NIST SP 800-53 Rev. 5 · Configuration Management
CM-8 — System Component Inventory
Device active in the estate but absent from the inventory. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
A device operating on the network that appears on no inventory
An organization cannot protect what it does not know it has. Devices arrive without going through any process — a contractor's laptop, a replacement machine, equipment from an acquired business — and they receive no updates, no monitoring, and no attention, because as far as every system of record is concerned they do not exist.
Why this check earns its place. It works from evidence of actual activity rather than from a scan, so it finds devices that are genuinely in use rather than addresses that happen to respond. New devices are given a grace period, so ordinary onboarding does not generate findings.
- What it reads
- Evidence of devices actually being used, compared against the organization's own inventory.
- What it reports
- Devices that have been active for longer than the registration period allows and appear on no inventory.
See related public disclosures on the Signals page →
The requirement
The organization must develop and maintain an inventory of system components that accurately reflects the system, is at the level of granularity deemed necessary for tracking and reporting, and is reviewed and updated at an organization-defined frequency.
NIST SP 800-53 Rev. 5 — CM-8 (System Component Inventory).
NIST requires the inventory to be accurate. It does not say what counts as a component, how quickly a new device must be registered, or which populations are exempt. This pack finds devices that are demonstrably active — they authenticated or generated telemetry — and are not in the inventory you supplied. The registration grace period and the exempt populations are yours to define.
What a check finds
A device generated authentication or platform telemetry, has been doing so for longer than the registration grace period, and does not appear in the supplied asset inventory.
Choose your platform
CISA performance goals
- 3.R — Prohibit connection of unauthorized devices
- 2.A — Manage organizational assets
What a result does not prove
An unregistered device is not evidence of an intrusion, and this is the pack most likely to report a records problem rather than a security one. Identifier mismatches between telemetry and inventory produce the same result as a genuinely unknown device, which is why the review tier is automated-with-review rather than automated.