Common use of Information Security Categorization Clause in Contracts

Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Contractor Non-Disclosure Agreement and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following: Confidentiality: [ ] Low [ ] Moderate [ ] High Integrity: [ ] Low [ ] Moderate [ ] High Availability: [ ] Low [ ] Moderate [ ] High Overall Risk Level: [ ] Low [ ] Moderate [ ] High Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves: [ ] No PII [ ] Yes PII Personally Identifiable Information (PII) – Per the Office of Management and Budget (OMB) Circular A-130, "PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual." Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother's maiden name, biometric records, etc. PII Confidentiality Impact Level has been determined to be: [ ] Low [ ] Moderate [ ] High

Appears in 8 contracts

Samples: Chief Information Officer, Chief Information Officer, Chief Information Officer – Solutions And

AutoNDA by SimpleDocs
Time is Money Join Law Insider Premium to draft better contracts faster.