Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CM-8 — System Component Inventory

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

9Enhancements
2Parameters
3Baseline memberships
3Assessment methods

CM — Configuration Management · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Develop and document an inventory of system components that:
    1. 1.Accurately reflects the system;
    2. 2.Includes all components within the system;
    3. 3.Does not include duplicate accounting of components or components assigned to any other system;
    4. 4.Is at the level of granularity deemed necessary for tracking and reporting; and
    5. 5.Includes the following information to achieve system component accountability: [Organization-defined: information] ; and
  2. b.Review and update the system component inventory [Organization-defined: frequency].
Official NIST discussion

Discussion

System components are discrete, identifiable information technology assets that include hardware, software, and firmware. Organizations may choose to implement centralized system component inventories that include components from all organizational systems. In such situations, organizations ensure that the inventories include system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, hardware inventory specifications, software license information, and for networked components, the machine names and network addresses across all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include date of receipt, cost, model, serial number, manufacturer, supplier information, component type, and physical location. Preventing duplicate accounting of system components addresses the lack of accountability that occurs when component ownership and system association is not known, especially in large or complex connected systems. Effective prevention of duplicate accounting of system components necessitates use of a unique identifier for each component. For software inventory, centrally managed software that is accessed via other systems is addressed as a component of the system on which it is installed and managed. Software installed on multiple organizational systems and managed at the system level is addressed for each individual system and may appear more than once in a centralized component inventory, necessitating a system association for each software instance in the centralized inventory to avoid duplicate accounting of components. Scanning systems implementing multiple network protocols (e.g., IPv4 and IPv6) can result in duplicate components being identified in different address spaces. The implementation of [CM-8(7)](#cm-8.7) can help to eliminate duplicate accounting of components.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

informationinformation deemed necessary to achieve effective system component accountability is defined;
frequencyfrequency at which to review and update the system component inventory is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use System Component Inventory as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • approved baseline configurations
  • change tickets and approvals
  • configuration scans and drift reports
  • software and hardware inventories

Common failure patterns

  • baselines documented but not enforced
  • emergency changes never reconciled
  • asset inventories that omit cloud or ephemeral resources
  • security-impact analysis performed after deployment

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CM-08a.
    1. CM-08a.01an inventory of system components that accurately reflects the system is developed and documented;
    2. CM-08a.02an inventory of system components that includes all components within the system is developed and documented;
    3. CM-08a.03an inventory of system components that does not include duplicate accounting of components or components assigned to any other system is developed and documented;
    4. CM-08a.04an inventory of system components that is at the level of granularity deemed necessary for tracking and reporting is developed and documented;
    5. CM-08a.05an inventory of system components that includes [Organization-defined: information] is developed and documented;
  2. CM-08b.the system component inventory is reviewed and updated [Organization-defined: frequency].

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system security plan
  • system design documentation
  • system component inventory
  • inventory reviews and update records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing the system component inventory
  • mechanisms supporting and/or implementing system component inventory
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CM-8(1) — Updates During Installation and Removal

ModerateHigh

Update the inventory of system components as part of component installations, removals, and system updates.

Official discussion

Organizations can improve the accuracy, completeness, and consistency of system component inventories if the inventories are updated as part of component installations or removals or during general system updates. If inventories are not updated at these key times, there is a greater likelihood that the information will not be appropriately captured and documented. System updates include hardware, software, and firmware components.

Assessment objectives and methods
  1. CM-08(01)[01]the inventory of system components is updated as part of component installations;
  2. CM-08(01)[02]the inventory of system components is updated as part of component removals;
  3. CM-08(01)[03]the inventory of system components is updated as part of system updates.

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system security plan
  • system component inventory
  • inventory reviews and update records
  • change control records
  • component installation records
  • component removal records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory updating responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for updating the system component inventory
  • mechanisms supporting and/or implementing system component inventory updates
Related controls
Official NIST control enhancement

CM-8(2) — Automated Maintenance

High

Maintain the currency, completeness, accuracy, and availability of the inventory of system components using [Organization-defined: organization-defined automated mechanisms].

Official discussion

Organizations maintain system inventories to the extent feasible. For example, virtual machines can be difficult to monitor because such machines are not visible to the network when not in use. In such cases, organizations maintain as up-to-date, complete, and accurate an inventory as is deemed reasonable. Automated maintenance can be achieved by the implementation of [CM-2(2)](#cm-2.2) for organizations that combine system component inventory and baseline configuration activities.

Organization-defined parameters (5)
organization-defined automated mechanisms
automated mechanismsautomated mechanisms used to maintain the currency of the system component inventory are defined;
automated mechanismsautomated mechanisms used to maintain the completeness of the system component inventory are defined;
automated mechanismsautomated mechanisms used to maintain the accuracy of the system component inventory are defined;
automated mechanismsautomated mechanisms used to maintain the availability of the system component inventory are defined;
Assessment objectives and methods
  1. CM-08(02)[01][Organization-defined: automated mechanisms] are used to maintain the currency of the system component inventory;
  2. CM-08(02)[02][Organization-defined: automated mechanisms] are used to maintain the completeness of the system component inventory;
  3. CM-08(02)[03][Organization-defined: automated mechanisms] are used to maintain the accuracy of the system component inventory;
  4. CM-08(02)[04][Organization-defined: automated mechanisms] are used to maintain the availability of the system component inventory.

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system design documentation
  • system security plan
  • system component inventory
  • change control records
  • system maintenance records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers

Test

  • Organizational processes for maintaining the system component inventory
  • automated mechanisms supporting and/or implementing the system component inventory
Official NIST control enhancement

CM-8(3) — Automated Unauthorized Component Detection

ModerateHigh
  1. (a)Detect the presence of unauthorized hardware, software, and firmware components within the system using [Organization-defined: organization-defined automated mechanisms] [Organization-defined: frequency] ; and
  2. (b)Take the following actions when unauthorized components are detected: [Organization-defined: cm-08.03_odp.05].
Official discussion

Automated unauthorized component detection is applied in addition to the monitoring for unauthorized remote connections and mobile devices. Monitoring for unauthorized system components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized components (see [CM-7(9)](#cm-7.9) ). Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organizations consider whether such mechanisms depend on the ability of the system component to support an agent or supplicant in order to be detected since some types of components do not have or cannot support agents (e.g., IoT devices, sensors). Isolation can be achieved , for example, by placing unauthorized system components in separate domains or subnets or quarantining such components. This type of component isolation is commonly referred to as "sandboxing."

Organization-defined parameters (7)
organization-defined automated mechanisms
automated mechanismsautomated mechanisms used to detect the presence of unauthorized hardware within the system are defined;
automated mechanismsautomated mechanisms used to detect the presence of unauthorized software within the system are defined;
automated mechanismsautomated mechanisms used to detect the presence of unauthorized firmware within the system are defined;
frequencyfrequency at which automated mechanisms are used to detect the presence of unauthorized system components within the system is defined;
cm-08.03_odp.05
personnel or rolespersonnel or roles to be notified when unauthorized components are detected is/are defined (if selected);
Assessment objectives and methods
  1. CM-08(03)(a)
    1. CM-08(03)(a)[01]the presence of unauthorized hardware within the system is detected using [Organization-defined: automated mechanisms] [Organization-defined: frequency];
    2. CM-08(03)(a)[02]the presence of unauthorized software within the system is detected using [Organization-defined: automated mechanisms] [Organization-defined: frequency];
    3. CM-08(03)(a)[03]the presence of unauthorized firmware within the system is detected using [Organization-defined: automated mechanisms] [Organization-defined: frequency];
  2. CM-08(03)(b)
    1. CM-08(03)(b)[01][Organization-defined: cm-08.03_odp.05] are taken when unauthorized hardware is detected;
    2. CM-08(03)(b)[02][Organization-defined: cm-08.03_odp.05] are taken when unauthorized software is detected;
    3. CM-08(03)(b)[03][Organization-defined: cm-08.03_odp.05] are taken when unauthorized firmware is detected.

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system design documentation
  • system security plan
  • system component inventory
  • change control records
  • alerts/notifications of unauthorized components within the system
  • system monitoring records
  • system maintenance records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • organizational personnel with responsibilities for managing the automated mechanisms implementing unauthorized system component detection
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers

Test

  • Organizational processes for detection of unauthorized system components
  • organizational processes for taking action when unauthorized system components are detected
  • automated mechanisms supporting and/or implementing the detection of unauthorized system components
  • automated mechanisms supporting and/or implementing actions taken when unauthorized system components are detected
Related controls
Official NIST control enhancement

CM-8(4) — Accountability Information

High

Include in the system component inventory information, a means for identifying by [Organization-defined: cm-08.04_odp] , individuals responsible and accountable for administering those components.

Official discussion

Identifying individuals who are responsible and accountable for administering system components ensures that the assigned components are properly administered and that organizations can contact those individuals if some action is required (e.g., when the component is determined to be the source of a breach, needs to be recalled or replaced, or needs to be relocated).

Organization-defined parameters (1)
cm-08.04_odp
Assessment objectives and methods

individuals responsible and accountable for administering system components are identified by [Organization-defined: cm-08.04_odp] in the system component inventory.

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system security plan
  • system component inventory
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing the system component inventory
  • mechanisms supporting and/or implementing the system component inventory
Related controls
Official NIST control enhancement

CM-8(5) — No Duplicate Accounting of Components

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

CM-8(6) — Assessed Configurations and Approved Deviations

Include assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.

Official discussion

Assessed configurations and approved deviations focus on configuration settings established by organizations for system components, the specific components that have been assessed to determine compliance with the required configuration settings, and any approved deviations from established configuration settings.

Assessment objectives and methods
  1. CM-08(06)[01]assessed component configurations are included in the system component inventory;
  2. CM-08(06)[02]any approved deviations to current deployed configurations are included in the system component inventory.

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system security plan
  • system design documentation
  • system component inventory
  • system configuration settings and associated documentation
  • change control records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • organizational personnel with assessment responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing the system component inventory
  • mechanisms supporting and/or implementing system component inventory
Official NIST control enhancement

CM-8(7) — Centralized Repository

Provide a centralized repository for the inventory of system components.

Official discussion

Organizations may implement centralized system component inventories that include components from all organizational systems. Centralized repositories of component inventories provide opportunities for efficiencies in accounting for organizational hardware, software, and firmware assets. Such repositories may also help organizations rapidly identify the location and responsible individuals of components that have been compromised, breached, or are otherwise in need of mitigation actions. Organizations ensure that the resulting centralized inventories include system-specific information required for proper component accountability.

Assessment objectives and methods

a centralized repository for the system component inventory is provided.

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system design documentation
  • system security plan
  • system component inventory
  • system configuration settings and associated documentation
  • change control records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • organizational personnel with security responsibilities

Test

  • Organizational processes for managing the system component inventory
  • mechanisms supporting and/or implementing system component inventory
Official NIST control enhancement

CM-8(8) — Automated Location Tracking

Support the tracking of system components by geographic location using [Organization-defined: automated mechanisms].

Official discussion

The use of automated mechanisms to track the location of system components can increase the accuracy of component inventories. Such capability may help organizations rapidly identify the location and responsible individuals of system components that have been compromised, breached, or are otherwise in need of mitigation actions. The use of tracking mechanisms can be coordinated with senior agency officials for privacy if there are implications that affect individual privacy.

Organization-defined parameters (1)
automated mechanismsautomated mechanisms for tracking components are defined;
Assessment objectives and methods

[Organization-defined: automated mechanisms] are used to support the tracking of system components by geographic location.

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system design documentation
  • system component inventory
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators
  • system developers

Test

  • Organizational processes for managing the system component inventory
  • automated mechanisms supporting and/or implementing system component inventory
  • automated mechanisms supporting and/or implementing tracking of components by geographic locations
Official NIST control enhancement

CM-8(9) — Assignment of Components to Systems

  1. (a)Assign system components to a system; and
  2. (b)Receive an acknowledgement from [Organization-defined: personnel or roles] of this assignment.
Official discussion

System components that are not assigned to a system may be unmanaged, lack the required protection, and become an organizational vulnerability.

Organization-defined parameters (1)
personnel or rolespersonnel or roles from which to receive an acknowledgement is/are defined;
Assessment objectives and methods
  1. CM-08(09)(a)system components are assigned to a system;
  2. CM-08(09)(b)an acknowledgement of the component assignment is received from [Organization-defined: personnel or roles].

Examine

  • Configuration management policy
  • procedures addressing system component inventory
  • configuration management plan
  • system security plan
  • system design documentation
  • system component inventory
  • change control records
  • acknowledgements of system component assignments
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with component inventory management responsibilities
  • system owner
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for assigning components to systems
  • organizational processes for acknowledging assignment of components to systems
  • mechanisms implementing assignment of components to the system
  • mechanisms implementing acknowledgment of assignment of components to the system
Source record

Authoritative sources