Control statement
- a.Develop and document an inventory of system components that:
- 1.Accurately reflects the system;
- 2.Includes all components within the system;
- 3.Does not include duplicate accounting of components or components assigned to any other system;
- 4.Is at the level of granularity deemed necessary for tracking and reporting; and
- 5.Includes the following information to achieve system component accountability: [Organization-defined: information] ; and
- b.Review and update the system component inventory [Organization-defined: frequency].
Discussion
System components are discrete, identifiable information technology assets that include hardware, software, and firmware. Organizations may choose to implement centralized system component inventories that include components from all organizational systems. In such situations, organizations ensure that the inventories include system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, hardware inventory specifications, software license information, and for networked components, the machine names and network addresses across all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include date of receipt, cost, model, serial number, manufacturer, supplier information, component type, and physical location. Preventing duplicate accounting of system components addresses the lack of accountability that occurs when component ownership and system association is not known, especially in large or complex connected systems. Effective prevention of duplicate accounting of system components necessitates use of a unique identifier for each component. For software inventory, centrally managed software that is accessed via other systems is addressed as a component of the system on which it is installed and managed. Software installed on multiple organizational systems and managed at the system level is addressed for each individual system and may appear more than once in a centralized component inventory, necessitating a system association for each software instance in the centralized inventory to avoid duplicate accounting of components. Scanning systems implementing multiple network protocols (e.g., IPv4 and IPv6) can result in duplicate components being identified in different address spaces. The implementation of [CM-8(7)](#cm-8.7) can help to eliminate duplicate accounting of components.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use System Component Inventory as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- approved baseline configurations
- change tickets and approvals
- configuration scans and drift reports
- software and hardware inventories
Common failure patterns
- baselines documented but not enforced
- emergency changes never reconciled
- asset inventories that omit cloud or ephemeral resources
- security-impact analysis performed after deployment
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CM-08a.
- CM-08a.01an inventory of system components that accurately reflects the system is developed and documented;
- CM-08a.02an inventory of system components that includes all components within the system is developed and documented;
- CM-08a.03an inventory of system components that does not include duplicate accounting of components or components assigned to any other system is developed and documented;
- CM-08a.04an inventory of system components that is at the level of granularity deemed necessary for tracking and reporting is developed and documented;
- CM-08a.05an inventory of system components that includes [Organization-defined: information] is developed and documented;
- CM-08b.the system component inventory is reviewed and updated [Organization-defined: frequency].
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system security plan
- system design documentation
- system component inventory
- inventory reviews and update records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing the system component inventory
- mechanisms supporting and/or implementing system component inventory
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CM-8(1) — Updates During Installation and Removal
Update the inventory of system components as part of component installations, removals, and system updates.
Official discussion
Organizations can improve the accuracy, completeness, and consistency of system component inventories if the inventories are updated as part of component installations or removals or during general system updates. If inventories are not updated at these key times, there is a greater likelihood that the information will not be appropriately captured and documented. System updates include hardware, software, and firmware components.
Assessment objectives and methods
- CM-08(01)[01]the inventory of system components is updated as part of component installations;
- CM-08(01)[02]the inventory of system components is updated as part of component removals;
- CM-08(01)[03]the inventory of system components is updated as part of system updates.
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system security plan
- system component inventory
- inventory reviews and update records
- change control records
- component installation records
- component removal records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory updating responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for updating the system component inventory
- mechanisms supporting and/or implementing system component inventory updates
Related controls
CM-8(2) — Automated Maintenance
Maintain the currency, completeness, accuracy, and availability of the inventory of system components using [Organization-defined: organization-defined automated mechanisms].
Official discussion
Organizations maintain system inventories to the extent feasible. For example, virtual machines can be difficult to monitor because such machines are not visible to the network when not in use. In such cases, organizations maintain as up-to-date, complete, and accurate an inventory as is deemed reasonable. Automated maintenance can be achieved by the implementation of [CM-2(2)](#cm-2.2) for organizations that combine system component inventory and baseline configuration activities.
Organization-defined parameters (5)
Assessment objectives and methods
- CM-08(02)[01][Organization-defined: automated mechanisms] are used to maintain the currency of the system component inventory;
- CM-08(02)[02][Organization-defined: automated mechanisms] are used to maintain the completeness of the system component inventory;
- CM-08(02)[03][Organization-defined: automated mechanisms] are used to maintain the accuracy of the system component inventory;
- CM-08(02)[04][Organization-defined: automated mechanisms] are used to maintain the availability of the system component inventory.
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system security plan
- system component inventory
- change control records
- system maintenance records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
Test
- Organizational processes for maintaining the system component inventory
- automated mechanisms supporting and/or implementing the system component inventory
CM-8(3) — Automated Unauthorized Component Detection
- (a)Detect the presence of unauthorized hardware, software, and firmware components within the system using [Organization-defined: organization-defined automated mechanisms] [Organization-defined: frequency] ; and
- (b)Take the following actions when unauthorized components are detected: [Organization-defined: cm-08.03_odp.05].
Official discussion
Automated unauthorized component detection is applied in addition to the monitoring for unauthorized remote connections and mobile devices. Monitoring for unauthorized system components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized components (see [CM-7(9)](#cm-7.9) ). Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organizations consider whether such mechanisms depend on the ability of the system component to support an agent or supplicant in order to be detected since some types of components do not have or cannot support agents (e.g., IoT devices, sensors). Isolation can be achieved , for example, by placing unauthorized system components in separate domains or subnets or quarantining such components. This type of component isolation is commonly referred to as "sandboxing."
Organization-defined parameters (7)
Assessment objectives and methods
- CM-08(03)(a)
- CM-08(03)(a)[01]the presence of unauthorized hardware within the system is detected using [Organization-defined: automated mechanisms] [Organization-defined: frequency];
- CM-08(03)(a)[02]the presence of unauthorized software within the system is detected using [Organization-defined: automated mechanisms] [Organization-defined: frequency];
- CM-08(03)(a)[03]the presence of unauthorized firmware within the system is detected using [Organization-defined: automated mechanisms] [Organization-defined: frequency];
- CM-08(03)(b)
- CM-08(03)(b)[01][Organization-defined: cm-08.03_odp.05] are taken when unauthorized hardware is detected;
- CM-08(03)(b)[02][Organization-defined: cm-08.03_odp.05] are taken when unauthorized software is detected;
- CM-08(03)(b)[03][Organization-defined: cm-08.03_odp.05] are taken when unauthorized firmware is detected.
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system security plan
- system component inventory
- change control records
- alerts/notifications of unauthorized components within the system
- system monitoring records
- system maintenance records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- organizational personnel with responsibilities for managing the automated mechanisms implementing unauthorized system component detection
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
Test
- Organizational processes for detection of unauthorized system components
- organizational processes for taking action when unauthorized system components are detected
- automated mechanisms supporting and/or implementing the detection of unauthorized system components
- automated mechanisms supporting and/or implementing actions taken when unauthorized system components are detected
Related controls
CM-8(4) — Accountability Information
Include in the system component inventory information, a means for identifying by [Organization-defined: cm-08.04_odp] , individuals responsible and accountable for administering those components.
Official discussion
Identifying individuals who are responsible and accountable for administering system components ensures that the assigned components are properly administered and that organizations can contact those individuals if some action is required (e.g., when the component is determined to be the source of a breach, needs to be recalled or replaced, or needs to be relocated).
Organization-defined parameters (1)
Assessment objectives and methods
individuals responsible and accountable for administering system components are identified by [Organization-defined: cm-08.04_odp] in the system component inventory.
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system security plan
- system component inventory
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing the system component inventory
- mechanisms supporting and/or implementing the system component inventory
Related controls
CM-8(5) — No Duplicate Accounting of Components
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CM-8(6) — Assessed Configurations and Approved Deviations
Include assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.
Official discussion
Assessed configurations and approved deviations focus on configuration settings established by organizations for system components, the specific components that have been assessed to determine compliance with the required configuration settings, and any approved deviations from established configuration settings.
Assessment objectives and methods
- CM-08(06)[01]assessed component configurations are included in the system component inventory;
- CM-08(06)[02]any approved deviations to current deployed configurations are included in the system component inventory.
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system security plan
- system design documentation
- system component inventory
- system configuration settings and associated documentation
- change control records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- organizational personnel with assessment responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing the system component inventory
- mechanisms supporting and/or implementing system component inventory
CM-8(7) — Centralized Repository
Provide a centralized repository for the inventory of system components.
Official discussion
Organizations may implement centralized system component inventories that include components from all organizational systems. Centralized repositories of component inventories provide opportunities for efficiencies in accounting for organizational hardware, software, and firmware assets. Such repositories may also help organizations rapidly identify the location and responsible individuals of components that have been compromised, breached, or are otherwise in need of mitigation actions. Organizations ensure that the resulting centralized inventories include system-specific information required for proper component accountability.
Assessment objectives and methods
a centralized repository for the system component inventory is provided.
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system security plan
- system component inventory
- system configuration settings and associated documentation
- change control records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- organizational personnel with security responsibilities
Test
- Organizational processes for managing the system component inventory
- mechanisms supporting and/or implementing system component inventory
CM-8(8) — Automated Location Tracking
Support the tracking of system components by geographic location using [Organization-defined: automated mechanisms].
Official discussion
The use of automated mechanisms to track the location of system components can increase the accuracy of component inventories. Such capability may help organizations rapidly identify the location and responsible individuals of system components that have been compromised, breached, or are otherwise in need of mitigation actions. The use of tracking mechanisms can be coordinated with senior agency officials for privacy if there are implications that affect individual privacy.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: automated mechanisms] are used to support the tracking of system components by geographic location.
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system design documentation
- system component inventory
- system configuration settings and associated documentation
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- organizational personnel with information security and privacy responsibilities
- system/network administrators
- system developers
Test
- Organizational processes for managing the system component inventory
- automated mechanisms supporting and/or implementing system component inventory
- automated mechanisms supporting and/or implementing tracking of components by geographic locations
CM-8(9) — Assignment of Components to Systems
- (a)Assign system components to a system; and
- (b)Receive an acknowledgement from [Organization-defined: personnel or roles] of this assignment.
Official discussion
System components that are not assigned to a system may be unmanaged, lack the required protection, and become an organizational vulnerability.
Organization-defined parameters (1)
Assessment objectives and methods
- CM-08(09)(a)system components are assigned to a system;
- CM-08(09)(b)an acknowledgement of the component assignment is received from [Organization-defined: personnel or roles].
Examine
- Configuration management policy
- procedures addressing system component inventory
- configuration management plan
- system security plan
- system design documentation
- system component inventory
- change control records
- acknowledgements of system component assignments
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with component inventory management responsibilities
- system owner
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for assigning components to systems
- organizational processes for acknowledging assignment of components to systems
- mechanisms implementing assignment of components to the system
- mechanisms implementing acknowledgment of assignment of components to the system
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.