CGRC · Question #53
The authorization boundary of a system undergoing assessment comprises of: Response:
The correct answer is A. The information System (IS) elements to be authorized for operation. The authorization boundary of an information system includes all elements subject to a single authorization decision. This clearly defines the scope of components for which an authorizing official grants approval to operate.
Question
The authorization boundary of a system undergoing assessment comprises of:
Response:
Options
- AThe information System (IS) elements to be authorized for operation
- BAny elements or systems specified by the Chief Information Owner (CIO)
- CAny components found withing the given Internet Protocol (IP) range
- DThe information System (IS) elements to be authorized for operation as well as interconnected
How the community answered
(23 responses)- A87% (20)
- B4% (1)
- C9% (2)
Why each option
The authorization boundary of an information system includes all elements subject to a single authorization decision. This clearly defines the scope of components for which an authorizing official grants approval to operate.
The authorization boundary of a system comprises all information system elements that are directly under the management control of the authorizing organization and are subject to a single authorization decision to operate.
While a CIO may have input, the authorization boundary is defined by the technical and operational scope of the system under assessment for a single authorization, not solely by stakeholder specification.
Defining a boundary purely by an IP range is insufficient as it might arbitrarily include systems not under the organization's control or exclude relevant authorized components.
Including 'interconnected' systems expands the boundary beyond what is typically subject to a *single* authorization, as interconnected systems often have their own distinct authorization boundaries.
Concept tested: Information system authorization boundary
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.