Purpose: Inform organizational risk management processes and tasks by determining the adverse impact with respect to the loss of confidentiality, integrity, and availability of systems and the information processed, stored, and transmitted by those systems
Outcomes:
Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems
NIST SP 800-60 Volume I and Volume II, Guide for Mapping Types of Information and Information Systems to Security Categories
Security and Privacy: general security & privacy, privacy, risk management, security measurement, security programs & operations
Laws and Regulations: E-Government Act, Federal Information Security Modernization Act