PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CM-8 — System Component Inventory

Framework: NIST SP 800-53 Rev.5 CM-8 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Verify a documented inventory of system components exists at the defined granularity, capturing required attributes such as component type, hardware/software identity, network address, physical/logical location, and assigned owner.
Test Reconcile the inventory against an independent active/passive discovery scan to confirm accuracy and completeness (CIS Controls 1 and 2).
Test Perform a two-way sample test: trace live assets on the network to inventory records and trace inventory records to real assets, confirming no missing or duplicate-accounted components.
Interview Ask how the inventory is updated during component installation, removal, and update, and confirm the process is consistently followed.
Examine Confirm the inventory is reviewed and updated at the organization-defined frequency by examining update timestamps or review logs.
Test Verify the mechanism for detecting unauthorized hardware/software components (CM-8(3)) generates alerts, and review recent alerts and their dispositions.