Skip to main content
Category: Risk Assessment & Analysis

Information Type

Simply put

An information type is a specific category of information, such as privacy, medical, proprietary, financial, investigative, contractor-sensitive, or security-management information, that helps organizations describe the kind of data a system handles. Grouping information into types supports decisions about how that information should be protected. The specific set of information types and their handling can vary by organization and by the applicable federal guidance.

Formal definition

Per the NIST CSRC glossary, an information type is a specific category of information (for example, privacy, medical, proprietary, financial, investigative, contractor-sensitive, or security-management information) defined by an organization or, in some cases, by a specific law, executive order, directive, policy, or regulation. Information types are foundational to security categorization activities, where each type is generally evaluated for potential impact and used to inform the categorization of an information system. The precise enumeration and treatment of information types depends on the applicable revision of the governing NIST guidance and on agency- or organization-specific tailoring, which readers should verify against current authoritative sources. This entry addresses the categorization concept and does not cover implementation-specific classification tooling or contractual data-handling obligations.

Why it matters

Information type is the starting point for security categorization, and errors at this stage propagate through every downstream protection decision. If an organization fails to accurately identify the information types a system handles, such as privacy, medical, financial, or contractor-sensitive information, it risks misjudging the potential impact of a compromise and, in turn, selecting an inappropriate control baseline. In defense and public sector environments, this can mean under-protecting sensitive data or expending resources on controls disproportionate to the actual risk. Because the enumeration of information types can be defined by an organization or, in some cases, by a specific law, executive order, directive, policy, or regulation, getting the identification right requires understanding both organizational context and applicable federal guidance.

Who it's relevant to

Information System Security Managers and System Owners
These practitioners identify the information types a system handles as the first step in security categorization. Accurate typing directly influences impact determinations and, ultimately, the selection of an appropriate control baseline, so errors here affect the entire protection posture of the system.
Compliance Officers and Auditors
Reviewers assess whether an organization has correctly identified applicable information types and whether categorization decisions align with governing guidance. They should confirm that information typing reflects the current applicable NIST revision and any agency-specific tailoring rather than a generic or outdated list.
Authorizing Officials
Authorizing officials rely on categorization outcomes that begin with information type identification when weighing risk acceptance decisions. Understanding which information types drive a system's categorization helps them evaluate whether the assessed impact levels are supportable.
Government Contractors Handling Sensitive Information
Contractors whose systems process categories such as contractor-sensitive, proprietary, or privacy information should understand how those information types factor into categorization. Because handling expectations can be shaped by law, policy, or regulation as well as by contractual obligations, contractors should verify applicable requirements against current authoritative and contractual sources.

Inside Information Type

Information Type Definition
A specific category or class of information (for example, financial, medical, privacy, investigative, or mission-specific data) defined by an organization or in law, executive order, directive, policy, or regulation. NIST SP 800-60 provides guidance for identifying and categorizing information types, though agencies may tailor and supplement these categories.
Security Objective Impact Ratings
Each information type is generally assigned potential impact values (typically expressed as low, moderate, or high) for the three security objectives of confidentiality, integrity, and availability, as described in FIPS 199. These provisional ratings feed into the overall system security categorization.
Basis in Authoritative Sources
Information types can derive from statutory, regulatory, or policy requirements, or from an organization's mission and business functions. NIST SP 800-60 distinguishes management and support information types from mission-based information types, but agency-specific missions may require additional categories not enumerated in the guidance.
Role in System Categorization
The set of information types processed, stored, or transmitted by a system, together with their impact ratings, is used to determine the system's overall security categorization under FIPS 199, which in turn influences control baseline selection under NIST SP 800-53 as applied through the Risk Management Framework.

Common questions

Answers to the questions practitioners most commonly ask about Information Type.

Does assigning an information type to a system by itself establish the system's security categorization?
Not on its own. An information type is one input to security categorization, but categorization under the FIPS 199 and NIST SP 800-60 approach generally involves determining the potential impact (low, moderate, or high) for confidentiality, integrity, and availability across all information types the system processes, stores, or transmits. The system's overall categorization is typically driven by the highest impact value among its information types (the high water mark), subject to agency tailoring. Confirm the current process against the applicable NIST guidance, since revisions and agency-specific interpretations can affect how information types map to categorization.
Is 'information type' the same thing as a data classification such as CUI or classified?
No, though the terms are related and often confused. As used in NIST SP 800-60, an information type is a category of information defined by its subject matter and mission or business function, used to help determine security impact levels. Classification markings such as CUI, or classified levels handled under the NISPOM, are distinct designations governing handling, access, and protection requirements. A given information type may involve CUI or other designations, but the information type construct and the classification framework serve different purposes and are maintained under different authorities. Verify how each applies in your environment against the current authoritative sources.
Where do I find a starting list of information types to identify what my system handles?
NIST SP 800-60 provides catalogs of information types organized around mission-based and management/support functions, drawing on federal business reference models, and offers provisional impact assignments intended as a starting point. These are generally recommendations rather than mandates, and organizations are expected to review and adjust the provisional impact levels based on their specific context. Check the applicable revision of SP 800-60 and any agency supplements, and confirm whether your agency maintains its own approved information type list.
How should I handle a system that processes multiple information types with different impact levels?
In most implementations following the NIST approach, you identify each information type the system processes, stores, or transmits, assign potential impact levels for confidentiality, integrity, and availability to each, and then determine the system categorization using the high water mark across those types. Aggregation effects, where combining information raises the effective impact, may warrant a higher assignment than any single type suggests. Document the rationale for each assignment, and validate the resulting categorization against your organization's process and current NIST guidance.
Can I adjust the provisional impact levels that guidance assigns to an information type?
Generally yes. The provisional impact assignments in NIST SP 800-60 are intended as a baseline to be reviewed and adjusted based on mission needs, legal and regulatory factors, and organizational context. Any adjustment should be documented with supporting rationale and reviewed as part of your categorization process, typically with involvement from the information owner, system owner, and the authorizing official or their designee. Confirm your agency's specific procedures and approval requirements, as these can vary.
Who is responsible for identifying and validating information types for a system?
Responsibility is typically shared, and roles vary by organization. Information owners or stewards generally have insight into the nature and sensitivity of the information, while system owners and security staff apply that input to categorization. In an RMF context, the categorization decision is generally reviewed and approved as part of the authorization process, with the authorizing official or a designated representative accepting the resulting categorization. Confirm the specific roles, approvals, and documentation expected under your organization's process and the applicable guidance.

Common misconceptions

An information type's impact ratings from NIST SP 800-60 are mandatory values that must be used as-is.
NIST SP 800-60 provides provisional or recommended impact assignments as guidance, not fixed mandates. Agencies are generally expected to review and adjust these provisional values based on their specific mission, operating context, and applicable law or policy, and the resulting categorization should reflect that tailoring.
Categorizing information types is the same as categorizing the system.
Identifying and rating individual information types is an input to, not a substitute for, system security categorization. Under FIPS 199, the system-level categorization typically applies the high-water mark across the information types for each security objective, and additional factors may influence the final result. Confirm the applicable methodology against current guidance.
The CUI designation and an information type are interchangeable labels.
Controlled Unclassified Information is a marking and handling designation governed by the CUI program and its registry, whereas an information type is a categorization construct used for impact analysis and control selection. A given information type may or may not contain CUI, and CUI handling obligations are determined separately from FIPS 199 impact ratings.

Best practices

Enumerate all information types processed, stored, or transmitted by the system before assigning impact values, rather than categorizing at the system level first, so that no relevant category is overlooked.
Use NIST SP 800-60 provisional impact assignments as a starting point, then review and adjust each rating to reflect your organization's mission, operating environment, and any statutory, regulatory, or policy drivers that apply.
Document the rationale for any adjustment to a provisional impact value, including the authoritative source or mission consideration that supports the change, to support the authorization package and later reviews.
Determine whether any information type contains CUI or other specially regulated data separately from the FIPS 199 impact analysis, and confirm handling obligations against the current CUI program and applicable agency guidance.
Revisit information type identification and impact ratings when the system's mission, data holdings, or interconnections change, since categorization is not a one-time activity and should be maintained through continuous monitoring.
Verify the applicable revisions of FIPS 199, NIST SP 800-60, and any agency-specific tailoring guidance before finalizing categorization, as impact criteria and enumerated information types may change across revisions.