Problem
There are two different forms of guidance for the "impact" of an event in Risk Management, associated with information systems, documented in FIPS 199 and NIST. The former uses three categories and the latter uses five. Is there a negligible difference to the two additional categories, or is the deeper level of granularity beneficial?