GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INF-003 System Component Inventory

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

An accurate, maintained inventory of all production system components, including servers, containers, virtual machines, cloud resources and network devices, is kept. The inventory captures component type, owner, environment and version. It is reviewed and reconciled at a defined frequency. Components present in the environment but absent from the inventory are detected automatically at a defined frequency, and each detection triggers a defined action: disabling the component's network access, isolating it or notifying the named owner.

Rationale

A complete, current inventory is the foundation of vulnerability management, change control and incident response. Periodic reconciliation finds what was added between reviews, which for a cloud estate can mean weeks of exposure on a resource nobody knows about. Automated detection closes that window. Binding an action to the detection stops the finding from sitting in a report: an unknown component with an owner and a deadline is a task, while one in a monthly spreadsheet is a statistic.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (9)

DCS-07Assets Cataloguing and Trackingpartial
DCS-07Assets Cataloguing and Trackingpartial
HIPAA-164.310.d.2.iiiAccountabilityinformative
NIS2-CIR-12.4Asset Inventoryinformative
CA-9Internal System Connectionspartial
CM-8System Component Inventoryfull
CM-8(1)System Component Inventory | Updates During Installation and Removalinformative
CM-8(3)System Component Inventory | Automated Unauthorized Component Detectionfull
CC6.1Logical Access Security Software, Infrastructure, and Architecturesinformative

Evidence (3)

tool_outputtechnicalautomated

Asset inventory export from a CMDB or cloud-native discovery tool listing all production system components with type, owner, environment, and version.

Example: AWS Config resource inventory export, Snipe-IT or ServiceNow CMDB export, or Terraform state file listing for production environments, dated within the last review cycle

Test: Request the asset inventory export and the most recent reconciliation record. Verify: (1) the inventory includes all production component types (servers, containers, VMs, cloud resources, network devices); (2) each record has an owner, environment tag, and version; (3) inventory was reconciled against actual deployed resources within the defined review period; (4) cross-reference a sample of 10 live resources against the inventory to confirm coverage.

recorddocumentmanual

Completed inventory reconciliation record demonstrating the inventory was reviewed and updated within the defined frequency.

Example: Inventory reconciliation ticket or change record (e.g., Jira or ServiceNow task) showing the last reconciliation date, reviewer, and any discrepancies resolved

Test: Request the last three inventory reconciliation records. Verify: (1) reconciliations occur at or within the defined frequency; (2) discrepancies identified during reconciliation are documented and resolved; (3) the record includes the name of the person responsible for the review.

tool_outputtechnicalautomated

Unauthorised component detection output listing components found in the environment that are absent from the inventory, with the action taken against each.

Example: unmanaged-resource-detection-2026-08.json

Test: Request the detection output for the last 90 days. Verify: (1) detection runs at or more often than the defined frequency, (2) its scope covers every production account, cluster and network the inventory claims to cover, (3) each detection resolves to one of the defined actions recorded against it, (4) a component stood up in a controlled test is detected within the defined interval, (5) detections that turned out to be legitimate resulted in an inventory entry rather than a suppression rule alone.

Questions (3)

boolean

Is an accurate, maintained inventory of all production system components kept, capturing component type, owner, environment, and version?

The inventory should cover servers, containers, virtual machines, cloud resources, and network devices. Cloud-native discovery tools or a CMDB are the expected mechanisms.

select

How frequently is the production asset inventory reconciled against actual deployed resources?

Continuously: automated discovery feeds the inventory in real timeWeekly or more frequently via scheduled scan or pipeline outputMonthlyQuarterlyLess frequently than quarterly or on an ad hoc basis

Continuous or weekly automated reconciliation is preferred. Quarterly is the minimum acceptable frequency for a controlled environment.

multi

What happens when a component is found in the environment that is not in the inventory?

Its network access is disabled automaticallyIt is isolated automaticallyThe named owner is notified automaticallyA ticket is raised and tracked to closureIt is picked up only by the periodic reconciliationNone of the above

Options run from the strongest response to the weakest. A detection with nothing bound to it produces a monthly list that nobody is accountable for closing. Automatic isolation suits environments where an unknown component is never legitimate.