MLchartDataset catalogue

Moderate-impact system

Term · Cybersecurity · MLC-T-CYB-002731

1. An information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of moderate, and no security objective is assigned a FIPS 199 potential impact value of high.

2. An information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high. Note: For National Security Systems, CNSSI No. 1253 assigns one impact value (low, moderate, or high) for each of the three security objectives (confidentiality, integrity, and availability), rather than using the FIPS 200 high water mark across security objectives.

3. A system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS Publication 199 potential impact value of moderate and no security objective is assigned a potential impact value of high.

4. An information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high.

Table 1. Record
IdentifierMLC-T-CYB-002731
FieldCybersecurity
ReferencesFIPS 200; CNSSI 4009-2022 from FIPS 200; NIST SP 800-37 Rev. 2 from FIPS 200; NIST SP 800-53 Rev. 5 from FIPS 200; NIST SP 800-53A Rev. 5 from FIPS 200; NIST SP 800-53B from FIPS 200; NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200; NIST SP 800-60 Vol. 2 Rev. 1 from FIPS 200; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-002731",
  "term": "Moderate-impact system",
  "field": "Cybersecurity",
  "definition": "1. An information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of moderate, and no security objective is assigned a FIPS 199 potential impact value of high.\n\n2. An information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high. Note: For National Security Systems, CNSSI No. 1253 assigns one impact value (low, moderate, or high) for each of the three security objectives (confidentiality, integrity, and availability), rather than using the FIPS 200 high water mark across security objectives.\n\n3. A system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS Publication 199 potential impact value of moderate and no security objective is assigned a potential impact value of high.\n\n4. An information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of moderate and no security objective is assigned a FIPS 199 potential impact value of high.",
  "references": [
    "FIPS 200",
    "CNSSI 4009-2022 from FIPS 200",
    "NIST SP 800-37 Rev. 2 from FIPS 200; NIST SP 800-53 Rev. 5 from FIPS 200; NIST SP 800-53A Rev. 5 from FIPS 200; NIST SP 800-53B from FIPS 200",
    "NIST SP 800-60 Vol. 1 Rev. 1 from FIPS 200; NIST SP 800-60 Vol. 2 Rev. 1 from FIPS 200",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/moderate-impact-system/"
}

Record 2,716 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.