Skip to main content

💼 CM-8 System Component Inventory

  • ID: /frameworks/nist-sp-800-53-r5/cm/08

Description

a. Develop and document an inventory of system components that:

  1. Accurately reflects the system;
  2. Includes all components within the system;
  3. Does not include duplicate accounting of components or components assigned to any other system;
  4. Is at the level of granularity deemed necessary for tracking and reporting; and
  5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].

Similar

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/config/01
    • /frameworks/aws-fsbp-v1.0.0/fsx/02
    • /frameworks/aws-fsbp-v1.0.0/service-catalog/01
    • /frameworks/aws-fsbp-v1.0.0/ssm/01
    • /frameworks/aws-fsbp-v1.0.0/ssm/03
  • Internal
    • ID: dec-c-cc75dbf4

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [Config.1] AWS Config should be enabled and use the service-linked role for resource recording1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [FSx.2] FSx for Lustre file systems should be configured to copy tags to backupsno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [ServiceCatalog.1] Service Catalog portfolios should be shared within an AWS organization onlyno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [SSM.1] Amazon EC2 instances should be managed by AWS Systems Managerno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [SSM.3] Amazon EC2 instances managed by Systems Manager should have an association compliance status of COMPLIANTno data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 FedRAMP High Security Controls → 💼 CM-8 System Component Inventory (L)(M)(H)45no data
💼 FedRAMP Low Security Controls → 💼 CM-8 System Component Inventory (L)(M)(H)2no data
💼 NIST CSF v2.0 → 💼 ID.AM-01: Inventories of hardware managed by the organization are maintained4no data
💼 NIST CSF v2.0 → 💼 ID.AM-02: Inventories of software, services, and systems managed by the organization are maintained9no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CM-8(1) System Component Inventory _ Updates During Installation and Removal2no data
💼 CM-8(2) System Component Inventory _ Automated Maintenance1no data
💼 CM-8(3) System Component Inventory _ Automated Unauthorized Component Detection1no data
💼 CM-8(4) System Component Inventory _ Accountability Informationno data
💼 CM-8(5) System Component Inventory _ No Duplicate Accounting of Componentsno data
💼 CM-8(6) System Component Inventory _ Assessed Configurations and Approved Deviationsno data
💼 CM-8(7) System Component Inventory _ Centralized Repositoryno data
💼 CM-8(8) System Component Inventory _ Automated Location Trackingno data
💼 CM-8(9) System Component Inventory _ Assignment of Components to Systemsno data

Policies (2)

PolicyLogic CountFlagsCompliance
🛡️ AWS Account Config is not enabled in all regions🟢1🟢 x6no data
🛡️ Google Cloud Asset Inventory API is not enabled🟢1🟢 x6no data