Establishing impact
An essential part of assessing information value is assigning a qualitative score representing the potential impact on the organization if the information is lost, stolen, or destroyed. This score helps inform the information security professional about the importance of a dataset to the organization.
Using the potential impact definitions from NIST Special Publication 199 as a reference, we will apply the information that was gathered during the categorization process to assign an impact rating to the data. The potential impact levels are categorized as Low, Moderate, and High based on the three core security objectives – that is, confidentiality, integrity, and availability:
- Confidentiality: This objective focuses on preserving authorized information access and disclosure restrictions, including measures for protecting personal privacy and proprietary information:
- Low impact: Unauthorized disclosure of the information would likely result in limited...