Assignment of Components to Systems
LOW MODERATE HIGHRequirements NIST SOURCE
Requirement Context
This element is part of CM-8(9) — Assignment of Components to Systems. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CM-8(9) — Assignment of Components to Systems. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
System components that are not assigned to a system may be unmanaged, lack the required protection, and become an organizational vulnerability.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CM-8(9) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- personnel or roles from which to receive an acknowledgement is/are defined;
- system components are assigned to a system;
- an acknowledgement of the component assignment is received from <CM-08(09)_ODP personnel or roles>.
Examine
[SELECT FROM: Configuration management policy; procedures addressing system component inventory; configuration management plan; system security plan; system design documentation; system component inventory; change control records; acknowledgements of system component assignments; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with component inventory management responsibilities; system owner; organizational personnel with information security responsibilities; system/network administrators].
Test
[SELECT FROM: Organizational processes for assigning components to systems; organizational processes for acknowledging assignment of components to systems; mechanisms implementing assignment of components to the system; mechanisms implementing acknowledgment of assignment of components to the system].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CM-8(9). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- system security plan
Configuration
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system component inventory
Testing
- Organizational processes for assigning components to systems
- organizational processes for acknowledging assignment of components to systems
- mechanisms implementing assignment of components to the system
- mechanisms implementing acknowledgment of assignment of components to the system
Other Records
- change control records
- acknowledgements of system component assignments
- other relevant documents or records