connected system
Any information system, application, or infrastructure component that lies **outside** a given system's authorization boundary yet maintains a data-flow, network, or processing link to it. It is distinguished from components *within* the boundary by the fact that it is independently owned, operated, or authorized — and therefore not directly governed by the controls of the system it connects to — while still being relevant to that system's risk posture, data flows, and scope determinations. In practice, security frameworks use the expression to delineate where one system's security responsibility ends and another's begins: an authorization boundary covers all components of an information system to be authorized for operation by an authorizing official, and excludes separately authorized systems to which the information system is connected. For each interconnection between systems owned or operated by different organizations, frameworks require documentation of the authorization for the connection and the sharing of information. An authorization boundary provides a diagrammatic illustration of a provider's internal services, components, and other devices along with connections to ex
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- Any information system, application, or infrastructure component that lies **outside** a given system's authorization boundary yet maintains a data-flow, network, or processing link to it. It is distinguished from components *within* the boundary by the fact that it is independently owned, operated, or authorized — and therefore not directly governed by the controls of the system it connects to — while still being relevant to that system's risk posture, data flows, and scope determinations. In practice, security frameworks use the expression to delineate where one system's security responsibility ends and another's begins: an authorization boundary covers all components of an information system to be authorized for operation by an authorizing official, and excludes separately authorized systems to which the information system is connected. For each interconnection between systems owned or operated by different organizations, frameworks require documentation of the authorization for the connection and the sharing of information. An authorization boundary provides a diagrammatic illustration of a provider's internal services, components, and other devices along with connections to exDR-088 backfill from the noun definition column