ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A security officer is starting the RMF Prepare phase for a new SaaS environment. Before identifying information types or selecting controls, which element must be documented first to establish the system's authorization boundary and lay the groundwork for all later scoping activities?
The system's name or unique ID and a brief statement of its mission, purpose, and scope
The preliminary list of compensating controls for any anticipated baseline deviations
The planned schedule for penetration testing and continuous-monitoring activities
The information types the system will process, including data flows and external interfaces
NIST RMF tasks require that the authorization boundary begin with basic system identification: the system's official name or unique identifier together with a concise statement of its mission, purpose, and scope. This high-level description comes before listing hardware, software, information types, data flows, assessments, or training needs, and anchors all subsequent scoping and categorization work.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an authorization boundary in the RMF context?
Open an interactive chat with Bash
Why is a system's mission, purpose, and scope documented first in the RMF Prepare phase?
Open an interactive chat with Bash
What role does NIST guidance play in defining authorization boundaries?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .