FIPS 200
FIPS 200 is a U.S. government standard, issued by NIST and approved in March 2006, that sets the minimum security requirements federal agencies must meet to protect their information and information systems. It identifies broad security-related areas that agencies must address and points to a risk-based approach for choosing the specific safeguards. Because it is a Federal Information Processing Standard, it establishes a mandatory baseline rather than optional guidance for the systems within its scope.
FIPS 200, Minimum Security Requirements for Federal Information and Information Systems (March 2006), is a Federal Information Processing Standard issued by NIST that specifies minimum security requirements for federal information and information systems across seventeen security-related areas. It establishes a risk-based process for selecting the security controls necessary to satisfy those minimum requirements, and in most implementations agencies apply it together with the companion control catalog to determine appropriate safeguards. As of the applicable revision, practitioners should confirm scope against current authoritative text: FIPS 200 governs federal information and information systems (generally federal civilian systems under FISMA) and does not by itself address the tailoring, contractual, or agency-specific implementation details that a reader must verify against the current official publication. National security systems and CUI-specific or DoD-specific obligations may be governed by separate authorities.
Why it matters
FIPS 200 matters because it establishes a mandatory security baseline, not optional advice. As a Federal Information Processing Standard issued by NIST and approved in March 2006, it obligates federal agencies within its scope to address minimum security requirements across seventeen security-related areas rather than leaving those decisions entirely to individual discretion. This gives compliance officers, ISSMs, and authorizing officials a common floor against which systems can be measured, which is foundational to the risk management activities that follow.
Because FIPS 200 points to a risk-based process for selecting security controls, it is typically applied alongside the companion control catalog to determine which specific safeguards satisfy the minimum requirements. Practitioners should understand that meeting FIPS 200 is about establishing and documenting an appropriate control baseline, not a one-time checkbox: compliance with a minimum standard is not the same as being secure, and the standard itself does not resolve the tailoring and implementation choices an agency must make and justify.
Scope discipline is essential when relying on FIPS 200. It generally governs federal information and information systems, most commonly federal civilian systems under FISMA. National security systems, CUI-specific obligations, and DoD-specific requirements may be governed by separate authorities, so treating FIPS 200 as automatically satisfying those distinct regimes would be a mistake. Readers should confirm scope, applicability, and current requirements against the official publication and any governing agency guidance.
Who it's relevant to
Inside FIPS 200
Common questions
Answers to the questions practitioners most commonly ask about FIPS 200.