Control statement
- a.Identify and document the location of [Organization-defined: information] and the specific system components on which the information is processed and stored;
- b.Identify and document the users who have access to the system and system components where the information is processed and stored; and
- c.Document changes to the location (i.e., system or system components) where the information is processed and stored.
Discussion
Information location addresses the need to understand where information is being processed and stored. Information location includes identifying where specific information types and information reside in system components and how information is being processed so that information flow can be understood and adequate protection and policy management provided for such information and system components. The security category of the information is also a factor in determining the controls necessary to protect the information and the system component where the information resides (see [FIPS 199](#628d22a1-6a11-4784-bc59-5cd9497b5445) ). The location of the information and system components is also a factor in the architecture and design of the system (see [SA-4](#sa-4), [SA-8](#sa-8), [SA-17](#sa-17)).
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Information Location as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- approved baseline configurations
- change tickets and approvals
- configuration scans and drift reports
- software and hardware inventories
Common failure patterns
- baselines documented but not enforced
- emergency changes never reconciled
- asset inventories that omit cloud or ephemeral resources
- security-impact analysis performed after deployment
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CM-12a.
- CM-12a.[01]the location of [Organization-defined: information] is identified and documented;
- CM-12a.[02]the specific system components on which [Organization-defined: information] is processed are identified and documented;
- CM-12a.[03]the specific system components on which [Organization-defined: information] is stored are identified and documented;
- CM-12b.
- CM-12b.[01]the users who have access to the system and system components where [Organization-defined: information] is processed are identified and documented;
- CM-12b.[02]the users who have access to the system and system components where [Organization-defined: information] is stored are identified and documented;
- CM-12c.
- CM-12c.[01]changes to the location (i.e., system or system components) where [Organization-defined: information] is processed are documented;
- CM-12c.[02]changes to the location (i.e., system or system components) where [Organization-defined: information] is stored are documented.
Examine
- Configuration management policy
- procedures addressing identification and documentation of information location
- configuration management plan
- system design documentation
- system architecture documentation
- PII inventory documentation
- data mapping documentation
- audit records
- list of users with system and system component access
- change control records
- system component inventory
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with responsibilities for managing information location and user access to information
- organizational personnel with responsibilities for operating, using, and/or maintaining the system
- organizational personnel with information security and privacy responsibilities
- system/network administrators
- system developers
Test
- Organizational processes governing information location
- mechanisms enforcing policies and methods for governing information location
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CM-12(1) — Automated Tools to Support Information Location
Use automated tools to identify [Organization-defined: information by information type] on [Organization-defined: system components] to ensure controls are in place to protect organizational information and individual privacy.
Official discussion
The use of automated tools helps to increase the effectiveness and efficiency of the information location capability implemented within the system. Automation also helps organizations manage the data produced during information location activities and share such information across the organization. The output of automated information location tools can be used to guide and inform system architecture and design decisions.
Organization-defined parameters (2)
Assessment objectives and methods
automated tools are used to identify [Organization-defined: information by information type] on [Organization-defined: system components] to ensure that controls are in place to protect organizational information and individual privacy.
Examine
- Configuration management policy
- procedures addressing identification and documentation of information location
- configuration management plan
- system design documentation
- PII inventory documentation
- data mapping documentation
- change control records
- system component inventory
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with responsibilities for managing information location
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
Test
- Organizational processes governing information location
- automated mechanisms enforcing policies and methods for governing information location
- automated tools used to identify information on system components
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.