Accreditation Boundary
Discussion
An Accreditation Boundary identifies the systems, components, services, information, interfaces, infrastructure, processes, personnel roles, and operating environments included within an Accreditation.
The boundary establishes the scope of the applicable requirements, controls, assessments, risks, and supporting Evidence. It also distinguishes included elements from external systems, services, organizations, and dependencies.
An Accreditation Boundary may contain internal subdivisions, trust boundaries, deployment environments, or responsibility boundaries. Those subdivisions remain part of the Accreditation Boundary when the accreditation includes them.
For an Accredited Software Factory, the boundary identifies the factory components and operational processes covered by the applicable Operational Approval.
Definition
defined scope of the systems, components, services, information, interfaces, infrastructure, processes, personnel roles, and operating environments included within an accreditation
Source
Generalised from security-accreditation, authorization-boundary, conformity-assessment, and risk-management usage and specialized for the Crucible architecture and operational model.
Note
An Accreditation Boundary defines the scope of an accreditation rather than a physical boundary alone. The boundary may include distributed components, external services under defined agreements, connected environments, and disconnected environments.
A dependency located outside the Accreditation Boundary may still affect the risks, controls, or evidence associated with the accredited entity.
Example
The Accreditation Boundary for a Software Factory includes source-control services, build services, hardened build workers, dependency repositories, artifact repositories, compliance services, deployment automation, administrative processes, and approved interfaces to external infrastructure providers.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.