CGRC · Question #6
In the case of a complex information system, where a "leveraged authorization" that involves two agencies will be conducted, what is the minimum number of system boundaries/accreditation boundaries…
The correct answer is A. Only one. In a leveraged authorization involving two agencies for a single complex information system, the goal is to define a single accreditation boundary for the system to streamline the authorization process.
Question
In the case of a complex information system, where a "leveraged authorization" that involves two agencies will be conducted, what is the minimum number of system boundaries/accreditation boundaries that can exist? Response:
Options
- AOnly one.
- BOnly two, because there are two agencies.
- CAt least two.
- DA leveraged authorization cannot be conducted with more that one agency involved.
How the community answered
(34 responses)- A94% (32)
- C3% (1)
- D3% (1)
Why each option
In a leveraged authorization involving two agencies for a single complex information system, the goal is to define a single accreditation boundary for the system to streamline the authorization process.
Leveraged authorization aims to utilize one authorization package or decision across multiple organizations or for a system shared by multiple agencies. For a 'complex information system' receiving a leveraged authorization, a single accreditation boundary is typically defined for that system to facilitate a unified authorization decision.
While two agencies are involved, leveraged authorization seeks to avoid redundant processes by establishing a single authorization scope or boundary for the system being authorized.
Defining at least two system boundaries would contradict the efficiency and sharing principles inherent in 'leveraged authorization' for a single complex information system.
Leveraged authorization is explicitly designed for situations involving multiple agencies or shared services to reduce duplicated effort, so it can certainly be conducted with more than one agency.
Concept tested: Leveraged authorization and accreditation boundaries
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.