home/glossary/Authorization Boundary

Authorization Boundary

nounid 1608·updated May 9, 2026
verified

All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.

MWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems2 citations · 2 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
3.2.2 ¶ 473.2.2 ¶ 49

Classifications

Entity Type

Requirement85%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated80%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

plural
Authorization Boundaries
possessive
Authorization Boundary's
pluralpossessive
Authorization Boundaries'

Framework definitions

NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.
NIST SP 800-531 senseview framework →
§1
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.
NIST SP 800-53A1 senseview framework →
§1
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.
NIST SP 800-371 senseview framework →
§1
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.