|
controlCM-8
System Component Inventory (CM-8)
Develop and document an inventory of system components that: Review and update the system component inventory [organization-defined].
Security Baselines
LOWMODERATEHIGH
configurationbaselineschange-control
Why These Connect
Maps To8
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports34
These related controls work together — a change to one may affect the others.
Mitigates1
This control helps defend against or reduce the risk of the linked threat technique.
Enhances9
These enhancements add specific capabilities or refinements to the base control.
Related Controls(25)
CM-2Baseline Configuration (CM-2)
LMH
CM-4Impact Analyses (CM-4)LMH
CM-7Least Functionality (CM-7)LMH
CM-9Configuration Management Plan (CM-9)MH
CM-10Software Usage Restrictions (CM-10)LMH
CM-11User-installed Software (CM-11)LMH
CM-13Data Action Mapping (CM-13)CP-2Contingency Plan (CP-2)LMH
CP-9System Backup (CP-9)LMH
MA-2Controlled Maintenance (MA-2)LMH
MA-6Timely Maintenance (MA-6)MH
PE-20Asset Monitoring and Tracking (PE-20)PL-9Central Management (PL-9)PM-5System Inventory (PM-5)SA-4Acquisition Process (SA-4)LMH
SA-5System Documentation (SA-5)LMH
SI-2Flaw Remediation (SI-2)LMH
SR-4Provenance (SR-4)CM-12Information Location (CM-12)MH
PE-16Delivery and Removal (PE-16)LMH
RA-2Security Categorization (RA-2)LMH
RA-5Vulnerability Monitoring and Scanning (RA-5)LMH
SI-3Malicious Code Protection (SI-3)LMH
SI-4System Monitoring (SI-4)LMH
SI-7Software, Firmware, and Information Integrity (SI-7)MH
Threat Coverage(1 ATT&CK techniques)
Cross-Framework Mappings(8)
ID.AM-01ID.AM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-02ID.AM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule2 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
ID.AM-01ID.AM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-02ID.AM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined information
Assignmentorganization-defined frequency
Control Enhancements(9)
CM-8(1)Updates During Installation and Removal (CM-8(1))
MH
CM-8(2)Automated Maintenance (CM-8(2))H
CM-8(3)Automated Unauthorized Component Detection (CM-8(3))MH
CM-8(4)Accountability Information (CM-8(4))H
CM-8(5)No Duplicate Accounting of Components (CM-8(5))WCM-8(6)Assessed Configurations and Approved Deviations (CM-8(6))CM-8(7)Centralized Repository (CM-8(7))CM-8(8)Automated Location Tracking (CM-8(8))CM-8(9)Assignment of Components to Systems (CM-8(9))