id: "CM-07(09)" title: "Prohibiting The Use of Unauthorized Hardware" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.09" priority: "P1" implementation_level: "system" parent: "CM-07" enhancement: True


Identify {{ insert: param, cm-07.09_odp.01 }};

Prohibit the use or connection of unauthorized hardware components;

Review and update the list of authorized hardware components {{ insert: param, cm-07.09_odp.02 }}.

Guidance

Hardware components provide the foundation for organizational systems and the platform for the execution of authorized software programs. Managing the inventory of hardware components and controlling which hardware components are permitted to be installed or connected to organizational systems is essential in order to provide adequate security.

Assessment Objective: {{ insert: param, cm-07.09_odp.01 }} are identified;

Assessment Objective: the use or connection of unauthorized hardware components is prohibited;

Assessment Objective: the list of authorized hardware components is reviewed and updated {{ insert: param, cm-07.09_odp.02 }}.

Configuration management policy

network connection policy and procedures

configuration management plan

system security plan

system design documentation

system component inventory

system audit records

system security plan

other relevant documents or records

Organizational personnel with system hardware management responsibilities

organizational personnel with information security responsibilities

system/network administrators

Organizational process for approving execution of binary or machine-executable code

mechanisms supporting and/or implementing the prohibition of binary or machine-executable code