Execute the Categorize step per NIST SP 800-37 Rev 2 Chapter 3 Step 2. Categorise the information processed, stored, and transmitted by the system and the system itself per the impact levels in FIPS 199 (Low, Moderate, High) for confidentiality + integrity + availability. Tasks include (C-1) document system characteristics, (C-2) identify information types per NIST SP 800-60 guidance, (C-3) determine provisional and adjusted impact levels per information type, (C-4) determine system security categorisation (high water mark across information types), (C-5) review and approve security categorisation. Categorisation determines control baseline selection and is the foundation for the Authorize decision.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.