What the requirement actually says · 1.3

Which systems are in scope

Which systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see official CMMC programme material.

Why this decides everything

The boundary is the most consequential document you produce

It determines what is assessed, what has to be remediated, what has to be documented, what the assessment costs and how long it takes. Every other decision in the programme sits inside it.

It is also free to get right and expensive to get wrong, and it is frequently drawn by whoever produced the first network diagram.

What is in scope

Anything that processes, stores or transmits it

The test is contact with covered information. A system that never touches it is not in scope, and saying so with a documented reason is legitimate rather than evasive.

The categories to work through: systems that hold it, systems that transmit it, systems that provide security for those, and systems that could reach them.

The last category is the one that expands: a management workstation with administrative access to an in-scope system is in scope, however little covered information it holds.

The tension

Small is cheap and brittle; large is expensive and stable

A tight boundary reduces every cost in the programme. It also requires that people work inside it, and a boundary drawn so tightly that the work cannot be done is a boundary people route around.

Routing around is worse than a wider boundary, because it is undocumented and it puts covered information exactly where you promised it would not be.

The right size is the smallest one in which the work can actually be done, established by asking the people who do it.

Enclaves

Separating the covered work from everything else

The common architecture is a defined environment for covered information with controlled entry and exit, leaving the rest of the business out of scope.

It works, it is what an enclave product provides, and it depends on two things being true: that covered information genuinely stays inside, and that you can show it does. Both are process questions rather than product questions.

The shop floor

Where the boundary meets machines

The hardest part, and the entry on legacy machines covers it. The boundary decision here is whether machines are in scope or whether the information is transformed before it reaches them.

Both are defensible. What is not defensible is a boundary drawn around the office with a diagram that stops at the workshop door while technical data goes through it daily.

Documenting it

A diagram, a list and a reason

A diagram showing what is in and out. A list of systems with their status. And, for each significant exclusion, a stated reason.

The reasons are the part that matters. An assessor is not looking for a large boundary; they are looking for one whose edges were decided rather than defaulted.

Changing it

Deliberately, and recorded

Boundaries drift as systems are added. The change control question from the blog entry on staying compliant catches this: does this touch the boundary, and who has checked.

A boundary that has drifted without record is the finding that undermines the rest of the assessment, because it means the document describes something that is no longer true.

Testing the boundary

Follow one file

Take a real technical data package and trace every place it goes from arrival to the finished part: systems, people, machines, emails, backups, suppliers.

The trace either stays inside the boundary or it does not, and where it leaves is either a documented exception or a mistake in the diagram. This exercise takes a morning and finds more than a workshop does.

The people question

Scope includes who, not only what

Which roles need access to covered information is part of the boundary. Narrowing it is as effective as narrowing the systems and it is frequently easier, because most people who have access do not need it.

Shared systems

The system that serves both sides of the line

An email platform, a file server or an identity system used for covered and uncovered work. Either it comes into scope entirely, or the covered use moves elsewhere.

Attempting to have it partly in scope is the arrangement that fails an assessment most predictably, because the separation cannot be demonstrated.

Physical scope

Rooms as well as systems

Where covered information exists on paper, on screens visible from a walkway, or in an area visitors pass through, the physical protection requirements apply to those places.

The boundary is therefore partly a floor plan, and marking it on one is the clearest way to show what you decided.

Growth

Draw it for the business you will be

A boundary sized exactly to today needs redrawing when a second production line or a new customer arrives, and redrawing means re-documenting and possibly re-assessing.

Leaving room where it is cheap to do so is worth the marginal assessment cost, and it is a judgement rather than a rule.

Also

Elsewhere in what the requirement actually says