Question 1
A federal agency is preparing a new data analytics platform for authorization. The platform will process publicly available datasets as well as sensitive citizen PII. The development team has proposed a system boundary that includes the cloud-based data lake and processing engines, but excludes the on-premises data ingestion servers that perform initial data cleansing. According to NIST SP 800-37 R2, what is the primary risk of this proposed boundary definition?
Answer and explanation
Correct answer: D
The authorization boundary must encompass all components essential for the system's mission. By excluding the on-premises ingestion servers, which are integral to the data processing workflow, the agency creates a significant gap in its risk assessment. Vulnerabilities in these excluded servers could be exploited to compromise the data's integrity or confidentiality before it even reaches the assessed and authorized cloud environment. This introduces unmanaged risk, undermining the entire authorization effort.