NIST releases draft security standard

Draft FIPS 199: Standards for Security Categorization of Federal Information and Information Systems

The National Institute of Standards and Technology's Computer Security Division today released the draft of a new Federal Information Processing Standard, FIPS 199, which dictates how agencies should categorize their systems based on the security risk faced by each.

The standard is the first step in several requirements generated by NIST under the Federal Information Security Management Act (FISMA) of 2002, all aimed at setting minimum security requirements for all government systems not related to national security.

The draft outlines three categories of risk, which are based on the potential impact of a breach in three areas: the confidentiality, integrity and availability of the information in the system.

NIST chose to focus on impact because every federal system faces some level of threat, and that threat changes every day, said Ed Roback, chief of the NIST Computer Security Division. Therefore, the most prudent path to follow is to base categorization on the potential harm to the agency and to the people whose information is stored in the system, he said.

Comments on the draft are due within 90 days, and can be submitted to [email protected]

The next steps for NIST will be to issue guidance on how different types of information — such as medical, judicial and geospatial — align with the three categories, and to then set guidance for the minimum security steps to be taken based on the categories, Roback said.


  • Defense
    Essye Miller, Director at Defense Information Management, speaks during the Breaking the Gender Barrier panel at the Air Space, Cyber Conference in National Harbor, Md., Sept. 19, 2017. (U.S. Air Force photo/Staff Sgt. Chad Trujillo)

    Essye Miller: The exit interview

    Essye Miller, DOD's outgoing principal deputy CIO, talks about COVID, the state of the tech workforce and the hard conversations DOD has to have to prepare personnel for the future.

  • innovation (Sergey Nivens/

    VA embraces procurement challenges at scale

    Steve Kelman applauds the Department of Veterans Affairs' ambitious attempt to move beyond one-off prize-based contests to combat veteran suicides more effectively.

Stay Connected


Sign up for our newsletter.

I agree to this site's Privacy Policy.