nerdexam
(ISC)2

CGRC · Question #687

Testing must include an assessment of the _____________ as described in the system security plan, as recorded in the risk assessment, and reflected in the accreditation boundary; all should be the sam

The correct answer is A. System Boundary. Testing within an information system's security lifecycle must encompass an assessment of the system boundary, which defines the scope of the system as described in its security plan, risk assessment, and accreditation documentation.

Scope of the System

Question

Testing must include an assessment of the _____________ as described in the system security plan, as recorded in the risk assessment, and reflected in the accreditation boundary; all should be the same. Response:

Options

  • ASystem Boundary
  • BAuthorization Boundary
  • CNetwork Boundary
  • DNone of these
  • EAll of the above

How the community answered

(41 responses)
  • A
    95% (39)
  • C
    2% (1)
  • E
    2% (1)

Why each option

Testing within an information system's security lifecycle must encompass an assessment of the system boundary, which defines the scope of the system as described in its security plan, risk assessment, and accreditation documentation.

ASystem BoundaryCorrect

The 'system boundary' defines the scope of an information system, encompassing all components that process, store, or transmit information. It is critical that this boundary is consistently defined and understood across the system security plan, risk assessment, and accreditation documentation to ensure that testing adequately covers the entire system in scope for authorization.

BAuthorization Boundary

The 'authorization boundary' refers to the entire set of information resources managed by an organization that is covered by an authorization decision, which can include multiple systems, and is a broader concept than the specific scope of a single system for testing.

CNetwork Boundary

A 'network boundary' is a specific type of boundary related to network segmentation but may not encompass all aspects of an information system, such as applications, data, and users, which are covered by the system boundary.

DNone of these

There is a correct answer among the choices.

EAll of the above

Not all options are correct, as A is the most precise term.

Concept tested: System Boundary Definition in RMF

Source: https://csrc.nist.gov/glossary/term/system_boundary

Topics

#System Boundary#RMF#System Security Plan#Accreditation Boundary

Community Discussion

No community discussion yet for this question.

Full CGRC Practice