How does cyber security architecture define a system and a system boundary, and what extra requirement does it add?
A system is a delimitable, coherent structure of several components whose parts relate to each other; the system boundary is drawn as a dashed line around the components under consideration. CSA adds the requirement that a system serves a specific purpose and is clearly delimitable both technically and organisationally.
The term comes from systems theory. A system can be broken down into subsystems as needed. Examples range from a simple single-component system through a single cloud service, multi-cloud services and hybrid mixtures to complex systems that span several clouds and on-premises components.
The added requirement is what makes the concept usable in practice. If you cannot say what a system is for, or who is organisationally responsible for what lies inside its boundary, you cannot decide what needs protecting or who has to act. Drawing the boundary is therefore the first step of any system analysis.