Research and explain the differences between the DISA categories used for STIGS (Mission Critical, Mission Support, Administrative, Classified, Sensitive, and Public). How would you apply these classifications to systems within a public organization?

A Jessica

Defense Information Systems Agency (DISA) is a division of the Department of Defense and was implemented to assist in providing guidance for the technical aspects of managing IT related security. DISA developed guides for this called Security Technical Implementation Guides (STIGs), which assist in outlining the recommendations for handling and managing security software and systems. The DISA has three different categories that they use within the STIGs to describe the severity of the security vulnerabilities that are discussed (Ashley, 2021). Category 1 refers to any vulnerability that will immediately result in loss of confidentiality, availability, or integrity. This is considered the most severe vulnerability because it results in data loss and a loss of integrity for the system, resulting in further possible damage. Category 2 refers to vulnerabilities that could possibly result in the loss of confidentiality, availability or integrity. Category 3 refers to any vulnerabilities that damages the security measures intended to protect against the loss of confidentiality, availability, or integrity. In regards to systems within a public organization, the Network Administrator should refer to the STIGs themselves for assisting with identifying the various categories at each point within the network.