nerdexam
(ISC)2

CGRC · Question #53

The authorization boundary of a system undergoing assessment comprises of: Response:

The correct answer is A. The information System (IS) elements to be authorized for operation. The authorization boundary of an information system includes all elements subject to a single authorization decision. This clearly defines the scope of components for which an authorizing official grants approval to operate.

Scope of the System

Question

The authorization boundary of a system undergoing assessment comprises of:

Response:

Options

  • AThe information System (IS) elements to be authorized for operation
  • BAny elements or systems specified by the Chief Information Owner (CIO)
  • CAny components found withing the given Internet Protocol (IP) range
  • DThe information System (IS) elements to be authorized for operation as well as interconnected

How the community answered

(23 responses)
  • A
    87% (20)
  • B
    4% (1)
  • C
    9% (2)

Why each option

The authorization boundary of an information system includes all elements subject to a single authorization decision. This clearly defines the scope of components for which an authorizing official grants approval to operate.

AThe information System (IS) elements to be authorized for operationCorrect

The authorization boundary of a system comprises all information system elements that are directly under the management control of the authorizing organization and are subject to a single authorization decision to operate.

BAny elements or systems specified by the Chief Information Owner (CIO)

While a CIO may have input, the authorization boundary is defined by the technical and operational scope of the system under assessment for a single authorization, not solely by stakeholder specification.

CAny components found withing the given Internet Protocol (IP) range

Defining a boundary purely by an IP range is insufficient as it might arbitrarily include systems not under the organization's control or exclude relevant authorized components.

DThe information System (IS) elements to be authorized for operation as well as interconnected

Including 'interconnected' systems expands the boundary beyond what is typically subject to a *single* authorization, as interconnected systems often have their own distinct authorization boundaries.

Concept tested: Information system authorization boundary

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorization Boundary#Information System#NIST RMF#System Scope

Community Discussion

No community discussion yet for this question.

Full CGRC Practice