Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CM-12 — Information Location

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

1Enhancements
1Parameters
2Baseline memberships
3Assessment methods

CM — Configuration Management · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

  1. a.Identify and document the location of [Organization-defined: information] and the specific system components on which the information is processed and stored;
  2. b.Identify and document the users who have access to the system and system components where the information is processed and stored; and
  3. c.Document changes to the location (i.e., system or system components) where the information is processed and stored.
Official NIST discussion

Discussion

Information location addresses the need to understand where information is being processed and stored. Information location includes identifying where specific information types and information reside in system components and how information is being processed so that information flow can be understood and adequate protection and policy management provided for such information and system components. The security category of the information is also a factor in determining the controls necessary to protect the information and the system component where the information resides (see [FIPS 199](#628d22a1-6a11-4784-bc59-5cd9497b5445) ). The location of the information and system components is also a factor in the architecture and design of the system (see [SA-4](#sa-4), [SA-8](#sa-8), [SA-17](#sa-17)).

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

informationinformation for which the location is to be identified and documented is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Information Location as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • approved baseline configurations
  • change tickets and approvals
  • configuration scans and drift reports
  • software and hardware inventories

Common failure patterns

  • baselines documented but not enforced
  • emergency changes never reconciled
  • asset inventories that omit cloud or ephemeral resources
  • security-impact analysis performed after deployment

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CM-12a.
    1. CM-12a.[01]the location of [Organization-defined: information] is identified and documented;
    2. CM-12a.[02]the specific system components on which [Organization-defined: information] is processed are identified and documented;
    3. CM-12a.[03]the specific system components on which [Organization-defined: information] is stored are identified and documented;
  2. CM-12b.
    1. CM-12b.[01]the users who have access to the system and system components where [Organization-defined: information] is processed are identified and documented;
    2. CM-12b.[02]the users who have access to the system and system components where [Organization-defined: information] is stored are identified and documented;
  3. CM-12c.
    1. CM-12c.[01]changes to the location (i.e., system or system components) where [Organization-defined: information] is processed are documented;
    2. CM-12c.[02]changes to the location (i.e., system or system components) where [Organization-defined: information] is stored are documented.

Examine

  • Configuration management policy
  • procedures addressing identification and documentation of information location
  • configuration management plan
  • system design documentation
  • system architecture documentation
  • PII inventory documentation
  • data mapping documentation
  • audit records
  • list of users with system and system component access
  • change control records
  • system component inventory
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for managing information location and user access to information
  • organizational personnel with responsibilities for operating, using, and/or maintaining the system
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators
  • system developers

Test

  • Organizational processes governing information location
  • mechanisms enforcing policies and methods for governing information location
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CM-12(1) — Automated Tools to Support Information Location

ModerateHigh

Use automated tools to identify [Organization-defined: information by information type] on [Organization-defined: system components] to ensure controls are in place to protect organizational information and individual privacy.

Official discussion

The use of automated tools helps to increase the effectiveness and efficiency of the information location capability implemented within the system. Automation also helps organizations manage the data produced during information location activities and share such information across the organization. The output of automated information location tools can be used to guide and inform system architecture and design decisions.

Organization-defined parameters (2)
information by information typeinformation to be protected is defined by information type;
system componentssystem components where the information is located are defined;
Assessment objectives and methods

automated tools are used to identify [Organization-defined: information by information type] on [Organization-defined: system components] to ensure that controls are in place to protect organizational information and individual privacy.

Examine

  • Configuration management policy
  • procedures addressing identification and documentation of information location
  • configuration management plan
  • system design documentation
  • PII inventory documentation
  • data mapping documentation
  • change control records
  • system component inventory
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for managing information location
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers

Test

  • Organizational processes governing information location
  • automated mechanisms enforcing policies and methods for governing information location
  • automated tools used to identify information on system components
Source record

Authoritative sources