nerdexam
(ISC)2

CGRC · Question #6

In the case of a complex information system, where a "leveraged authorization" that involves two agencies will be conducted, what is the minimum number of system boundaries/accreditation boundaries…

The correct answer is A. Only one. In a leveraged authorization involving two agencies for a single complex information system, the goal is to define a single accreditation boundary for the system to streamline the authorization process.

Scope of the System

Question

In the case of a complex information system, where a "leveraged authorization" that involves two agencies will be conducted, what is the minimum number of system boundaries/accreditation boundaries that can exist? Response:

Options

  • AOnly one.
  • BOnly two, because there are two agencies.
  • CAt least two.
  • DA leveraged authorization cannot be conducted with more that one agency involved.

How the community answered

(34 responses)
  • A
    94% (32)
  • C
    3% (1)
  • D
    3% (1)

Why each option

In a leveraged authorization involving two agencies for a single complex information system, the goal is to define a single accreditation boundary for the system to streamline the authorization process.

AOnly one.Correct

Leveraged authorization aims to utilize one authorization package or decision across multiple organizations or for a system shared by multiple agencies. For a 'complex information system' receiving a leveraged authorization, a single accreditation boundary is typically defined for that system to facilitate a unified authorization decision.

BOnly two, because there are two agencies.

While two agencies are involved, leveraged authorization seeks to avoid redundant processes by establishing a single authorization scope or boundary for the system being authorized.

CAt least two.

Defining at least two system boundaries would contradict the efficiency and sharing principles inherent in 'leveraged authorization' for a single complex information system.

DA leveraged authorization cannot be conducted with more that one agency involved.

Leveraged authorization is explicitly designed for situations involving multiple agencies or shared services to reduce duplicated effort, so it can certainly be conducted with more than one agency.

Concept tested: Leveraged authorization and accreditation boundaries

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Leveraged Authorization#System Boundary#Accreditation Boundary#Multi-agency Collaboration

Community Discussion

No community discussion yet for this question.

Full CGRC Practice