NIST SP 800-53 Rev 5
CM - Configuration Management

NIST SP 800-53 Rev 5 NIST800-CM-8: CM-8 System Component Inventory

a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 104 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 13 controls

  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 11.2.2 11.2.2 Inventory of authorized wireless access points
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 12.8.1 12.8.1 List of third-party service providers
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 9.4.5 9.4.5 Inventory logs of electronic media
  • 9.5.1.1 9.5.1.1 Current register of POI devices
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 6.3.2 6.3.2 Inventory of bespoke software and components

CIS Controls v8 · 12 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-1.2 Address Unauthorized Assets
  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.4 Utilize Automated Software Inventory Tools
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems

FedRAMP High · 7 controls

  • CM-2(3) Retention of Previous Configurations
  • CM-8 System Component Inventory
  • CM-8(1) Updates During Installation and Removal
  • CM-8(3) Automated Unauthorized Component Detection
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • SA-22 Unsupported System Components (SA-22)
  • SA-4(10) Use of Approved PIV Products

FedRAMP Moderate · 7 controls

  • CM-2(3) Retention of Previous Configurations
  • CM-8 System Component Inventory
  • CM-8(1) Updates During Installation and Removal
  • CM-8(3) Automated Unauthorized Component Detection
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • SA-22 Unsupported System Components (SA-22)
  • SA-4(10) Use of Approved PIV Products

ISO 27701:2019 · 6 controls

  • 5.5.5 Documented information
  • 6.5 Asset management
  • 6.5.1 Responsibility for assets
  • 6.5.2 Information classification
  • 6.8.2 Equipment
  • 6.9.1 Operational procedures and responsibilities
  • NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

ISO/IEC 42001:2023 · 4 controls

  • 7.5 Documented information
  • A.4.2 Resource documentation
  • A.4.4 Tooling resources
  • A.4.5 System and computing resources
  • AM-3 Ensure security of asset lifecycle management
  • ASBv3-AM-1 Track asset inventory and their risks
  • DS-2 Ensure software supply chain security

NIST SP 800-172 · 3 controls

  • 3.4.1e Authoritative Source for Software and Firmware
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software
  • 3.4.3e Automated Inventory of System Components
  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram
  • ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment
  • ADMF-3.1 Identify and understand organisational data
  • ADMF-3.2 Maintain a data inventory
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment

ISO 27001:2022 · 2 controls

  • 5.9 Inventory of information and other associated assets
  • 8.6 Capacity management

NIST SP 800-128 · 2 controls

NIST SP 800-207 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)

API 1164 · 1 control

  • API1164-04 Asset Inventory
  • CPS230-P25 Information and Technology Capability and Asset Health

APRA CPS 234 · 1 control

  • AESCSF-ACM-1 Asset inventory

C5 (Germany) · 1 control

  • ZTMM-DEV-SCRM Devices Pillar: Asset and Supply Chain Risk Management

CMMC 2.0 · 1 control

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 27002:2022 · 1 control

  • 5.9 Inventory of information and other associated assets

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-183 · 1 control

NIST SP 800-218 · 1 control

  • CM-8 CM-8 System Component Inventory
  • CM-8 CM-8 System Component Inventory
  • CM-8 CM-8 System Component Inventory

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CM - Configuration Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CM-8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.