Low, or vice versa — they're the ones that made the call quickly, didn't document why, and can't defend it when an assessor asks six months later.
Busy executives can stop here. The full guide below is for the team doing the categorization work.
Every authorization effort has a moment where the real timeline gets set — not at kickoff, not at the assessment, but at categorization. FIPS 199 asks a deceptively simple question: how bad would it be if this system's confidentiality, integrity, or availability were compromised? The answer determines your control baseline, shapes your SSP, and quietly sets the ceiling or floor for how much work is ahead of you.
FIPS 199 categorizes a system against three security objectives — the CIA triad:
Each objective gets its own impact rating: Low, Moderate, or High.
The system's overall categorization is the highest of the three ratings. A single High rating anywhere makes the whole system High, regardless of how the other two objectives score. Averaging, or picking "mostly Moderate," isn't how this works.
That fourth step is where most of the real damage happens later. A categorization without documented justification is a categorization nobody can defend when an assessor asks "why Moderate, not High?"
No login, no personal data. Reasonably lands at Low across all three objectives.
High confidentiality, high integrity, moderate availability — landing the whole system at High, driven by the highest of the three.
Same exercise, very different outcomes, because the information — not the system's general purpose — is what drives the rating.
Your FIPS 199 categorization feeds directly into control baseline selection, SSP scope and structure, and how your risk assessments and POA&M get sized. Get it wrong, and you're either over-building controls the system never needed, or discovering mid-assessment that you've under-built the ones it did.
The honest test: can you point to the specific information type behind each of your C, I, and A ratings — individually — and explain why? If the answer is "not really," that's worth fixing before anything downstream gets built on top of it.
A fillable PDF that walks you through categorization the way it's actually supposed to be done — information type by information type, each CIA objective assessed independently, with a guided high-water-mark rollup and real links to the official NIST publications.
Self-serve categorization, guided step by step, with the official NIST references built in.
Get the TemplateHave someone who's carried the accountability for this call before get it right the first time.
Book a Discovery Call