NIST SP 800-37 NISTSP37-2: RMF Categorize Step: Information and System Categorisation
Execute the Categorize step per NIST SP 800-37 Rev 2 Chapter 3 Step 2. Categorise the information processed, stored, and transmitted by the system and the system itself per the impact levels in FIPS 199 (Low, Moderate, High) for confidentiality + integrity + availability. Tasks include (C-1) document system characteristics, (C-2) identify information types per NIST SP 800-60 guidance, (C-3) determine provisional and adjusted impact levels per information type, (C-4) determine system security categorisation (high water mark across information types), (C-5) review and approve security categorisation. Categorisation determines control baseline selection and is the foundation for the Authorize decision.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 89 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33