What the requirement actually says · 1.3
Which systems are in scope
Which systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
For an adjacent operational perspective, more information explains the topic in a practical workplace context.
For an independent reference point, see official CMMC programme material.
Why this decides everything
The boundary is the most consequential document you produce
It determines what is assessed, what has to be remediated, what has to be documented, what the assessment costs and how long it takes. Every other decision in the programme sits inside it.
It is also free to get right and expensive to get wrong, and it is frequently drawn by whoever produced the first network diagram.
What is in scope
Anything that processes, stores or transmits it
The test is contact with covered information. A system that never touches it is not in scope, and saying so with a documented reason is legitimate rather than evasive.
The categories to work through: systems that hold it, systems that transmit it, systems that provide security for those, and systems that could reach them.
The last category is the one that expands: a management workstation with administrative access to an in-scope system is in scope, however little covered information it holds.
The tension
Small is cheap and brittle; large is expensive and stable
A tight boundary reduces every cost in the programme. It also requires that people work inside it, and a boundary drawn so tightly that the work cannot be done is a boundary people route around.
Routing around is worse than a wider boundary, because it is undocumented and it puts covered information exactly where you promised it would not be.
The right size is the smallest one in which the work can actually be done, established by asking the people who do it.
Enclaves
Separating the covered work from everything else
The common architecture is a defined environment for covered information with controlled entry and exit, leaving the rest of the business out of scope.
It works, it is what an enclave product provides, and it depends on two things being true: that covered information genuinely stays inside, and that you can show it does. Both are process questions rather than product questions.
The shop floor
Where the boundary meets machines
The hardest part, and the entry on legacy machines covers it. The boundary decision here is whether machines are in scope or whether the information is transformed before it reaches them.
Both are defensible. What is not defensible is a boundary drawn around the office with a diagram that stops at the workshop door while technical data goes through it daily.
Documenting it
A diagram, a list and a reason
A diagram showing what is in and out. A list of systems with their status. And, for each significant exclusion, a stated reason.
The reasons are the part that matters. An assessor is not looking for a large boundary; they are looking for one whose edges were decided rather than defaulted.
Changing it
Deliberately, and recorded
Boundaries drift as systems are added. The change control question from the blog entry on staying compliant catches this: does this touch the boundary, and who has checked.
A boundary that has drifted without record is the finding that undermines the rest of the assessment, because it means the document describes something that is no longer true.
Testing the boundary
Follow one file
Take a real technical data package and trace every place it goes from arrival to the finished part: systems, people, machines, emails, backups, suppliers.
The trace either stays inside the boundary or it does not, and where it leaves is either a documented exception or a mistake in the diagram. This exercise takes a morning and finds more than a workshop does.
The people question
Scope includes who, not only what
Which roles need access to covered information is part of the boundary. Narrowing it is as effective as narrowing the systems and it is frequently easier, because most people who have access do not need it.
Shared systems
The system that serves both sides of the line
An email platform, a file server or an identity system used for covered and uncovered work. Either it comes into scope entirely, or the covered use moves elsewhere.
Attempting to have it partly in scope is the arrangement that fails an assessment most predictably, because the separation cannot be demonstrated.
Physical scope
Rooms as well as systems
Where covered information exists on paper, on screens visible from a walkway, or in an area visitors pass through, the physical protection requirements apply to those places.
The boundary is therefore partly a floor plan, and marking it on one is the clearest way to show what you decided.
Growth
Draw it for the business you will be
A boundary sized exactly to today needs redrawing when a second production line or a new customer arrives, and redrawing means re-documenting and possibly re-assessing.
Leaving room where it is cheap to do so is worth the marginal assessment cost, and it is a judgement rather than a rule.
Also
Elsewhere in what the requirement actually says
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.