NIST SP 800-60
NIST SP 800-60 is a guide published by NIST that helps federal organizations figure out how sensitive different kinds of information are and assign a security category to their information systems. It works by first identifying the types of information a system handles and then mapping those types to appropriate security levels. This helps agencies apply the right level of protection based on how important the information is.
NIST Special Publication 800-60 is a NIST guidance document that supports the security categorization process by providing a methodology for mapping types of information and information systems to security categories. It is generally structured in two volumes: Volume I sets out the basic guidelines for the mapping process, and Volume II provides a catalog of information types with provisional impact-level assignments. The publication facilitates the application of appropriate levels of information security across a range of impact levels, and it defines an 'information type' as a specific category of information (for example, privacy, medical, proprietary, financial, or investigative). Practitioners should note that SP 800-60 has moved through multiple revisions, Volume I Revision 1 was finalized in 2008, and a Revision 2 was in initial working draft status as of 2024, with the earlier final version noted as withdrawn in NIST's catalog, so readers should verify the current authoritative revision, volume structure, and impact-level assignments against the official NIST source before relying on specific content. This entry does not cover the full control selection or tailoring process, which is addressed by related NIST publications.
Why it matters
Security categorization is the foundational first step in the NIST Risk Management Framework, and getting it wrong distorts every decision that follows. If an agency underestimates the impact level of the information a system handles, it may select an inadequate control baseline and leave sensitive information exposed; if it overestimates, it may apply costly controls that are disproportionate to the actual risk. NIST SP 800-60 exists to bring discipline and consistency to this judgment by giving federal organizations a repeatable methodology for identifying information types and mapping them to security categories, so that protection is proportionate to how important the information is.
The guide matters because categorization is not a purely subjective exercise. By defining an 'information type' as a specific category of information, such as privacy, medical, proprietary, financial, or investigative, and by providing provisional impact-level assignments, SP 800-60 helps different practitioners and agencies reach more comparable results for similar systems. This consistency supports downstream activities such as control selection and authorization, where an authorizing official must be able to trust that the stated impact level reflects a defensible analysis.
Practitioners should treat SP 800-60 as guidance that facilitates the application of appropriate levels of information security across a range of impact levels, not as an automatic answer. The impact-level assignments in the catalog are provisional and generally intended to be adjusted in light of the specific mission and operational context. Readers should also be aware that the publication has moved through multiple revisions and volume states, including a final Volume I Revision 1 and a later working draft revision, so relying on specific content without confirming the current authoritative version against the official NIST source can lead to categorization decisions built on withdrawn or superseded guidance.
Who it's relevant to
Inside SP 800-60
Common questions
Answers to the questions practitioners most commonly ask about SP 800-60.