Skip to main content
Category: Risk Management Framework

NIST SP 800-60

Also known as: SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories, NIST Special Publication 800-60
Simply put

NIST SP 800-60 is a guide published by NIST that helps federal organizations figure out how sensitive different kinds of information are and assign a security category to their information systems. It works by first identifying the types of information a system handles and then mapping those types to appropriate security levels. This helps agencies apply the right level of protection based on how important the information is.

Formal definition

NIST Special Publication 800-60 is a NIST guidance document that supports the security categorization process by providing a methodology for mapping types of information and information systems to security categories. It is generally structured in two volumes: Volume I sets out the basic guidelines for the mapping process, and Volume II provides a catalog of information types with provisional impact-level assignments. The publication facilitates the application of appropriate levels of information security across a range of impact levels, and it defines an 'information type' as a specific category of information (for example, privacy, medical, proprietary, financial, or investigative). Practitioners should note that SP 800-60 has moved through multiple revisions, Volume I Revision 1 was finalized in 2008, and a Revision 2 was in initial working draft status as of 2024, with the earlier final version noted as withdrawn in NIST's catalog, so readers should verify the current authoritative revision, volume structure, and impact-level assignments against the official NIST source before relying on specific content. This entry does not cover the full control selection or tailoring process, which is addressed by related NIST publications.

Why it matters

Security categorization is the foundational first step in the NIST Risk Management Framework, and getting it wrong distorts every decision that follows. If an agency underestimates the impact level of the information a system handles, it may select an inadequate control baseline and leave sensitive information exposed; if it overestimates, it may apply costly controls that are disproportionate to the actual risk. NIST SP 800-60 exists to bring discipline and consistency to this judgment by giving federal organizations a repeatable methodology for identifying information types and mapping them to security categories, so that protection is proportionate to how important the information is.

The guide matters because categorization is not a purely subjective exercise. By defining an 'information type' as a specific category of information, such as privacy, medical, proprietary, financial, or investigative, and by providing provisional impact-level assignments, SP 800-60 helps different practitioners and agencies reach more comparable results for similar systems. This consistency supports downstream activities such as control selection and authorization, where an authorizing official must be able to trust that the stated impact level reflects a defensible analysis.

Practitioners should treat SP 800-60 as guidance that facilitates the application of appropriate levels of information security across a range of impact levels, not as an automatic answer. The impact-level assignments in the catalog are provisional and generally intended to be adjusted in light of the specific mission and operational context. Readers should also be aware that the publication has moved through multiple revisions and volume states, including a final Volume I Revision 1 and a later working draft revision, so relying on specific content without confirming the current authoritative version against the official NIST source can lead to categorization decisions built on withdrawn or superseded guidance.

Who it's relevant to

Information System Security Managers and System Owners
Those responsible for characterizing a system rely on SP 800-60 to identify the information types their system handles and to assign a defensible security category. Because the catalog assignments are provisional, they should document any adjustments made for mission and operational context and confirm they are working from the current authoritative revision.
Authorizing Officials
Authorizing officials depend on a sound categorization to judge whether the selected controls are proportionate to the system's impact level. SP 800-60 provides the shared methodology behind that categorization, though officials should remember that categorization supports, but does not replace, the broader control selection and authorization decisions addressed by related NIST publications.
Federal Compliance Officers and Assessors
Compliance and assessment personnel use SP 800-60 as a reference for evaluating whether an organization's categorization is consistent and reasonable. They should verify that the organization applied the current authoritative volume and revision, since the publication has moved through multiple revisions and volume states, including a version noted as withdrawn in NIST's catalog.
Practitioners Supporting Federal and Related Systems
Contractors and staff who support federal government information systems use the guide to align their categorization approach with federal expectations. Note that scope and specific obligations can differ for other environments, and this entry does not cover the full control selection or tailoring process.

Inside SP 800-60

Information Type Categorization Guidance
NIST SP 800-60 provides guidance for mapping types of information and information systems to security categories, supporting the categorization step required under FIPS 199. It is maintained by NIST and is intended primarily for federal civilian agency systems operating under FISMA, though DoD and other communities may reference it during RMF categorization.
Two-Volume Structure
The publication is generally organized into a volume describing the categorization methodology and a companion volume providing catalogs of provisional impact-level assignments for identified information types. Practitioners should verify the current revision and volume structure against the official NIST text, as content and organization can change across revisions.
Confidentiality, Integrity, and Availability Impact Levels
For each information type, the guidance offers provisional impact-level recommendations (commonly expressed as low, moderate, or high) across the security objectives of confidentiality, integrity, and availability, consistent with the FIPS 199 framework.
Provisional and Adjustable Assignments
The impact-level assignments in SP 800-60 are provisional starting points, not final determinations. The guidance anticipates that agencies will review and adjust categorizations based on mission, operational context, and organizational risk considerations.
Input to the RMF Categorization Step
The results of applying SP 800-60 generally feed into the categorization step of the NIST Risk Management Framework, which in turn informs baseline control selection from NIST SP 800-53. SP 800-60 addresses categorization and does not itself specify the control baseline.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-60.

Does NIST SP 800-60 assign the security controls my system must implement?
No. NIST SP 800-60 supports the information categorization step by helping organizations map information types to security impact levels (low, moderate, or high) for confidentiality, integrity, and availability. It does not assign or specify security controls. Control selection is generally driven by the categorization result, which then points to a baseline in NIST SP 800-53 (with tailoring). Treating SP 800-60 as a control catalog conflates it with SP 800-53. Confirm the current revision and your agency's tailoring guidance against the authoritative NIST text.
Is the impact level produced under NIST SP 800-60 the final, binding categorization for my system?
Not necessarily. SP 800-60 provides provisional impact-level recommendations for information types that generally serve as a starting point. Organizations are typically expected to review and adjust these provisional values based on their specific mission, operational context, and risk considerations, and the authorizing official or designated authority ultimately approves the system categorization. The guidance is a recommendation aid rather than an automatic determination. Verify how your agency's process treats these provisional values against current policy.
How does NIST SP 800-60 fit into the categorization step of the Risk Management Framework?
SP 800-60 is generally used to support the categorization step by helping identify the information types processed, stored, or transmitted by a system and their provisional impact levels. The results inform the overall system security categorization, which in most RMF implementations feeds subsequent steps such as control selection. Note that SP 800-60 does not itself define the RMF steps; that structure is described in the applicable NIST RMF guidance. Confirm current step names and sequencing against the authoritative source.
Do I apply NIST SP 800-60 to each information type separately or to the system as a whole?
In most implementations, impact levels are assessed for the individual information types a system handles, and the system-level categorization is then generally derived by considering the impact levels across those types. SP 800-60 supports identifying and evaluating information types; the method for aggregating them into a system categorization is described in the applicable NIST categorization guidance. Verify the specific aggregation approach and any agency-specific interpretation against current official sources.
Does NIST SP 800-60 apply to Controlled Unclassified Information or to DoD systems under the RMF?
SP 800-60 is federal guidance used to support information categorization and can be relevant across federal environments that follow NIST-based processes. However, how it is applied may differ by context, civilian agency systems under FISMA, DoD systems under the RMF, and information involving CUI may each carry additional or agency-specific requirements and tailoring. National security systems and classified environments may be governed by different authorities. Confirm applicability and any supplemental requirements against the governing policy for your environment.
Should I use the version of NIST SP 800-60 my organization has on file, or check for a current revision?
Always verify the applicable revision. Categorization guidance, referenced information type catalogs, and related NIST publications can change across revisions, and agencies may specify which version applies. Using an outdated copy can lead to inconsistencies with current control-selection or RMF guidance. Confirm the current authoritative text and your agency's applicable-revision requirements before relying on any specific mapping or provisional impact value.

Common misconceptions

The impact levels assigned in NIST SP 800-60 are mandatory final categorizations that agencies must adopt as written.
The assignments are provisional recommendations intended as a starting point. Agencies are generally expected to review and, where justified, adjust the categorization based on their specific mission, operational environment, and risk posture. Practitioners should document the rationale for any adjustments.
NIST SP 800-60 selects or defines the security controls a system must implement.
SP 800-60 supports categorization of information and information systems; it does not establish the control baseline. Control selection is generally handled through FIPS 200 and NIST SP 800-53 once the FIPS 199 category is determined. Confusing categorization guidance with control catalogs is a common error.
NIST SP 800-60 applies uniformly to all systems, including classified and defense systems, in the same way it applies to federal civilian systems.
The guidance is oriented toward federal civilian systems under FISMA. Scope and applicability can differ for DoD systems under the RMF, national security systems, and classified systems governed under separate authorities. Readers should confirm applicability against the governing policy for their system category.

Best practices

Use NIST SP 800-60 impact-level assignments as a provisional baseline, then formally review and adjust each categorization based on your system's mission, operational context, and organizational risk tolerance.
Document the rationale for any deviation from the provisional impact levels so the categorization decision is defensible during assessment and authorization.
Verify you are working from the current revision of the publication, since information types, volume structure, and provisional assignments can change across revisions.
Treat categorization as an input to, not a substitute for, control selection, carry the FIPS 199 result forward into control baseline selection under the applicable framework rather than assuming SP 800-60 defines controls.
Confirm applicability before applying the guidance to DoD, national security, or classified systems, since those may be governed by separate authorities with different requirements.
Coordinate categorization decisions with the appropriate authorizing official and information owners so that confidentiality, integrity, and availability impacts reflect mission needs rather than a purely mechanical mapping.