Skip to main content
Category: NIST Standards & Publications

FIPS 199

Also known as: FIPS 199, Federal Information Processing Standard Publication 199, FIPS PUB 199, Standards for Security Categorization of Federal Information and Information Systems
Simply put

FIPS 199 is a federal standard, issued by NIST and approved in 2004, that provides a method for categorizing federal information and information systems according to the potential impact if their security were compromised. It helps agencies decide how serious the consequences would be if information or a system lost its confidentiality, integrity, or availability. This categorization is generally used as a starting point for selecting appropriate security protections.

Formal definition

FIPS 199, formally titled 'Standards for Security Categorization of Federal Information and Information Systems,' is a mandatory Federal Information Processing Standard developed and maintained by NIST and approved in February 2004. It establishes a standardized approach for categorizing federal information and information systems by assessing the potential impact, defined in impact levels, resulting from a loss of confidentiality, integrity, or availability. In most implementations, the resulting security categorization derived under FIPS 199 informs subsequent activities such as the selection of a security control baseline; readers should note that FIPS 199 addresses categorization itself and does not, within this evidence, prescribe the specific control sets applied afterward, and its application should be confirmed against the current authoritative NIST text and any agency-specific tailoring.

Why it matters

FIPS 199 sits at the front of the federal risk management process because it forces agencies to answer a foundational question before selecting any protections: how bad would it be if this information or system lost its confidentiality, integrity, or availability? By establishing a common vocabulary of impact levels, the standard gives agencies, authorizing officials, and assessors a consistent basis for judging the seriousness of a potential compromise. Without a defensible categorization, downstream decisions, such as which security control baseline to apply, lack a coherent starting point.

The categorization produced under FIPS 199 generally shapes the scope, cost, and rigor of the security effort that follows, so errors at this stage tend to propagate. Under-categorizing a system can leave it with weaker protections than its actual impact warrants, while over-categorizing can impose unnecessary burden. Because the standard addresses categorization itself and not the specific control sets applied afterward, practitioners should treat it as the first step in a larger process rather than a complete security solution.

A common expert correction is to remember that categorization is not the same as compliance or security: assigning an impact level does not by itself protect a system, and the resulting category must feed into control selection, implementation, assessment, and authorization to have practical effect. Readers should also confirm any categorization approach against the current authoritative NIST text and any agency-specific tailoring, since impact-level determinations can be shaped by mission context.

Who it's relevant to

Information System Security Managers and System Owners
These practitioners typically perform or oversee the initial FIPS 199 categorization for their systems, determining impact levels for confidentiality, integrity, and availability. Because this categorization generally drives downstream control selection, getting it defensible and well-documented is central to their responsibilities.
Authorizing Officials
Authorizing officials rely on the FIPS 199 categorization as an early basis for understanding the potential impact of a compromise and the corresponding rigor of protections a system should carry. They should recognize that categorization is one input to the broader risk decision and does not by itself constitute security or authorization.
Assessors and Auditors
Assessors and auditors evaluate whether an agency's security categorization is consistent, justified, and applied correctly under the standard. They should confirm that categorization decisions align with the current authoritative NIST text and any applicable agency-specific tailoring.
Federal Civilian Agency Compliance Staff
FIPS 199 was created so federal agencies could categorize the information and information systems they manage. Compliance staff use it as a mandatory federal standard that anchors the front end of the risk management process, while confirming that follow-on control selection and other requirements are handled through the appropriate governing guidance.

Inside FIPS 199

Security Objectives (Confidentiality, Integrity, Availability)
FIPS 199 frames categorization around three security objectives. Each objective is assessed independently for a given information type and information system.
Potential Impact Levels (Low, Moderate, High)
For each security objective, FIPS 199 defines potential impact as low, moderate, or high based on the expected adverse effect on organizational operations, assets, or individuals should a loss of confidentiality, integrity, or availability occur.
Information Type Categorization
FIPS 199 is applied to individual information types, with impact levels assigned to each. Supplementary guidance for identifying and categorizing information types is generally found in NIST SP 800-60, which readers should consult and verify against its current revision.
High-Water Mark Principle
The overall security category of an information system is generally determined by the highest impact level assigned across all applicable information types and security objectives.
Security Categorization (SC) Notation
FIPS 199 expresses results using a structured notation that pairs each of the three security objectives with its assigned potential impact value for the information type or system.
Scope and Authority
FIPS 199 is a Federal Information Processing Standard issued by NIST under FISMA. It applies to federal information and information systems other than those designated as national security systems, though agencies may apply it more broadly. Readers should confirm applicability against current authoritative sources.

Common questions

Answers to the questions practitioners most commonly ask about FIPS 199.

Does a FIPS 199 categorization by itself determine which security controls I must implement?
No. FIPS 199 establishes the security category of an information system based on the potential impact (low, moderate, or high) to confidentiality, integrity, and availability, but it does not itself specify controls. The categorization is an input that generally drives the selection of a control baseline through companion guidance, most notably NIST SP 800-53 (via the baselines described in NIST SP 800-53B) and the mapping in FIPS 200. Treating FIPS 199 as the source of a control set conflates categorization with control selection. Confirm the current relationship between categorization and baseline selection against the applicable revisions of the governing publications.
Is the FIPS 199 impact level the same thing as a FedRAMP or DoD impact level?
Not exactly, and they should not be treated as interchangeable. FIPS 199 defines low, moderate, and high impact for federal information and information systems generally, primarily in the FISMA context for federal civilian systems. FedRAMP applies these impact levels to cloud service offerings under its own program processes managed by the FedRAMP PMO, and DoD uses its own Impact Level scheme (commonly expressed as IL2, IL4, IL5, and higher) for cloud services handling categories such as CUI and national security information. A FedRAMP authorization does not automatically satisfy DoD requirements. Verify the specific impact-level definitions and applicability against the current authoritative sources for each program.
How do I apply FIPS 199 to a system that handles multiple types of information?
FIPS 199 generally uses a high-water mark approach: you determine the potential impact level (low, moderate, or high) for confidentiality, integrity, and availability for each information type, and the overall system security category is typically driven by the highest impact value assigned across those types and objectives. Information-type impact determinations are often informed by supporting NIST guidance on mapping information types to impact levels. Because agency tailoring and mission-specific considerations can affect these determinations, confirm your methodology against the applicable revision of the governing guidance and any agency-specific direction.
Where does FIPS 199 fit within the Risk Management Framework (RMF)?
FIPS 199 categorization generally corresponds to the categorize step of the RMF, which is typically the first step in preparing a system for authorization. The resulting security category then generally informs control selection in subsequent steps. Note that categorization is an early activity that supports, but is distinct from, later assessment and authorization steps; completing a FIPS 199 categorization does not by itself confer an Authority to Operate. Verify the current RMF step structure and terminology against the applicable NIST guidance, as this can evolve across revisions.
Who is responsible for making the FIPS 199 categorization decision?
In most implementations, the categorization is developed by the system owner or information owner with support from the information system security officer or equivalent, and it is generally reviewed or approved as part of the authorization process, often with involvement of the authorizing official. Roles and titles can vary by agency and by whether the system is a federal civilian system under FISMA or a DoD system under the RMF. Confirm the specific roles, approval authorities, and documentation expectations against your organization's policies and current authoritative guidance.
Does FIPS 199 apply to national security systems?
FIPS 199 is oriented toward federal information and information systems in the FISMA context and generally does not govern national security systems in the same way; such systems are typically subject to separate authorities and processes. Classified systems and national security systems may follow different categorization and control regimes rather than the FIPS 199 model. Because scope boundaries between federal civilian, defense, and national security systems are significant, confirm applicability for your specific system type against the current governing authorities before relying on FIPS 199.

Common misconceptions

FIPS 199 categorization by itself tells you which security controls to implement.
FIPS 199 establishes the security category; it does not select controls. The resulting impact level is generally used with FIPS 200 and NIST SP 800-53 baselines to inform control selection under the RMF. Categorization is an input to, not a substitute for, control selection and tailoring.
FIPS 199 applies to all federal systems, including national security systems.
FIPS 199 is generally directed at federal information and systems other than national security systems. National security systems are typically handled under separate authorities, and defense systems follow DoD RMF processes. Readers should verify the applicable scope for their environment.
The overall impact level is an average of the three security objectives.
FIPS 199 generally uses a high-water mark approach, where the overall categorization reflects the highest impact value assigned among the objectives and information types, not an average or blend of them.

Best practices

Assess confidentiality, integrity, and availability independently for each information type before determining an overall system category, rather than assigning a single blanket level.
Use NIST SP 800-60 as supplementary guidance for identifying and categorizing information types, and verify you are working from its current revision.
Apply the high-water mark principle deliberately, documenting the rationale for the highest impact value that drives the overall system category.
Treat FIPS 199 categorization as the starting input to the RMF and control selection under FIPS 200 and NIST SP 800-53, not as the endpoint of the process.
Confirm whether your system is a national security system or otherwise out of FIPS 199 scope, and follow the applicable DoD or agency-specific authority where it differs.
Revisit and update the security categorization when information types, mission use, or data sensitivity change, since categorization decisions can drift over a system's lifecycle.