Supports the administration of entitled benefits for organizational personnel such as retirement, medical, disability, and insurance. The overall accountability rating for this information classification is Low.
Confidentiality level = Moderate
The confidentiality impact level is the effect of unauthorized disclosure of benefits management information on the abilities of responsible entities to administer entitled benefits for organizational personnel and/or clients such as retirement, medical, disability, and insurance. The consequences of unauthorized disclosure of the majority of benefits management information will result in adverse effects on organizational operations, organizational assets, or individuals.
Known mitigating factors toward changing the confidentiality level
Where more sensitive information is involved, it will probably be personal information subject to the various state and international privacy laws, the Health Insurance Portability and Accountability Act of 1996, the Payment Card Industry Data Security Standard, contractual security and privacy standards, or information that is proprietary to a corporation or other organization. In such cases, the consequences of unauthorized disclosure of benefits management information could be serious (particularly in cases of exposure of large data bases that might reveal private medical information or facilitate identity theft or other financial fraud). (The provisional impact levels for personnel information are documented in the Personal Identity and Authentication, Income, and Entitlement Event information types.) In such cases, the confidentiality impact level would be high.
Integrity level = Low
The integrity impact level is based on the specific mission and the data supporting that mission, not on the time required to detect the modification or destruction of information. The consequences of unauthorized modification or destruction of benefits management information depends mostly on the criticality of the information with respect to organizational mission capability, protection of organizational assets, and safety of individuals. In general, the effects of modifications or deletion of this information are generally limited with respect to organizational mission capabilities or assets.
Availability level = Low
The availability impact level is based on the specific mission and the data supporting that mission, not on the time required to reestablish access to the benefits management information. Typically, benefits management processes are tolerant of reasonable delays.
