drm-public
[Top] [All Lists]

[drm-public] DRM_Feedback_drm:FIPS199PotentialImpactLevels_2005_06_11

To: <drm-public@xxxxxxxxxxxxxx>
From: "Johnson, Roger" <rlj6@xxxxxxx>
Date: Fri, 29 Jul 2005 17:50:01 -0400
Message-id: <4FF34E33B7A33B4283BD068D31EF42C30EE13FA7@xxxxxxxxxxxxxxxxxxx>

The FIPS 199 process involves identifying the “information type” of a data attribute.  Predefined information types are described in NIST Special Publication 800-60, though it is possible to create a non-standard information type.  After identifying an 800-60 information type for a data attribute, you then decide to accept the provisional Confidentiality, Integrity, and Availability categorizations suggested for that information type, or you can increase or decrease the categorization if applicable.

 

The three current child metadata elements capture the final categorization resulting from this process.  Is there value in including the NIST SP 800-60 information type as a child metadata element as well?  Perhaps this would provide the opportunity to identify when there have been increases or decreases from the provisional recommendation to verify the accuracy of these decisions.  Might there be other needs to identify the information type of the data?

 

Another option (perhaps better) is to add two child metadata elements – information type and information type source.  The information type source would most frequently be NIST SP 800-60, but agency specific / custom information types can also be defined, which perhaps is likely to have already occurred in organizations which have a mature enterprise data dictionary.

 _________________________________________________________________
Message Archives: http://colab.cim3.net/forum/drm-public/
To Post: mailto:drm-public@xxxxxxxxxxxxxx
Subscribe/Unsubscribe/Config: http://colab.cim3.net/mailman/listinfo/drm-public/
Shared Files: http://colab.cim3.net/file/work/drm/
Community Wiki: http://colab.cim3.net/cgi-bin/wiki.pl?DataReferenceModel    (01)
<Prev in Thread] Current Thread [Next in Thread>
  • [drm-public] DRM_Feedback_drm:FIPS199PotentialImpactLevels_2005_06_11, Johnson, Roger <=