Frameworks / NIST SP 800-53 Rev 5 / NIST800-CM-8 NIST SP 800-53 Rev 5
CM - Configuration Management
NIST SP 800-53 Rev 5 NIST800-CM-8: CM-8 System Component Inventory a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 104 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.3 1.2.3 Accurate network diagram of CDE connections 1.2.5 1.2.5 Allowed services, protocols and ports justified 11.2.2 11.2.2 Inventory of authorized wireless access points 12.2.1 12.2.1 Rules for acceptable use of end-user technology 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.3.4 12.3.4 Annual review of hardware and software technologies 12.5.1 12.5.1 Inventory of in-scope system components 12.8.1 12.8.1 List of third-party service providers 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates 9.4.5 9.4.5 Inventory logs of electronic media 9.5.1.1 9.5.1.1 Current register of POI devices 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware 6.3.2 6.3.2 Inventory of bespoke software and components CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory CIS-1.2 Address Unauthorized Assets CIS-1.3 Utilize an Active Discovery Tool CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory CIS-1.5 Use a Passive Asset Discovery Tool CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-2.1 Establish and Maintain a Software Inventory CIS-2.2 Ensure Authorized Software is Currently Supported CIS-2.4 Utilize Automated Software Inventory Tools CIS-4.6 Securely Manage Enterprise Assets and Software CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems CM-2(3) Retention of Previous Configurations CM-8 System Component Inventory CM-8(1) Updates During Installation and Removal CM-8(3) Automated Unauthorized Component Detection CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8)) SA-22 Unsupported System Components (SA-22) SA-4(10) Use of Approved PIV Products CM-2(3) Retention of Previous Configurations CM-8 System Component Inventory CM-8(1) Updates During Installation and Removal CM-8(3) Automated Unauthorized Component Detection CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8)) SA-22 Unsupported System Components (SA-22) SA-4(10) Use of Approved PIV Products 5.5.5 Documented information 6.5 Asset management 6.5.1 Responsibility for assets 6.5.2 Information classification 6.8.2 Equipment 6.9.1 Operational procedures and responsibilities NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk 7.5 Documented information A.4.2 Resource documentation A.4.4 Tooling resources A.4.5 System and computing resources AM-3 Ensure security of asset lifecycle management ASBv3-AM-1 Track asset inventory and their risks DS-2 Ensure software supply chain security 3.4.1e Authoritative Source for Software and Firmware 3.4.2e Automated Detection and Remediation of Unauthorized Software 3.4.3e Automated Inventory of System Components ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ADMF-3.1 Identify and understand organisational data ADMF-3.2 Maintain a data inventory AUCDR-IS-3 Securely manage information assets over their lifecycle AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment 5.9 Inventory of information and other associated assets 8.6 Capacity management SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure E8-PATCHOS-ML1 Patch Operating Systems (ML1) API1164-04 Asset Inventory CPS230-P25 Information and Technology Capability and Asset Health AESCSF-ACM-1 Asset inventory ZTMM-DEV-SCRM Devices Pillar: Asset and Supply Chain Risk Management 5.9 Inventory of information and other associated assets Art.21.2.i Human resources security, access control policies and asset management CM-8 CM-8 System Component Inventory CM-8 CM-8 System Component Inventory CM-8 CM-8 System Component Inventory Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CM - Configuration Management You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-CM-8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.