03.04.10: System Component Inventory
Control Familly: Configuration Management
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-124 [28]
SP 800-128 [41]
IR 8011-2 [42]
IR 8011-3 [43]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.04.10
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
CM-08
CM-08(01)
a. Develop and document an inventory of system components.
b. Review and update the system component inventory [Assignment: organizationdefined frequency].
c. Update the system component inventory as part of installations, removals, and system updates.
Discussion:
System components are discrete, identifiable assets (i.e., hardware, software, and firmware elements) that compose a system. Organizations may implement centralized system component inventories that include components from all systems. In such situations, organizations ensure that the inventories include the system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, software license information, hardware inventory specifications, and — for networked components — the machine names and network addresses for all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include component type, physical location, date of receipt, manufacturer, cost, model, serial number, and supplier information.
Assessment Methods and Objectives
Examine [SELECT FROM: configuration management policy and procedures; procedures for system component inventory; configuration management plan; system design documentation; system component inventory; inventory reviews and update records; component installation records; change control records; component removal records; system change records; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with component inventory management responsibilities; personnel with information security responsibilities; system administrators]
Test [SELECT FROM: processes for managing the system component inventory; mechanisms for supporting or implementing the system component inventory; processes for updating the system component inventory; mechanisms for supporting or implementing the system component inventory updates]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.04.10.ODP[01]: the frequency at which to review and update the system component inventory is defined.
A.03.04.10.a: an inventory of system components is developed and documented.
A.03.04.10.b[01]: the system component inventory is reviewed <A.03.04.10.ODP[01]: frequency>.
A.03.04.10.b[02]: the system component inventory is updated <A.03.04.10.ODP[01]: frequency>.
A.03.04.10.c[01]: the system component inventory is updated as part of component installations.
A.03.04.10.c[02]: the system component inventory is updated as part of component removals.
A.03.04.10.c[03]: the system component inventory is updated as part of system updates.