An OSC is preparing for a CMMC assessment. It has multiple information systems, some of which process CUI and others that do not. The OSC has identified a specific system that processes CUI and defined this as its system boundary. However, this system is connected to other systems within the OSC that are separately authorized and do not process CUI. As a Certified CMMC Assessor, which of the following best describes your approach to defining the CMMC Certification Boundary and Assessment Scope for the OSC?
Comprehensive and Detailed
The CMMC Assessment Process (CAP) distinguishes the Certification Boundary (the CUI-processing system) from the Assessment Scope (all components needing authorization, excluding separately authorized connected systems). The scoping guide and glossary confirm that separately authorized systems are out of scope, aligning with Option D. Option A is too broad, Option B too narrow, and Option C reverses the definitions. D is correct.
CMMC Assessment Process (CAP) v1.0, Section 2.1 (Certification Boundary), p. 8: 'The Assessment Scope excludes separately authorized systems.'
Marta
22 days agoSelma
27 days agoTracey
2 months agoJoanna
2 months agoDannie
2 months agoQuentin
2 months agoIluminada
2 months agoBernadine
2 months agoFlo
3 months agoLynette
3 months agoTerina
3 months agoEleonora
3 months agoValentine
3 months agoEttie
3 months agoGilberto
4 months agoLaurene
4 months agoQuentin
4 months agoBenton
4 months agoIsabella
5 months agoJose
5 months agoVerdell
5 months agoEarlean
5 months agoFatima
5 months agoLuis
6 months agoBobbie
6 months agoGerald
6 months agoVivienne
6 months agoMari
6 days agoCaren
11 days agoArthur
17 days agoSharen
4 months ago