Automated Unauthorized Component Detection
LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of CM-8(3) — Automated Unauthorized Component Detection. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CM-8(3) — Automated Unauthorized Component Detection. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Automated unauthorized component detection is applied in addition to the monitoring for unauthorized remote connections and mobile devices. Monitoring for unauthorized system components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized components (see CM-7(9) ). Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organizations consider whether such mechanisms depend on the ability of the system component to support an agent or supplicant in order to be detected since some types of components do not have or cannot support agents (e.g., IoT devices, sensors). Isolation can be achieved , for example, by placing unauthorized system components in separate domains or subnets or quarantining such components. This type of component isolation is commonly referred to as "sandboxing."
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CM-8(3) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- automated mechanisms used to detect the presence of unauthorized hardware within the system are defined;
- automated mechanisms used to detect the presence of unauthorized software within the system are defined;
- automated mechanisms used to detect the presence of unauthorized firmware within the system are defined;
- frequency at which automated mechanisms are used to detect the presence of unauthorized system components within the system is defined;
- one or more of the following PARAMETER VALUES is/are selected: {disable network access by unauthorized components; isolate unauthorized components; notify <CM-08(03)_ODP[06] personnel or roles>};
- personnel or roles to be notified when unauthorized components are detected is/are defined (if selected);
- the presence of unauthorized hardware within the system is detected using <CM-08(03)_ODP[01] automated mechanisms> <CM-08(03)_ODP[04] frequency>;
- the presence of unauthorized software within the system is detected using <CM-08(03)_ODP[02] automated mechanisms> <CM-08(03)_ODP[04] frequency>;
- the presence of unauthorized firmware within the system is detected using <CM-08(03)_ODP[03] automated mechanisms> <CM-08(03)_ODP[04] frequency>;
- <CM-08(03)_ODP[05] SELECTED PARAMETER VALUES> are taken when unauthorized hardware is detected;
- <CM-08(03)_ODP[05] SELECTED PARAMETER VALUES> are taken when unauthorized software is detected;
- <CM-08(03)_ODP[05] SELECTED PARAMETER VALUES> are taken when unauthorized firmware is detected.
Examine
[SELECT FROM: Configuration management policy; procedures addressing system component inventory; configuration management plan; system design documentation; system security plan; system component inventory; change control records; alerts/notifications of unauthorized components within the system; system monitoring records; system maintenance records; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with component inventory management responsibilities; organizational personnel with responsibilities for managing the automated mechanisms implementing unauthorized system component detection; organizational personnel with information security responsibilities; system/network administrators; system developers].
Test
[SELECT FROM: Organizational processes for detection of unauthorized system components; organizational processes for taking action when unauthorized system components are detected; automated mechanisms supporting and/or implementing the detection of unauthorized system components; automated mechanisms supporting and/or implementing actions taken when unauthorized system components are detected].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CM-8(3). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- system security plan
Configuration
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system component inventory
Testing
- Organizational processes for detection of unauthorized system components
- organizational processes for taking action when unauthorized system components are detected
- automated mechanisms supporting and/or implementing the detection of unauthorized system components
- automated mechanisms supporting and/or implementing actions taken when unauthorized system components are detected
Other Records
- change control records
- alerts/notifications of unauthorized components within the system
- system monitoring records
- system maintenance records
- system audit records
- other relevant documents or records