Define system scope and security boundary
Assessment starts with a clear boundary: which components, data flows, users, interconnections and providers are part of the system being authorized.
Questions to ask
- What is inside the boundary, and what connects to it?
- Which data at which classification does the system handle?
- Is the boundary documented in an architecture diagram?
