id: "CM-08(03)" title: "Automated Unauthorized Component Detection" family: "CM" family_name: "Configuration Management" sort_id: "cm-08.03" priority: "P1" implementation_level: "organization" parent: "CM-08" enhancement: True
Detect the presence of unauthorized hardware, software, and firmware components within the system using {{ insert: param, cm-8.3_prm_1 }} {{ insert: param, cm-08.03_odp.04 }} ; and
Take the following actions when unauthorized components are detected: {{ insert: param, cm-08.03_odp.05 }}.
Guidance
Automated unauthorized component detection is applied in addition to the monitoring for unauthorized remote connections and mobile devices. Monitoring for unauthorized system components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized components (see CM-7(9) ). Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organizations consider whether such mechanisms depend on the ability of the system component to support an agent or supplicant in order to be detected since some types of components do not have or cannot support agents (e.g., IoT devices, sensors). Isolation can be achieved , for example, by placing unauthorized system components in separate domains or subnets or quarantining such components. This type of component isolation is commonly referred to as "sandboxing."
Assessment Objective: the presence of unauthorized hardware within the system is detected using {{ insert: param, cm-08.03_odp.01 }} {{ insert: param, cm-08.03_odp.04 }};
Assessment Objective: the presence of unauthorized software within the system is detected using {{ insert: param, cm-08.03_odp.02 }} {{ insert: param, cm-08.03_odp.04 }};
Assessment Objective: the presence of unauthorized firmware within the system is detected using {{ insert: param, cm-08.03_odp.03 }} {{ insert: param, cm-08.03_odp.04 }};
Assessment Objective: {{ insert: param, cm-08.03_odp.05 }} are taken when unauthorized hardware is detected;
Assessment Objective: {{ insert: param, cm-08.03_odp.05 }} are taken when unauthorized software is detected;
Assessment Objective: {{ insert: param, cm-08.03_odp.05 }} are taken when unauthorized firmware is detected.
Configuration management policy
procedures addressing system component inventory
configuration management plan
system design documentation
system security plan
system component inventory
change control records
alerts/notifications of unauthorized components within the system
system monitoring records
system maintenance records
system audit records
system security plan
other relevant documents or records
Organizational personnel with component inventory management responsibilities
organizational personnel with responsibilities for managing the automated mechanisms implementing unauthorized system component detection
organizational personnel with information security responsibilities
system/network administrators
system developers
Organizational processes for detection of unauthorized system components
organizational processes for taking action when unauthorized system components are detected
automated mechanisms supporting and/or implementing the detection of unauthorized system components
automated mechanisms supporting and/or implementing actions taken when unauthorized system components are detected