NIST SP 800-53 Rev 5 LOW CM-8: System Component Inventory
Develop and document inventory of system components; review and update at least monthly (FedRAMP).
What else in your programme already covers this
This control maps to 48 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.2.3 Any system components that are not at risk for malware are evaluated periodically to include the following: • A documented list of all system components not at risk for malware. • Identification and evaluation
6.3.2 An inventory of bespoke and custom software, and third-party software components incorporated into bespoke and custom software is maintained to facilitate vulnerability and patch management
NIST800-SR-4 Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined]