Centralized Repository
LOW MODERATE HIGHRequirements NIST SOURCE
Provide a centralized repository for the inventory of system components.
Discussion (NIST Supplemental Guidance)
Organizations may implement centralized system component inventories that include components from all organizational systems. Centralized repositories of component inventories provide opportunities for efficiencies in accounting for organizational hardware, software, and firmware assets. Such repositories may also help organizations rapidly identify the location and responsible individuals of components that have been compromised, breached, or are otherwise in need of mitigation actions. Organizations ensure that the resulting centralized inventories include system-specific information required for proper component accountability.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CM-8(7) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- a centralized repository for the system component inventory is provided.
Examine
[SELECT FROM: Configuration management policy; procedures addressing system component inventory; configuration management plan; system design documentation; system security plan; system component inventory; system configuration settings and associated documentation; change control records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with component inventory management responsibilities; organizational personnel with security responsibilities; ].
Test
[SELECT FROM: Organizational processes for managing the system component inventory; mechanisms supporting and/or implementing system component inventory].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CM-8(7). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- system security plan
Configuration
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system component inventory
- system configuration settings and associated documentation
Testing
- Organizational processes for managing the system component inventory
- mechanisms supporting and/or implementing system component inventory
Other Records
- change control records
- other relevant documents or records