B. Boundary + Authorization

GCC-Moderate boundary model, data classification, ATO / OSCAL, 3PAO engagement

Published

April 24, 2026

B. Boundary + Authorization

The boundary is the single most load-bearing assertion UIAO makes. Every artifact either lives inside the GCC-Moderate boundary or is explicitly marked as an out-of-scope reference. This sub-category documents the boundary model, the authorization path, and the evidence format for continuous-authorization.

Leaves

  • B.1 GCC-Moderate boundary model (MOD_U)
  • B.2 Commercial-Cloud exception (Amazon Connect)
  • B.3 Data classification (Controlled, CUI)
  • B.4 ATO package / OSCAL authoring
  • B.5 3PAO engagement flow
  • B.6 Package handoff / continuous authorization
Back to top