FIPS 199
FIPS 199 is a federal standard, issued by NIST and approved in 2004, that provides a method for categorizing federal information and information systems according to the potential impact if their security were compromised. It helps agencies decide how serious the consequences would be if information or a system lost its confidentiality, integrity, or availability. This categorization is generally used as a starting point for selecting appropriate security protections.
FIPS 199, formally titled 'Standards for Security Categorization of Federal Information and Information Systems,' is a mandatory Federal Information Processing Standard developed and maintained by NIST and approved in February 2004. It establishes a standardized approach for categorizing federal information and information systems by assessing the potential impact, defined in impact levels, resulting from a loss of confidentiality, integrity, or availability. In most implementations, the resulting security categorization derived under FIPS 199 informs subsequent activities such as the selection of a security control baseline; readers should note that FIPS 199 addresses categorization itself and does not, within this evidence, prescribe the specific control sets applied afterward, and its application should be confirmed against the current authoritative NIST text and any agency-specific tailoring.
Why it matters
FIPS 199 sits at the front of the federal risk management process because it forces agencies to answer a foundational question before selecting any protections: how bad would it be if this information or system lost its confidentiality, integrity, or availability? By establishing a common vocabulary of impact levels, the standard gives agencies, authorizing officials, and assessors a consistent basis for judging the seriousness of a potential compromise. Without a defensible categorization, downstream decisions, such as which security control baseline to apply, lack a coherent starting point.
The categorization produced under FIPS 199 generally shapes the scope, cost, and rigor of the security effort that follows, so errors at this stage tend to propagate. Under-categorizing a system can leave it with weaker protections than its actual impact warrants, while over-categorizing can impose unnecessary burden. Because the standard addresses categorization itself and not the specific control sets applied afterward, practitioners should treat it as the first step in a larger process rather than a complete security solution.
A common expert correction is to remember that categorization is not the same as compliance or security: assigning an impact level does not by itself protect a system, and the resulting category must feed into control selection, implementation, assessment, and authorization to have practical effect. Readers should also confirm any categorization approach against the current authoritative NIST text and any agency-specific tailoring, since impact-level determinations can be shaped by mission context.
Who it's relevant to
Inside FIPS 199
Common questions
Answers to the questions practitioners most commonly ask about FIPS 199.