Categorize the authorization package
In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting information types for the package from a list of information types provided by NIST and using the information types to define the impact levels for the package.
Before you begin
Role required: to use the Categorize button:
- sn_irm_cont_auth.system_owner
- sn_irm_cont_auth.info_system_sec_manager
- sn_irm_cont_auth.info_system_sec_officer
Role required: to write to an authorization package:
- sn_irm_cont_auth.admin
- sn_irm_cont_auth.system_owner
- sn_irm_cont_auth.info_system_sec_manager
- sn_irm_cont_auth.authorization_official
- sn_irm_cont_auth.info_system_sec_officer
Role required: to select information types:
- sn_irm_cont_auth.admin
- sn_irm_cont_auth.system_owner
Role required: to write to overridden fields on the Package form:
- sn_irm_cont_auth.system_owner