FIPS 199 Assessment Clause Samples

The FIPS 199 Assessment clause requires an evaluation of an information system's security categorization based on the Federal Information Processing Standard (FIPS) Publication 199. In practice, this involves determining the potential impact levels—low, moderate, or high—on confidentiality, integrity, and availability of the system's information. This assessment guides the selection of appropriate security controls and ensures compliance with federal standards, ultimately helping organizations manage risk and protect sensitive data effectively.
FIPS 199 Assessment. In accordance with HHSAR Clause 352.239-72, Security Requirements For Federal Information Technology Resources, the Contractor shall submit a FIPS 199 Assessment within thirty (30) days after contract award. The FIPS 199 Assessment shall be consistent with the cited NIST standard. (Reference subparagraph D.c.3 of the Information and Physical Access Security clause in Article H.7