INF-003 System Component Inventory
Description
An accurate, maintained inventory of all production system components, including servers, containers, virtual machines, cloud resources and network devices, is kept. The inventory captures component type, owner, environment and version. It is reviewed and reconciled at a defined frequency. Components present in the environment but absent from the inventory are detected automatically at a defined frequency, and each detection triggers a defined action: disabling the component's network access, isolating it or notifying the named owner.
Rationale
A complete, current inventory is the foundation of vulnerability management, change control and incident response. Periodic reconciliation finds what was added between reviews, which for a cloud estate can mean weeks of exposure on a resource nobody knows about. Automated detection closes that window. Binding an action to the detection stops the finding from sitting in a report: an unknown component with an owner and a deadline is a task, while one in a monthly spreadsheet is a statistic.
Applicability (9 profiles)
Framework Mappings (9)
| DCS-07 | Assets Cataloguing and Tracking | partial |
| DCS-07 | Assets Cataloguing and Tracking | partial |
| HIPAA-164.310.d.2.iii | Accountability | informative |
| NIS2-CIR-12.4 | Asset Inventory | informative |
| CA-9 | Internal System Connections | partial |
| CM-8 | System Component Inventory | full |
| CM-8(1) | System Component Inventory | Updates During Installation and Removal | informative |
| CM-8(3) | System Component Inventory | Automated Unauthorized Component Detection | full |
| CC6.1 | Logical Access Security Software, Infrastructure, and Architectures | informative |
Evidence (3)
Asset inventory export from a CMDB or cloud-native discovery tool listing all production system components with type, owner, environment, and version.
Example: AWS Config resource inventory export, Snipe-IT or ServiceNow CMDB export, or Terraform state file listing for production environments, dated within the last review cycle
Test: Request the asset inventory export and the most recent reconciliation record. Verify: (1) the inventory includes all production component types (servers, containers, VMs, cloud resources, network devices); (2) each record has an owner, environment tag, and version; (3) inventory was reconciled against actual deployed resources within the defined review period; (4) cross-reference a sample of 10 live resources against the inventory to confirm coverage.
Completed inventory reconciliation record demonstrating the inventory was reviewed and updated within the defined frequency.
Example: Inventory reconciliation ticket or change record (e.g., Jira or ServiceNow task) showing the last reconciliation date, reviewer, and any discrepancies resolved
Test: Request the last three inventory reconciliation records. Verify: (1) reconciliations occur at or within the defined frequency; (2) discrepancies identified during reconciliation are documented and resolved; (3) the record includes the name of the person responsible for the review.
Unauthorised component detection output listing components found in the environment that are absent from the inventory, with the action taken against each.
Example: unmanaged-resource-detection-2026-08.json
Test: Request the detection output for the last 90 days. Verify: (1) detection runs at or more often than the defined frequency, (2) its scope covers every production account, cluster and network the inventory claims to cover, (3) each detection resolves to one of the defined actions recorded against it, (4) a component stood up in a controlled test is detected within the defined interval, (5) detections that turned out to be legitimate resulted in an inventory entry rather than a suppression rule alone.
Questions (3)
Is an accurate, maintained inventory of all production system components kept, capturing component type, owner, environment, and version?
The inventory should cover servers, containers, virtual machines, cloud resources, and network devices. Cloud-native discovery tools or a CMDB are the expected mechanisms.
How frequently is the production asset inventory reconciled against actual deployed resources?
Continuous or weekly automated reconciliation is preferred. Quarterly is the minimum acceptable frequency for a controlled environment.
What happens when a component is found in the environment that is not in the inventory?
Options run from the strongest response to the weakest. A detection with nothing bound to it produces a monthly list that nobody is accountable for closing. Automatic isolation suits environments where an unknown component is never legitimate.