9.3 Boundary Definition, Data Flow Diagrams & Secure Enclave Isolation
Key Takeaways
- The CMMC Assessment Scope is the set of OSA assets assessed against CMMC requirements; scope follows CUI handling, security capabilities, asset categories, and provider rules rather than a marketing label such as enclave.
- For in-scope Level 2 asset categories, §170.19 requires inventory, SSP treatment, and network-diagram documentation; data-flow documentation is highly useful but no single DFD notation or mandatory diagram field list exists.
- An enclave can reduce scope only when actual capabilities, connections, identities, providers, physical paths, and transfer channels support the proposed asset categories.
- Out-of-Scope Assets require inability to handle CUI, no security-protection role, and physical or logical separation; CRMAs use different criteria and do not require separation.
- CCA teams select adequate Examine, Interview, and Test evidence for boundaries; no universal NGFW, ZTNA, VDI, session-recording, or live-transaction test is mandated.
Assessment Boundaries, Data Flows & Enclaves
32 CFR §170.19 defines the CMMC Assessment Scope as the set of OSA assets assessed against CMMC requirements. Practitioners often say “CUI boundary” or “enclave,” but those labels do not replace the regulatory asset categories and provider rules. Scope follows what systems and services can do, what information they handle, and what security capabilities they provide.
Build the scope from facts
Start with contracts and information flows. Identify CUI creation, receipt, processing, storage, transmission, output, backup, archive, and destruction. Then include identities, facilities, technologies, physical media, cloud services, non-cloud ESP services, and protection dependencies.
At Level 2, CUI Assets, SPAs, CRMAs, and Specialized Assets are in scope with different assessment treatment. Out-of-Scope Assets are not. A device is not outside scope simply because CUI is encrypted when crossing it or because a diagram draws it beyond a line.
Required and useful documentation
For the four in-scope Level 2 categories, §170.19 requires documentation in the asset inventory, SSP, and network diagram, with the exact treatment varying by category. These artifacts should reconcile: names or groupings, sites, networks, service providers, trust paths, asset treatment, and scope identifiers cannot contradict each other.
A data-flow diagram or linked data-flow record is extremely useful for showing how CUI and SPD move. CAP and the scoping rule do not require one universal DFD notation, five-stage picture, protocol label on every arrow, or CMVP certificate number on the diagram. Put detail where it can be maintained and traced—diagram, flow register, CRM, SSP, inventory, or evidence index.
Useful flow questions include:
- Where does CUI enter and who can initiate the flow?
- Which endpoints, applications, printers, backups, and physical media can receive it?
- Which identity, DNS, logging, security, or management services protect the path?
- Which CSPs or non-cloud ESPs process CUI or SPD on provider assets?
- Which output, subcontractor, support, archive, and disposal paths exist?
- Which technical channel or procedure prevents CUI from entering an asset claimed as CRMA or out of scope?
Enclaves and segmentation
An enclave is an architecture that concentrates a workflow and its security dependencies. It can reduce assessment scope, but only when the resulting categories are supported. Firewalls, VLANs, separate identity, virtual desktops, physical rooms, gateways, and transfer controls are possible mechanisms—not universal CMMC mandates.
An isolated VLAN is not evidence of separation if unrestricted routing bypasses the control. A separate directory can still depend on an out-of-scope administrator or provider. A cloud product name does not establish FedRAMP status or a customer’s configuration. A locked room does not control remote and backup paths.
Do not impose out-of-scope criteria on CRMAs. A CRMA can but is not intended to handle CUI due to documented risk-based practices, and the rule says separation is not required. An Out-of-Scope Asset, by contrast, cannot handle CUI, provides no protection for CUI Assets, and is physically or logically separated.
VDI analysis
Section 170.19 gives a specific out-of-scope example: an endpoint hosting a VDI client that cannot process, store, or transmit CUI beyond keyboard, video, and mouse interaction. The team evaluates clipboard, local-drive and device redirection, download, cache, print, screenshots or capture, browser integration, offline mode, administrative access, and other actual channels.
VDI does not automatically make an endpoint out of scope. Nor does a thin-client label. The configured and tested capability decides. If local storage or printing receives CUI, categorize the endpoint and downstream device from those facts.
Provider paths
A CSP handling CUI follows the FedRAMP Authorized Moderate-or-higher or current equivalency route, and the OSC demonstrates CRM responsibilities. A non-cloud ESP handling CUI has its services assessed within the OSA’s scope. A provider handling SPD without CUI is assessed as a Security Protection Asset. Provider consoles, support workstations, ticketing, log storage, backups, and identities can change the scope.
Boundary evidence
A qualified CCA team can examine diagrams, inventories, SSP content, CRM data, rules, routes, configurations, facility controls, and records; interview designers, administrators, users, and provider personnel; and test representative allowed or denied flows. Focused sampling is nonstatistical and selected for the objective and scope.
No universal rule demands a live end-to-end transaction, packet capture, full session video, NGFW, ZTNA, or a particular port. The method must produce adequate and sufficient evidence without unsafe or unauthorized activity.
Scenario method
- Trace the information and SPD through the whole life cycle.
- Reconcile inventory, SSP, network diagram, data flows, CRM, sites, and providers.
- Categorize every relevant asset under §170.19.
- Test claimed separation and no-CUI paths with appropriate evidence.
- Expand or correct scope when an undisclosed path changes capability.
If an undocumented off-site backup contains CUI, the service and connecting path must be categorized under current provider rules; the team does not hide the discrepancy by deleting a script. If unrestricted routing connects corporate endpoints to a CUI database, the proposed out-of-scope claim is unsupported. Scope is an evidence conclusion.
Which evidence best supports an out-of-scope claim for a VDI client endpoint?
An undocumented non-cloud backup service stores CUI. What should the team do?
Which statement distinguishes CRMA from Out-of-Scope Assets?