CGRC · Domain 2
Scope of the System
About 10% of the exam
The authorization boundary
- Everything the AO is accepting risk for
- Components under the same direct management control
- Includes people, processes, technology, locations
- Dependencies inside or explicitly inherited
- Diagram, narrative, inventory must agree
- Too narrow: unassessed dependencies
- Too broad: unmanageable, everything reauthorizes
The boundary decides which controls were assessed; a mismatch between SSP and SAR boundaries is a decision blocker
Categorize step
- Identify information types
- Provisional impact per objective
- Adjust with justification
- High water mark for the system
- Document and approve
- Information types
- SP 800-60 Volume 2 catalog
- Objectives
- confidentiality, integrity, availability
- Provisional levels
- low, moderate, high, or not applicable
- High water mark
- highest objective sets the system level
- Approval
- AO or designee signs the categorization
- Output
- drives baseline selection in Select
SC = {(confidentiality, impact), (integrity, impact), (availability, impact)}; the system takes the highest
FIPS 199 impact levels
- Low
- limited adverse effect
- Moderate
- serious adverse effect
- High
- severe or catastrophic effect
- Not applicable
- confidentiality of public information only
- Adverse effect on
- operations, assets, individuals, nation
- National security systems
- CNSSI 1253, not FIPS 199
Only confidentiality can be Not Applicable; integrity and availability always rate at least Low
SSP contents per SP 800-18
- System name, identifier, categorization
- Owner, AO, ISSO, points of contact
- Responsible organization and operational status
- General description and purpose
- Environment, architecture, data flows
- Interconnections with ISAs referenced
- Rules of behavior
- Control implementation statements
- References, not copies, of other plans
Control designations
- Common
- inherited, provider owns and assesses
- System-specific
- system owner implements fully
- Hybrid
- part inherited, part system implemented
- Provider named
- SSP must say who provides
- Scope stated
- provider documents exactly what is covered
- Redesignate
- when inheritance changes after re-architecture
Without a designation nobody knows who implements, assesses or answers for the control
Environment and interconnections
- Hardware, software, communications inventory
- Data flow diagrams with trust boundaries
- Interconnection table matches the diagrams
- MOU states intent; ISA states technical requirements
- External services and their authorizations
- Cloud: shared responsibility drawn explicitly
- Physical locations and hosting facilities
Who does what in scoping
- System owner
- defines boundary, owns the SSP
- Information owner
- sets information type and sensitivity
- ISSO
- drafts and maintains, day to day
- AO
- approves categorization and boundary
- Common control provider
- documents what others inherit
- SCA
- independently assesses against the plan
- Privacy officer
- PII inventory, PTA, PIA input
Registering and describing the system
Registration
- Unique identifier in the inventory
- Mission or business function supported
- Status: initiation, development, operational, disposal
- System type: major application, general support
- Ownership and responsible organization
Rules of behavior
- Expected user conduct and consequences
- Separate rules for privileged users
- Tailored per user community when needed
- Signed acknowledgement before access
- Required SSP component under SP 800-18
Information types
- Mission-based and management types
- Each mapped to provisional C, I, A
- PII flagged for privacy analysis
- Feeds categorization directly
Boundary pitfalls
- Critical database left outside the boundary
- Load balancer in diagram, absent in narrative
- Interconnection with MOU but no ISA
- Inherited controls with no named provider
- Planned controls marked implemented
- New PII module without recategorizing
- Boundary redrawn without AO approval
Cloud and leveraged authorizations
- FedRAMP provider holds its own authorization
- Agency SSP leverages and references it
- Provider controls documented as inherited
- Customer responsibility matrix fills the gaps
- Boundary crosses into shared responsibility
- Multiple zones, one logical boundary
- PaaS configuration is usually hybrid
Leveraging means inheriting what was assessed, then documenting and assessing what the provider left to you
Privacy in scoping
- PII inventory
- what personal data, where, why
- PTA
- threshold analysis: is a PIA needed
- PIA
- privacy risk analysis, SAOP signs
- SORN
- Federal Register notice, system of records
- Privacy plan
- in SSP or companion document
- Update trigger
- new data source, use or sharing
PIA analyzes risk; SORN gives public notice; a new routine use needs a new SORN, not just a revised PIA
Keeping the SSP current
- Update on significant change, at least annually
- Tie updates to configuration management
- Security impact analysis before changes
- Ownership transfer means plan update
- Status vocabulary: implemented, partial, planned, not applicable
- Not applicable needs written justification
- Partial links to a POA&M item
- Living document across the SDLC
Know the order
- Register
- Describe
- Identify information types
- Categorize
- Draw boundary
- Draft SSP
- Information types before impact levels
- Categorization before control selection
- Boundary before assessment scope
- PTA before PIA before SORN
Reference strip: boundary, categorization, SSP, privacy
Boundary
- Direct management control
- Diagram, narrative, inventory agree
- Dependencies in or inherited
- AO approves changes
Categorization
- FIPS 199 low, moderate, high
- SP 800-60 information types
- High water mark rule
- CNSSI 1253 for national security
SSP essentials
- SP 800-18 structure
- Roles and points of contact
- Rules of behavior signed
- Common, hybrid, system-specific
Interconnections
- MOU for intent and responsibilities
- ISA for technical security terms
- External services and their authorizations
Privacy
- PII inventory first
- PTA, then PIA if needed
- SORN for systems of records
- SAOP approves the PIA
Quick exam traps
- Trap: Integrity or availability can be rated Not Applicable
- Trap: The system takes the average of its three impact levels
- Trap: An MOU alone documents an interconnection adequately
- Trap: A FedRAMP authorization removes the agency's need for an SSP
- Trap: The SSP is finished once the system is authorized
- Trap: Not Applicable needs no justification if the control is obviously irrelevant
- Trap: Adding a new routine use only requires revising the PIA
cybercertprep.com · original revision sheet written from the public body of knowledge