System Component Inventory
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
- 1.Accurately reflects the system;
- 2.Includes all components within the system;
- 3.Does not include duplicate accounting of components or components assigned to any other system;
- 4.Is at the level of granularity deemed necessary for tracking and reporting; and
- 5.Includes the following information to achieve system component accountability: [information] ; and
Requirement Context
This element is part of CM-8 — System Component Inventory. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CM-8 — System Component Inventory. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
System components are discrete, identifiable information technology assets that include hardware, software, and firmware. Organizations may choose to implement centralized system component inventories that include components from all organizational systems. In such situations, organizations ensure that the inventories include system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, hardware inventory specifications, software license information, and for networked components, the machine names and network addresses across all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include date of receipt, cost, model, serial number, manufacturer, supplier information, component type, and physical location. Preventing duplicate accounting of system components addresses the lack of accountability that occurs when component ownership and system association is not known, especially in large or complex connected systems. Effective prevention of duplicate accounting of system components necessitates use of a unique identifier for each component. For software inventory, centrally managed software that is accessed via other systems is addressed as a component of the system on which it is installed and managed. Software installed on multiple organizational systems and managed at the system level is addressed for each individual system and may appear more than once in a centralized component inventory, necessitating a system association for each software instance in the centralized inventory to avoid duplicate accounting of components. Scanning systems implementing multiple network protocols (e.g., IPv4 and IPv6) can result in duplicate components being identified in different address spaces. The implementation of CM-8(7) can help to eliminate duplicate accounting of components.
Enhancements NIST SOURCE
CM-8(1) Updates During Installation and Removal LOW ✓ MODERATE ✓ HIGH
Update the inventory of system components as part of component installations, removals, and system updates.
Discussion
Organizations can improve the accuracy, completeness, and consistency of system component inventories if the inventories are updated as part of component installations or removals or during general system updates. If inventories are not updated at these key times, there is a greater likelihood that the information will not be appropriately captured and documented. System updates include hardware, software, and firmware components.
CM-8(2) Automated Maintenance LOW MODERATE ✓ HIGH
Maintain the currency, completeness, accuracy, and availability of the inventory of system components using [organization-defined automated mechanisms].
Discussion
Organizations maintain system inventories to the extent feasible. For example, virtual machines can be difficult to monitor because such machines are not visible to the network when not in use. In such cases, organizations maintain as up-to-date, complete, and accurate an inventory as is deemed reasonable. Automated maintenance can be achieved by the implementation of CM-2(2) for organizations that combine system component inventory and baseline configuration activities.
CM-8(3) Automated Unauthorized Component Detection LOW ✓ MODERATE ✓ HIGH
- (a) Detect the presence of unauthorized hardware, software, and firmware components within the system using [organization-defined automated mechanisms][frequency] ; and
- (b) Take the following actions when unauthorized components are detected: [one of: disable network access by unauthorized components; isolate unauthorized components; notify].
Discussion
Automated unauthorized component detection is applied in addition to the monitoring for unauthorized remote connections and mobile devices. Monitoring for unauthorized system components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized components (see CM-7(9) ). Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organizations consider whether such mechanisms depend on the ability of the system component to support an agent or supplicant in order to be detected since some types of components do not have or cannot support agents (e.g., IoT devices, sensors). Isolation can be achieved , for example, by placing unauthorized system components in separate domains or subnets or quarantining such components. This type of component isolation is commonly referred to as "sandboxing."
CM-8(4) Accountability Information LOW MODERATE ✓ HIGH
Include in the system component inventory information, a means for identifying by [one of: name; position; role] , individuals responsible and accountable for administering those components.
Discussion
Identifying individuals who are responsible and accountable for administering system components ensures that the assigned components are properly administered and that organizations can contact those individuals if some action is required (e.g., when the component is determined to be the source of a breach, needs to be recalled or replaced, or needs to be relocated).
CM-8(5) No Duplicate Accounting of Components WITHDRAWN
Withdrawn. Incorporated into CM-8.
CM-8(6) Assessed Configurations and Approved Deviations LOW MODERATE HIGH
Include assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.
Discussion
Assessed configurations and approved deviations focus on configuration settings established by organizations for system components, the specific components that have been assessed to determine compliance with the required configuration settings, and any approved deviations from established configuration settings.
CM-8(7) Centralized Repository LOW MODERATE HIGH
Provide a centralized repository for the inventory of system components.
Discussion
Organizations may implement centralized system component inventories that include components from all organizational systems. Centralized repositories of component inventories provide opportunities for efficiencies in accounting for organizational hardware, software, and firmware assets. Such repositories may also help organizations rapidly identify the location and responsible individuals of components that have been compromised, breached, or are otherwise in need of mitigation actions. Organizations ensure that the resulting centralized inventories include system-specific information required for proper component accountability.
CM-8(8) Automated Location Tracking LOW MODERATE HIGH
Support the tracking of system components by geographic location using [automated mechanisms].
Discussion
The use of automated mechanisms to track the location of system components can increase the accuracy of component inventories. Such capability may help organizations rapidly identify the location and responsible individuals of system components that have been compromised, breached, or are otherwise in need of mitigation actions. The use of tracking mechanisms can be coordinated with senior agency officials for privacy if there are implications that affect individual privacy.
CM-8(9) Assignment of Components to Systems LOW MODERATE HIGH
- (a) Assign system components to a system; and
- (b) Receive an acknowledgement from [personnel or roles] of this assignment.
Discussion
System components that are not assigned to a system may be unmanaged, lack the required protection, and become an organizational vulnerability.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CM-8 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- information deemed necessary to achieve effective system component accountability is defined;
- frequency at which to review and update the system component inventory is defined;
- an inventory of system components that accurately reflects the system is developed and documented;
- an inventory of system components that includes all components within the system is developed and documented;
- an inventory of system components that does not include duplicate accounting of components or components assigned to any other system is developed and documented;
- an inventory of system components that is at the level of granularity deemed necessary for tracking and reporting is developed and documented;
- an inventory of system components that includes <CM-08_ODP[01] information> is developed and documented;
- the system component inventory is reviewed and updated <CM-08_ODP[02] frequency>.
Examine
[SELECT FROM: Configuration management policy; procedures addressing system component inventory; configuration management plan; system security plan; system design documentation; system component inventory; inventory reviews and update records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with component inventory management responsibilities; organizational personnel with information security responsibilities; system/network administrators].
Test
[SELECT FROM: Organizational processes for managing the system component inventory; mechanisms supporting and/or implementing system component inventory].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CM-8. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- system security plan
Configuration
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system component inventory
- inventory reviews and update records
Testing
- Organizational processes for managing the system component inventory
- mechanisms supporting and/or implementing system component inventory
Other Records
- other relevant documents or records