An OSC is preparing for a CMMC assessment. It has multiple information systems, some of which process CUI and others that do not. The OSC has identified a specific system that processes CUI and defined this as its system boundary. However, this system is connected to other systems within the OSC that are separately authorized and do not process CUI. As a Certified CMMC Assessor, which of the following best describes your approach to defining the CMMC Certification Boundary and Assessment Scope for the OSC?
Comprehensive and Detailed
The CMMC Assessment Process (CAP) distinguishes the Certification Boundary (the CUI-processing system) from the Assessment Scope (all components needing authorization, excluding separately authorized connected systems). The scoping guide and glossary confirm that separately authorized systems are out of scope, aligning with Option D. Option A is too broad, Option B too narrow, and Option C reverses the definitions. D is correct.
CMMC Assessment Process (CAP) v1.0, Section 2.1 (Certification Boundary), p. 8: 'The Assessment Scope excludes separately authorized systems.'
Tracey
10 hours agoJoanna
6 days agoDannie
11 days agoQuentin
16 days agoIluminada
21 days agoBernadine
26 days agoFlo
1 month agoLynette
1 month agoTerina
1 month agoEleonora
2 months agoValentine
2 months agoEttie
2 months agoGilberto
2 months agoLaurene
2 months agoQuentin
3 months agoBenton
3 months agoIsabella
3 months agoJose
3 months agoVerdell
4 months agoEarlean
4 months agoFatima
4 months agoLuis
4 months agoBobbie
4 months agoGerald
4 months agoVivienne
5 months agoSharen
2 months ago