RMF step 1 - Categorize the authorization package
In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.
Vorbereitungen
Role required to use Categorize:
- sn_irm_cont_auth.system_owner
- sn_irm_cont_auth.info_system_sec_manager
- sn_irm_cont_auth.info_system_sec_officer
Role required to write to an authorization package:
- sn_irm_cont_auth.admin
- sn_irm_cont_auth.system_owner
- sn_irm_cont_auth.info_system_sec_manager
- sn_irm_cont_auth.authorization_official
- sn_irm_cont_auth.info_system_sec_officer
Role required to select information types:
- sn_irm_cont_auth.admin
- sn_irm_cont_auth.system_owner
Role required to write to overridden fields on the Package form: sn_irm_cont_auth.system_owner