nerdexam
(ISC)2

CGRC · Question #619

What are the three primary considerations for defining system boundaries? Response:

The correct answer is A. 1. Normally be under the same direct management control. One primary consideration for defining system boundaries is that the system components should normally be under the same direct management control. This criterion helps to ensure consistent application of security policies and accountability within the system's scope.

Scope of the System

Question

What are the three primary considerations for defining system boundaries? Response:

Options

  • A
    1. Normally be under the same direct management control.
  • B
    1. Abnormally be under the same direct management control.
  • C
    1. Normally be under the same indirect management control.
  • D
    1. Normally be under the same direct management control.

How the community answered

(33 responses)
  • A
    91% (30)
  • B
    6% (2)
  • C
    3% (1)

Why each option

One primary consideration for defining system boundaries is that the system components should normally be under the same direct management control. This criterion helps to ensure consistent application of security policies and accountability within the system's scope.

A1. Normally be under the same direct management control.Correct

A fundamental consideration when defining system boundaries is that the components within the boundary are typically under the same direct management control. This criterion helps delineate which assets and operations are consistently governed by the same security policies and processes, simplifying risk management and oversight.

B1. Abnormally be under the same direct management control.

System components being "abnormally" under the same direct management control is not a standard or logical consideration for defining boundaries.

C1. Normally be under the same indirect management control.

Components being under "indirect" management control suggests a less unified approach to security, which complicates boundary definition and direct security responsibility.

D1. Normally be under the same direct management control.

This choice is identical to A in its provided text and therefore represents the same correct consideration for defining system boundaries.

Concept tested: NIST RMF system boundary definition

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#System boundaries#Scope definition#Management control

Community Discussion

No community discussion yet for this question.

Full CGRC Practice