arckit-us-fisma-categorization

Generate FIPS 199 security categorizations by mapping information types to NIST SP 800-60.

Updated Jul 24, 2026
One-click install
npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-us-fisma-categorization
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: arckit-us-fisma-categorization
Source: https://github.com/tractorjuice/arckit-kimi/tree/main/skills/arckit-us-fisma-categorization
Command: npx skills add https://github.com/tractorjuice/arckit-kimi --skill arckit-us-fisma-categorization

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This skill automates the complex and error-prone process of determining the FIPS 199 security impact level for US federal information systems, ensuring compliance with FISMA requirements.

Core Features & Use Cases

  • Automated Categorization: Maps information types to NIST SP 800-60 categories and calculates the system high-water mark.
  • Compliance Documentation: Generates a structured FIPS 199 artefact including the CIA impact matrix and rationale for adjustments.
  • Use Case: An enterprise architect needs to establish the security baseline for a new federal system; this skill inventories information types and derives the required Low, Moderate, or High impact level to inform the RMF process.

Quick Start

Invoke the arckit-us-fisma-categorization skill to generate the FIPS 199 security categorization for the current project.

Frequently Asked Questions about arckit-us-fisma-categorization

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I calculate the FIPS 199 security categorization for a federal civilian information system?

To calculate the FIPS 199 security categorization, you map information types to NIST SP 800-60 standards and evaluate CIA impact levels. This determines the system high-water mark of Low, Moderate, or High for FISMA compliance.

What is the FIPS 199 system high-water mark in the FISMA RMF process?

The FIPS 199 system high-water mark is the overall security impact level derived from the highest Confidentiality, Integrity, or Availability rating. It establishes the required security baseline for a federal system during RMF Step 1.

How do I map information types to NIST SP 800-60 categories for FISMA compliance?

Mapping information types to NIST SP 800-60 categories involves inventorying the system's data and matching it to predefined standards. This process calculates the CIA impact matrix to generate a structured FIPS 199 compliance artifact.

Does FIPS 199 categorization require integration with existing architecture artefacts?

Yes, FIPS 199 categorization requires integration with project-specific architecture artefacts. This ensures the information type inventory and resulting CIA impact matrix accurately reflect the system's design and adhere to OMB and NIST regulatory frameworks.

Can I automate the FIPS 199 CIA impact matrix generation for multiple federal systems?

You can automate FIPS 199 CIA impact matrix generation by inventorying information types and calculating system high-water marks. This ensures consistent FISMA compliance documentation and standardizes the security baseline establishment process.

When do I need to perform a FIPS 199 security categorization during the RMF process?

You need to perform FIPS 199 security categorization during RMF Step 1. It establishes the Low, Moderate, or High security baseline before proceeding with security control selection and implementation for US federal civilian information systems.