nerdexam
(ISC)2

CGRC · Question #533

One of the following sentences can appropriately help Authorizing Officials and CISOs define an accreditation boundary. Response:

The correct answer is B. The set of system elements comprising the system to be authorized for operation or use. An accreditation boundary delineates the scope of an information system that is subject to a specific authorization decision, encompassing all its interconnected components. It defines the specific set of system elements that will be authorized for operation or use.

Scope of the System

Question

One of the following sentences can appropriately help Authorizing Officials and CISOs define an accreditation boundary. Response:

Options

  • AThe components of an information system that are under the same management authority
  • BThe set of system elements comprising the system to be authorized for operation or use
  • CInternal and external systems that are interconnected through the internet.

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    93% (41)
  • C
    5% (2)

Why each option

An accreditation boundary delineates the scope of an information system that is subject to a specific authorization decision, encompassing all its interconnected components. It defines the specific set of system elements that will be authorized for operation or use.

AThe components of an information system that are under the same management authority

While management authority is a factor, an accreditation boundary is more comprehensively defined by the actual system elements under authorization, not just management.

BThe set of system elements comprising the system to be authorized for operation or useCorrect

An accreditation boundary is precisely defined as the collection of all system elements, including hardware, software, firmware, and data, that collectively form the information system slated for authorization by an authorizing official.

CInternal and external systems that are interconnected through the internet.

This describes a network interconnection rather than the specific system boundary defined for an authorization.

Concept tested: Definition of an accreditation boundary

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Accreditation Boundary#Authorization Boundary#System Scope#Risk Management Framework (RMF)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice