id: "CM-08(03)" title: "Automated Unauthorized Component Detection" family: "CM" family_name: "Configuration Management" sort_id: "cm-08.03" priority: "P1" implementation_level: "organization" parent: "CM-08" enhancement: True


Detect the presence of unauthorized hardware, software, and firmware components within the system using {{ insert: param, cm-8.3_prm_1 }} {{ insert: param, cm-08.03_odp.04 }} ; and

Take the following actions when unauthorized components are detected: {{ insert: param, cm-08.03_odp.05 }}.

Guidance

Automated unauthorized component detection is applied in addition to the monitoring for unauthorized remote connections and mobile devices. Monitoring for unauthorized system components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized components (see CM-7(9) ). Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organizations consider whether such mechanisms depend on the ability of the system component to support an agent or supplicant in order to be detected since some types of components do not have or cannot support agents (e.g., IoT devices, sensors). Isolation can be achieved , for example, by placing unauthorized system components in separate domains or subnets or quarantining such components. This type of component isolation is commonly referred to as "sandboxing."

Assessment Objective: the presence of unauthorized hardware within the system is detected using {{ insert: param, cm-08.03_odp.01 }} {{ insert: param, cm-08.03_odp.04 }};

Assessment Objective: the presence of unauthorized software within the system is detected using {{ insert: param, cm-08.03_odp.02 }} {{ insert: param, cm-08.03_odp.04 }};

Assessment Objective: the presence of unauthorized firmware within the system is detected using {{ insert: param, cm-08.03_odp.03 }} {{ insert: param, cm-08.03_odp.04 }};

Assessment Objective: {{ insert: param, cm-08.03_odp.05 }} are taken when unauthorized hardware is detected;

Assessment Objective: {{ insert: param, cm-08.03_odp.05 }} are taken when unauthorized software is detected;

Assessment Objective: {{ insert: param, cm-08.03_odp.05 }} are taken when unauthorized firmware is detected.

Configuration management policy

procedures addressing system component inventory

configuration management plan

system design documentation

system security plan

system component inventory

change control records

alerts/notifications of unauthorized components within the system

system monitoring records

system maintenance records

system audit records

system security plan

other relevant documents or records

Organizational personnel with component inventory management responsibilities

organizational personnel with responsibilities for managing the automated mechanisms implementing unauthorized system component detection

organizational personnel with information security responsibilities

system/network administrators

system developers

Organizational processes for detection of unauthorized system components

organizational processes for taking action when unauthorized system components are detected

automated mechanisms supporting and/or implementing the detection of unauthorized system components

automated mechanisms supporting and/or implementing actions taken when unauthorized system components are detected