id: "CM-07(09)" title: "Prohibiting The Use of Unauthorized Hardware" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.09" priority: "P1" implementation_level: "system" parent: "CM-07" enhancement: True
Identify {{ insert: param, cm-07.09_odp.01 }};
Prohibit the use or connection of unauthorized hardware components;
Review and update the list of authorized hardware components {{ insert: param, cm-07.09_odp.02 }}.
Guidance
Hardware components provide the foundation for organizational systems and the platform for the execution of authorized software programs. Managing the inventory of hardware components and controlling which hardware components are permitted to be installed or connected to organizational systems is essential in order to provide adequate security.
Assessment Objective: {{ insert: param, cm-07.09_odp.01 }} are identified;
Assessment Objective: the use or connection of unauthorized hardware components is prohibited;
Assessment Objective: the list of authorized hardware components is reviewed and updated {{ insert: param, cm-07.09_odp.02 }}.
Configuration management policy
network connection policy and procedures
configuration management plan
system security plan
system design documentation
system component inventory
system audit records
system security plan
other relevant documents or records
Organizational personnel with system hardware management responsibilities
organizational personnel with information security responsibilities
system/network administrators
Organizational process for approving execution of binary or machine-executable code
mechanisms supporting and/or implementing the prohibition of binary or machine-executable code