Impact Levels
Impact levels are a ranked way of describing how serious the consequences would be if a system failed or suffered a security breach. They are commonly expressed as Low, Moderate, or High, with higher levels indicating more severe potential harm. In government cloud contexts, the assigned impact level also reflects how sensitive the data is and helps determine which set of security requirements applies.
Impact levels are a categorization scheme that ranks the potential adverse effect of a loss of confidentiality, integrity, or availability arising from a system failure or security breach. Under FIPS 200, as referenced in the NIST glossary, impact is broadly categorized into three levels: Low, Moderate, or High. In the FedRAMP context, impact levels characterize the sensitivity of federal data within a cloud system and determine which security baseline applies, and GSA describes the corresponding low-impact, moderate-impact, and high-impact identifications as based on federal government requirements. This entry addresses the security-categorization sense of the term; it does not cover the distinct usage of impact in social or organizational outcome frameworks, nor does it detail the specific control selections, baselines, or authorization procedures associated with each level.
Why it matters
Impact levels give organizations a shared vocabulary for triaging risk. By ranking the potential adverse effect of a loss of confidentiality, integrity, or availability as Low, Moderate, or High, teams can prioritize where to concentrate limited security resources and justify why a given system warrants more rigorous controls than another. This categorization sits at the front end of security planning: it shapes downstream decisions about which safeguards are proportionate to the consequences of a failure or breach, rather than applying uniform controls regardless of sensitivity.
In the U.S. federal cloud context, impact levels carry particular weight because they are tied to formal requirements. Under FedRAMP, the impact level assigned to a cloud system characterizes how sensitive the federal data within it is and, in turn, determines which security baseline applies. GSA describes the low-impact, moderate-impact, and high-impact identifications as based on the federal government's requirements. A misjudged categorization can therefore result in a system being held to the wrong baseline, undermining the assurance that the process is meant to provide.
Because impact levels reflect the severity of consequences rather than the likelihood of an event, they should be understood as one input into a broader risk process, not a complete measure of risk on their own. This entry addresses the security-categorization sense of the term and does not cover the specific control selections, baselines, or authorization procedures associated with each level, nor the distinct usage of impact in social or organizational outcome frameworks.
Who it's relevant to
Inside Impact Levels
Common questions
Answers to the questions practitioners most commonly ask about Impact Levels.