id: "CM-12" title: "Information Location" family: "CM" family_name: "Configuration Management" sort_id: "cm-12" priority: "P1" implementation_level: "organization" enhancements: - cm-12.1


Identify and document the location of {{ insert: param, cm-12_odp }} and the specific system components on which the information is processed and stored;

Identify and document the users who have access to the system and system components where the information is processed and stored; and

Document changes to the location (i.e., system or system components) where the information is processed and stored.

Guidance

Information location addresses the need to understand where information is being processed and stored. Information location includes identifying where specific information types and information reside in system components and how information is being processed so that information flow can be understood and adequate protection and policy management provided for such information and system components. The security category of the information is also a factor in determining the controls necessary to protect the information and the system component where the information resides (see FIPS 199 ). The location of the information and system components is also a factor in the architecture and design of the system (see SA-4, SA-8, SA-17).

Assessment Objective: the location of {{ insert: param, cm-12_odp }} is identified and documented;

Assessment Objective: the specific system components on which {{ insert: param, cm-12_odp }} is processed are identified and documented;

Assessment Objective: the specific system components on which {{ insert: param, cm-12_odp }} is stored are identified and documented;

Assessment Objective: the users who have access to the system and system components where {{ insert: param, cm-12_odp }} is processed are identified and documented;

Assessment Objective: the users who have access to the system and system components where {{ insert: param, cm-12_odp }} is stored are identified and documented;

Assessment Objective: changes to the location (i.e., system or system components) where {{ insert: param, cm-12_odp }} is processed are documented;

Assessment Objective: changes to the location (i.e., system or system components) where {{ insert: param, cm-12_odp }} is stored are documented.

Configuration management policy

procedures addressing identification and documentation of information location

configuration management plan

system design documentation

system architecture documentation

PII inventory documentation

data mapping documentation

audit records

list of users with system and system component access

change control records

system component inventory

system security plan

privacy plan

other relevant documents or records

Organizational personnel with responsibilities for managing information location and user access to information

organizational personnel with responsibilities for operating, using, and/or maintaining the system

organizational personnel with information security and privacy responsibilities

system/network administrators

system developers

Organizational processes governing information location

mechanisms enforcing policies and methods for governing information location