Determining Potential Impact of Authentication Errors

cite #sec22-1 Potential impact of inconvenience, distress, or damage to standing or reputation:

  • Low - at worst, limited, short-term inconvenience, distress or embarrassment to any party.
  • Moderate - at worst, serious short term or limited long-term inconvenience, distress or damage to the standing or reputation of any party
  • High - severe or serious long-term inconvenience, distress or damage to the standing or reputation of any party (ordinarily reserved for situations with particularly severe effects or which affect many individuals).

cite #sec22-2 Potential impact of financial loss:

  • Low - at worst, an insignificant or inconsequential unrecoverable financial loss to any party, or at worst, an insignificant or inconsequential agency liability.
  • Moderate - at worst, a serious unrecoverable financial loss to any party, or a serious agency liability.
  • High - severe or catastrophic unrecoverable financial loss to any party; or severe or catastrophic agency liability.

cite #sec22-3 Potential impact of harm to agency programs or public interests:

  • Low - at worst, a limited adverse effect on organizational operations or assets, or public interests. Examples of limited adverse effects are: (i) mission capability degradation to the extent and duration that the organization is able to perform its primary functions with noticeably reduced effectiveness, or (ii) minor damage to organizational assets or public interests.
  • Moderate - at worst, a serious adverse effect on organizational operations or assets, or public interests. Examples of serious adverse effects are: (i) significant mission capability degradation to the extent and duration that the organization is able to perform its primary functions with significantly reduced effectiveness; or (ii) significant damage to organizational assets or public interests.
  • High - a severe or catastrophic adverse effect on organizational operations or assets, or public interests. Examples of severe or catastrophic effects are: (i) severe mission capability degradation or loss of to the extent and duration that the organization is unable to perform one or more of its primary functions; or (ii) major damage to organizational assets or public interests.

cite #sec22-4 Potential impact of unauthorized release of sensitive information:

  • Low - at worst, a limited release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in a loss of confidentiality with a low impact as defined in FIPS PUB 199.
    • FIPS PUB 199 (Low Impact) - The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals. AMPLIFICATION: A limited adverse effect means that, for example, the loss of confidentiality, integrity, or availability might: (i) cause a degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced; (ii) result in minor damage to organizational assets; (iii) result in minor financial loss; or (iv) result in minor harm to individuals
  • Moderate - at worst, a release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in loss of confidentiality with a moderate impact as defined in FIPS PUB 199.
    • FIPS PUB 199 (Moderate Impact) - The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals. AMPLIFICATION: A serious adverse effect means that, for example, the loss of confidentiality, integrity, or availability might: (i) cause a significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced; (ii) result in significant damage to organizational assets; (iii) result in significant financial loss; or (iv) result in significant harm to individuals that does not involve loss of life or serious life threatening injuries.
  • High - a release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in loss of confidentiality with a high impact as defined in FIPS PUB 199.
    • FIPS PUB 199 (High Impact) - The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. AMPLIFICATION: A severe or catastrophic adverse effect means that, for example, the loss of confidentiality, integrity, or availability might: (i) cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions; (ii) result in major damage to organizational assets; (iii) result in major financial loss; or (iv) result in severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.

cite #sec22-5 Potential impact to personal safety:

  • Low - at worst, minor injury not requiring medical treatment.
  • Moderate - at worst, moderate risk of minor injury or limited risk of injury requiring medical treatment.
  • High - a risk of serious injury or death.

cite #sec22-6 The potential impact of civil or criminal violations is:

  • Low - at worst, a risk of civil or criminal violations of a nature that would not ordinarily be subject to enforcement efforts.
  • Moderate - at worst, a risk of civil or criminal violations that may be subject to enforcement efforts.
  • High - a risk of civil or criminal violations that are of special importance to enforcement programs.