CGRC · Question #533
One of the following sentences can appropriately help Authorizing Officials and CISOs define an accreditation boundary. Response:
The correct answer is B. The set of system elements comprising the system to be authorized for operation or use. An accreditation boundary delineates the scope of an information system that is subject to a specific authorization decision, encompassing all its interconnected components. It defines the specific set of system elements that will be authorized for operation or use.
Question
One of the following sentences can appropriately help Authorizing Officials and CISOs define an accreditation boundary. Response:
Options
- AThe components of an information system that are under the same management authority
- BThe set of system elements comprising the system to be authorized for operation or use
- CInternal and external systems that are interconnected through the internet.
How the community answered
(44 responses)- A2% (1)
- B93% (41)
- C5% (2)
Why each option
An accreditation boundary delineates the scope of an information system that is subject to a specific authorization decision, encompassing all its interconnected components. It defines the specific set of system elements that will be authorized for operation or use.
While management authority is a factor, an accreditation boundary is more comprehensively defined by the actual system elements under authorization, not just management.
An accreditation boundary is precisely defined as the collection of all system elements, including hardware, software, firmware, and data, that collectively form the information system slated for authorization by an authorizing official.
This describes a network interconnection rather than the specific system boundary defined for an authorization.
Concept tested: Definition of an accreditation boundary
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.