Criticality

How essential an asset, system, process or data set is to the organisation, judged by how severely and how quickly its loss would cause harm. It mainly drives availability and recovery decisions.

Full guide: Business Impact Analysis Explained: The BIA Process and Outputs for CISSP

Criticality measures how much the organisation depends on something. A critical asset, system, process or data set is one whose loss or unavailability would quickly cause serious harm: halted operations, missed legal obligations, lost revenue or danger to people. Criticality is one of the inputs to asset classification and data classification, and for business functions it is usually measured in the business impact analysis, which produces a ranked order for recovery.

The term most often confused with it is sensitivity. Sensitivity concerns the harm from disclosure, so it mainly drives confidentiality controls. Criticality concerns the harm from the item being unavailable or unusable, so it mainly drives redundancy, backup and recovery priority, and targets such as the maximum tolerable downtime. The two are independent: an online shop’s public product catalogue can be highly critical without being sensitive, while an archive of old personnel files can be sensitive without being critical. FIPS 199 reflects the same split by rating potential impact separately for confidentiality, integrity and availability.

Exam relevance: a scenario is likely to describe an asset or data set and ask what should drive its protection. Candidates are expected to link criticality with availability and recovery order, and sensitivity with confidentiality, and to recognise that one item can rate high on one and low on the other.