FISMA Interview Practice Test

Access More Questions
Accreditation boundary according to NIST SP 800-37 regroups
Correct Answer:
All components of an information system to be accredited by an authorizing official and excludes separately accredited systems to which the information system is connected.
Explanation:
The important idea here is what gets evaluated and approved in a security authorization. The accreditation boundary defines the scope of an information system that will be assessed and authorized by the authorizing official. It includes all components that make up the information system to be accredited, and it excludes separately accredited systems that are connected to it. This framing ensures the risk assessment and protections apply to the system as a unified package, without subsuming other systems that have their own authorizations. That’s why this choice fits best: it accurately describes the boundary as the entire system to be accredited, while omitting other systems that are connected but carry their own authorization. The other options describe boundaries that are either too broad (the whole organization network), too narrow (the physical perimeter, or just the software portion), and don’t reflect the formal authorization scope defined in the RMF.

Access more questions from this quiz

Continue to FISMA Interview Practice Test for more practice questions and the full quiz experience.

Access More Questions