Certified Authorization Professional – CAP – Question164

Which of the following formulas was developed by FIPS 199 for categorization of an information system?

A.
SC information system = {(confidentiality, impact), (integrity, controls), (availability, risk)}
B. SC information system = {(confidentiality, impact), (integrity, impact), (availability, impact)}
C. SC information system = {(confidentiality, controls), (integrity, controls), (availability, controls )}
D. SC information system = {(confidentiality, risk), (integrity, impact), (availability, controls)}

Correct Answer: B