Which document in the RMF authorization package formally describes the boundary of the information system being assessed?
-
A
System Security Plan (SSP)
-
B
Privacy Impact Assessment (PIA)
-
C
Security Assessment Report (SAR)
-
D
Plan of Action and Milestones (POA&M)