Skip to main content

πŸ’Ό CM-8 System Component Inventory (L)(M)(H)

  • Contextual name: πŸ’Ό CM-8 System Component Inventory (L)(M)(H)
  • ID: /frameworks/fedramp-high-security-controls/cm/08
  • Located in: πŸ’Ό Configuration Management

Description​

a. Develop and document an inventory of system components that:

  1. Accurately reflects the system;

  2. Includes all components within the system;

  3. Does not include duplicate accounting of components or components assigned to any other system;

  4. Is at the level of granularity deemed necessary for tracking and reporting; and

  5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and

b. Review and update the system component inventory [FedRAMP Assignment: at least monthly].

CM-8 Additional FedRAMP Requirements and Guidance:

Requirement: must be provided at least monthly or when there is a change.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/cm/08
  • Internal
    • ID: dec-c-522d70ef

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-8 System Component Inventory91

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό CM-8 System Component Inventory (L)(M)(H)1
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό CM-8 System Component Inventory (L)(M)(H)21

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CM-8(1) Updates During Installation and Removal (M)(H)
πŸ’Ό CM-8(2) Automated Maintenance (H)1
πŸ’Ό CM-8(3) Automated Unauthorized Component Detection (M)(H)
πŸ’Ό CM-8(4) Accountability Information (H)

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS Account Config is not enabled in all regions 🟒1🟒 x6