• No se han encontrado resultados

MARCO TEÓRICO

2.1. Marco Teórico

2.1.2. La competencia lectora

The sensitivity of Virtual Server Architecture critical assets has been rated based on the scale shown in the table below which is based upon the guidance provided in the FIPS 199. FIPS 199 only addresses impacts to non-national security systems. (For asset categorization guidance related to national security systems, Executive Order 1295827 and CNSS Instruction 125328 should be consulted.)

26 [US FIPS 199 Feb 04] Standards for Security Categorization of Federal Information and Information Systems, FIPS PUB 199, Feb 2004 27

[US EO 12958 Apr 95] Executive Order 12958, Classified National Security Information, White House, 17 Apr 1995

28

[US CNSS 1253 Oct 09] Security Categorization and Control Selection for National Security Systems, Committee on National Security Systems, CNSS Instruction 1253, Version 1, October 2009

Document TMIC-002 Version: 1.0 Dated 29 November 2011 Page 29

Sensitivities US Government - Sensitivity Rating Scale

High Moderate Low

Confidentiality (Impacts to non-national

security systems)

Impact level: High

Potential Impact: The unauthorized disclosure of information could be expected to have a severe or catastrophic adverse effect on organizational operations,

organizational assets, or individuals...

Examples include:

• cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;

• major damage to organizational assets;

• major financial loss; or

• severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.

Impact level: Moderate

Potential Impact:The unauthorized disclosure of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals..

Examples include:

• significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;

• significant damage to organizational assets;

• significant financial loss; or

• Significant harm to individuals that does not involve loss of life or serious life threatening injuries.

Impact level: Low

Potential Impact: The unauthorized disclosure of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals

Examples include:

• degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;

• minor damage to organizational assets;

• minor financial loss; or

• Minor harm to individuals.

Integrity Impact level: High

Potential Impact: The unauthorized modification or destruction of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

Examples include:

• cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;

• major damage to organizational assets;

• major financial loss; or

• severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.

Impact level: Moderate

Potential Impact: The unauthorized modification or destruction of information could be expected to have a serious adverse effect on organizational operations,

organizational assets, or individuals..

Examples include:

• significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;

• significant damage to organizational assets;

• significant financial loss; or

• Significant harm to individuals that does not involve loss of life or serious life threatening injuries.

Impact level: Low

Potential Impact: The unauthorized modification or destruction of information could be expected to have a limited

adverse effect on organizational operations, organizational assets, or individuals..

Examples include:

• degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;

• minor damage to organizational assets;

• minor financial loss; or

Document TMIC-002 Version: 1.0 Dated 29 November 2011 Page 30

Sensitivities US Government - Sensitivity Rating Scale

High Moderate Low

Availability Impact level: High

Potential Impact: The disruption of access to or use of information or an information system could be expected to have a severe or catastrophic

adverse effect on organizational operations, organizational assets, or individuals.

Examples include:

• Severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;

• Major damage to organizational assets;

• Major financial loss; or

• Ssevere or catastrophic harm to individuals involving loss of life or serious life threatening injuries.

Impact level: Moderate

Potential Impact: The disruption of access to or use of information or an information system could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.

Examples include:

• Significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;

• Significant damage to organizational assets;

• Significant financial loss; or

• Significant harm to individuals that does not involve loss of life or serious life threatening injuries.

Impact level: Low

Potential Impact: The disruption of access to or use of information or an information system could be expected to have a limited

adverse effect on organizational operations, organizational assets, or individuals.

Examples include:

• Degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;

• Minor damage to organizational assets;

• Minor financial loss; or

• Minor harm to individuals

Table 1 – FIPS 199 Asset Categorization Criteria 4.1.3 CRITICAL ASSETS

The critical assets in the typical government virtualized server environment are documented in the Trend Micro, Government Enterprise, Large Scale Virtual Server Environment, Risk Assessment; 17 Feb, 2011. This report is available from Trend Micro on request.

Documento similar