nerdexam
(ISC)2

CGRC · Question #392

A system or system element that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application or…

The correct answer is B. An external system (or component). The description refers to a system or element outside an organization's authorization boundary and not under its direct control for application or control assessment.

Scope of the System

Question

A system or system element that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application or required controls of the assessment of control effectiveness best defines:

Response:

Options

  • AA high-Impact System
  • BAn external system (or component)
  • CA major application
  • DA minor application

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    89% (40)
  • C
    2% (1)
  • D
    7% (3)

Why each option

The description refers to a system or element outside an organization's authorization boundary and not under its direct control for application or control assessment.

AA high-Impact System

A high-Impact System refers to the impact level of a system, not its boundary or control.

BAn external system (or component)Correct

An 'external system (or component)' is precisely defined as a system or element outside an organization's authorization boundary over which it has no direct control regarding its application or control assessment. This definition is fundamental in risk management frameworks for understanding organizational scope and responsibilities.

CA major application

A major application is a term used to classify applications based on their scope or importance, not their control or boundary.

DA minor application

A minor application is a term used to classify applications based on their scope or importance, not their control or boundary.

Concept tested: Definition of external system or component

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#External system#Authorization boundary#System scope#Control effectiveness

Community Discussion

No community discussion yet for this question.

Full CGRC Practice