ISC2 Governance, Risk and Compliance (CGRC) Practice Question
You are preparing the SSP for a new EHR system. Its environment includes virtual-machine web/application servers, a SAN storing patient data, an internal load balancer, and the corporate HR system that receives a nightly EHR summary via an encrypted API. Which component lies outside the EHR authorization boundary?
The organization's HR system that ingests the nightly summary file
The internal load balancer distributing user traffic among the web servers
The virtual machines hosting the EHR web and application tiers
The dedicated SAN where patient records are stored
The authorization boundary encloses only components that process, store, or transmit EHR data directly. Because the virtual machines, SAN, and internal load balancer all handle patient information, they fall inside the boundary. The corporate HR system merely receives a summary file and does not inherit the EHR system's security controls, so NIST views it as a separate, externally connected information system that must be documented as an interconnection, not included in the EHR boundary.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an authorization boundary in NIST terminology?
Open an interactive chat with Bash
Why does the HR system fall outside the EHR authorization boundary?
Open an interactive chat with Bash
What is the significance of documenting interconnections for systems outside the authorization boundary?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .