MARCO TEÓRICO
2.1. Marco Teórico
2.1.2. La competencia lectora
The sensitivity of Virtual Server Architecture critical assets has been rated based on the scale shown in the table below which is based upon the guidance provided in the FIPS 199. FIPS 199 only addresses impacts to non-national security systems. (For asset categorization guidance related to national security systems, Executive Order 1295827 and CNSS Instruction 125328 should be consulted.)
26 [US FIPS 199 Feb 04] Standards for Security Categorization of Federal Information and Information Systems, FIPS PUB 199, Feb 2004 27
[US EO 12958 Apr 95] Executive Order 12958, Classified National Security Information, White House, 17 Apr 1995
28
[US CNSS 1253 Oct 09] Security Categorization and Control Selection for National Security Systems, Committee on National Security Systems, CNSS Instruction 1253, Version 1, October 2009
Document TMIC-002 Version: 1.0 Dated 29 November 2011 Page 29
Sensitivities US Government - Sensitivity Rating Scale
High Moderate Low
Confidentiality (Impacts to non-national
security systems)
Impact level: High
Potential Impact: The unauthorized disclosure of information could be expected to have a severe or catastrophic adverse effect on organizational operations,
organizational assets, or individuals...
Examples include:
• cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;
• major damage to organizational assets;
• major financial loss; or
• severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.
Impact level: Moderate
Potential Impact:The unauthorized disclosure of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals..
Examples include:
• significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;
• significant damage to organizational assets;
• significant financial loss; or
• Significant harm to individuals that does not involve loss of life or serious life threatening injuries.
Impact level: Low
Potential Impact: The unauthorized disclosure of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals
Examples include:
• degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;
• minor damage to organizational assets;
• minor financial loss; or
• Minor harm to individuals.
Integrity Impact level: High
Potential Impact: The unauthorized modification or destruction of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
Examples include:
• cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;
• major damage to organizational assets;
• major financial loss; or
• severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.
Impact level: Moderate
Potential Impact: The unauthorized modification or destruction of information could be expected to have a serious adverse effect on organizational operations,
organizational assets, or individuals..
Examples include:
• significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;
• significant damage to organizational assets;
• significant financial loss; or
• Significant harm to individuals that does not involve loss of life or serious life threatening injuries.
Impact level: Low
Potential Impact: The unauthorized modification or destruction of information could be expected to have a limited
adverse effect on organizational operations, organizational assets, or individuals..
Examples include:
• degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;
• minor damage to organizational assets;
• minor financial loss; or
Document TMIC-002 Version: 1.0 Dated 29 November 2011 Page 30
Sensitivities US Government - Sensitivity Rating Scale
High Moderate Low
Availability Impact level: High
Potential Impact: The disruption of access to or use of information or an information system could be expected to have a severe or catastrophic
adverse effect on organizational operations, organizational assets, or individuals.
Examples include:
• Severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;
• Major damage to organizational assets;
• Major financial loss; or
• Ssevere or catastrophic harm to individuals involving loss of life or serious life threatening injuries.
Impact level: Moderate
Potential Impact: The disruption of access to or use of information or an information system could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
Examples include:
• Significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;
• Significant damage to organizational assets;
• Significant financial loss; or
• Significant harm to individuals that does not involve loss of life or serious life threatening injuries.
Impact level: Low
Potential Impact: The disruption of access to or use of information or an information system could be expected to have a limited
adverse effect on organizational operations, organizational assets, or individuals.
Examples include:
• Degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;
• Minor damage to organizational assets;
• Minor financial loss; or
• Minor harm to individuals
Table 1 – FIPS 199 Asset Categorization Criteria 4.1.3 CRITICAL ASSETS
The critical assets in the typical government virtualized server environment are documented in the Trend Micro, Government Enterprise, Large Scale Virtual Server Environment, Risk Assessment; 17 Feb, 2011. This report is available from Trend Micro on request.