You want me to Count What? CMMC and Inventory
What counts when counting for CMMC?
The thing about the CMMC pause, it hasn’t really changed how one should get started with building systems that meet NIST-SP-800-171 requirements. Getting started involves getting better at doing the basics. Staying compliant for CMMC just means counting chickens and mending fences.
The discovery phase for many organizations means getting a handle on inventory. Businesses that struggle with inventory often have good problems. They have grown quickly and procedures have not kept up with contractual demands. You have different software platforms that count different things and all make pretty different dashboard, but nobody can see the full picture.
On the flip side you have microbusinesses of 1-3 employees who struggle with what feels like an overwhelming documentation burden to do Government contracting.
Most small businesses fall somewhere in the middle. For Manufactures you know how to inventory. You track BOMs and QM documents all the time. Lean into what you do well. If you
So What do you need to count?
At KNC we recommend doing your inventory with a mind toward NIST-SP-800-171 rev 3. You want these procedures to last, and under rev 2 rules you can set the frequency of what and when you count.
- Site Inventory
- Personnel Assets
- Endpoints
- Network Devices
- Manufacturing Equipment
- Printer Inventory
- USB Assets
- Mobile Devices or Enrolled BYOD
- Software
- SPA tools
- External Connections
- Service Accounts
- Documentation
Each of these has it’s own worksheet in our workbook. The headings customized to follow NIST Guidance for inventories.
Chances are a small or medium size company, you already gather much of this information, but you need to have it organized to complete a self-assessment of NIST-SP-800-171. This does not have to be a spreadsheet.
A ticketing system that notes when an authorized user gets added to the system can generate reports that serve as an inventory of users authorized to access systems that store, process, or transmit CUI.
But many companies like to maintain a Source of Truth for these assets outside of any external system or tool. Just a regular old workbook with a worksheet for each item. For small companies, maintaining this data manually gets built into the boundaries you build. You will need to think about the Security Protection Assets like Endpoint Detection and Response or your security cameras (like a Ring Doorbell).
Maybe in the Age of AI doing somethings manually is the best approach to protecting the integrity and availability of your source of truth and the resiliency of your procedures overall.
What Must I Count
NIST-SP-800-171 Rev 3 explicity calls for an inventory that, while part of Configuration Management and Access Control was more assumed to happen in Rev 2.
03.04.10 – System Component Inventory
Develop and document the component inventory; review and update it at the organization-defined frequency; update it during installations, removals, and system updates.
What must be explicitly inventoried under 03.04.10
Your inventory must cover system components within the NIST SP 800-171 boundaries. Anything that
- Process CUI
- Store CUI
- Transmit CUI
- Provide security protection for components that process, store, or transmit CUI.
“System components” include identifiable hardware, software, and firmware elements such as:
- Workstations, laptops, and servers
- Smartphones and tablets
- Printers, scanners, copiers, and other input/output devices
- Firewalls, routers, switches, wireless access points, and other network components
- Operating systems
- Virtual machines
- Database management systems
- Applications
- Security tools and services installed within or protecting the CUI environment
- Embedded firmware and other identifiable firmware components
Inventory then comes up as evidence of your controls satisfying other NIST-SP-800-171 requirements. 03.08.01 – Media Storage states that physically controlling stored CUI media includes conducting inventories, check-out/check-in procedures, and maintaining accountability. Counting your stuff gets brought up again in the next requirement as well, Media Access 03.08.02 when inventories get mentioned as a means of controlling access and maintaining accountability for stored media.
Of course 03.03.05 – Audit Record Review, Analysis, and Reporting will rely on your inventory. You need to audit your system component inventory from 03.04.10
What else must I count
NIST-SP-800-171 rev 3 requirements may ask you to count stuff but not call it an inventory. For many small businesses much of this gets maintained by your MSP/IT consultant. Having a template to give them that explicitly lays out the requirements to count stuff will help to ensure your CMMC compliance.
| Requirement | Required record |
|---|---|
| 03.04.08 – Authorized Software – Allow by Exception | List of software authorized to execute, reviewed and updated at the defined frequency |
| 03.04.11 – Information Location | Documented locations of CUI and the components on which CUI is processed or stored, including location changes |
| 03.07.06 – Maintenance Personnel | List of authorized maintenance organizations or personnel |
| 03.10.01 – Physical Access Authorizations | Approved and maintained list of individuals authorized to access facilities containing the system |
| 03.15.02 – System Security Plan | Definition of constituent system components, information types, interconnections, dependencies, and individuals assigned system roles |
| 03.05.07 – Password Management | Maintained list of commonly used, expected, or compromised passwords; this is a prohibited-password list, not an asset inventory |
Nobody says counting your stuff will stop an Advanced Persistent Threat. Foxes will get it in, but you can’t understand the risk if you have not count your chickens. . A few birds will fall, but if you don’t know how many hens stay in your boundary how can you protect them at all?
Discovery and CMMC
When doing the discovery stage of a CMMC call we really focus on the documentation. The data flow diagram, another key discovery element, uses a different methodology
A company does not need to have all of these documents, many 1-3 person companies will have few to none of these documents, but these are the docs we often see that companies already have that can provide evidence or be built into an inventory of components. Many manufacturers do inventory well. You might have a mature document control process and have much of this data somewhere.
I have not updated this discovery list with Rev 3 requirements yet, but during discover really we just want to know if inventory exists, and not so much complete your inventory. More often than not we discover that you may not have an adequately organized inventory, or have no real inventory at all.
If an item on the list below is missing nobody says you have to within your organization. You need your documentation to work for you. Create stackable procedures that allow you to do business better.
(if you want a copy of the full spreadsheet send me an email to greg.mcverry@kncss.com.)
| No. | Document or Evidence Requested | Associated Rev 2 Requirement(s) |
|---|---|---|
| 1 | System Security Plan | 3.12.4 |
| 2 | Plan of Action and Milestones (POA&M) | 3.12.2 |
| 3 | Information Flow Control Policy, including how and where data is handled and any external information systems used | 3.1.3 |
| 4 | Incident Response Plan, Policy, and/or Procedures | 3.6.1, 3.6.2 |
| 5 | Tabletop Exercise After-Action Report | 3.6.3 |
| 6 | Physical Security Policy and/or Procedures | 3.10, 3.7.4 |
| 7 | Sanitization and Destruction Procedures | 3.7.3 |
| 8 | Media Protection Policy | 3.8 |
| 9a | Employee Handbook: Authorized User Agreement | 3.1.1 |
| 9b | Employee Handbook: Company Acceptable Use Policy | 3.1.6, 3.1.7 |
| 9c | Employee Handbook: User Agreements or User Rules of Behavior | — |
| 9d | Social Media Policy, if not included in the Employee Handbook | 3.1.22 |
| 9e | Telework Policy | 3.10.6 |
| 10 | HR and employee procedures covering onboarding, offboarding, transfers, background checks, access revocation, and termination | 3.9 |
| 11 | Employee training requirements and/or programs covering information security awareness, CUI, and insider threats, including evidence of completion and training records | 3.2 |
| 12 | Data Handling Procedures, Data Retention Policy, and Data Destruction Policy and Procedures | 3.1.3, 3.8 |
| 13 | Most Recent Risk Assessment and Risk Register | 3.11 |
| 14 | Prior assessments or analyses, including Level 1 or Level 2 assessments | 3.11, 3.12 |
| 15 | Data Flow Diagrams | — |
| 16 | Organizational Chart | — |
| No. | Document or Evidence Requested | Details |
|---|---|---|
| 1 | List of External Service Providers | Include External Service Providers (ESPs), Managed Service Providers (MSPs), and Cloud Service Providers (CSPs) |
| 2 | Cloud Service Provider Agreements | Agreements governing cloud services used within the assessed environment |
| 3 | Subcontractor Agreements | Agreements with subcontractors that handle CUI or provide security-related services |
| 4 | Shared Responsibility Documentation | Identification of customer, provider, and subcontractor security responsibilities and inherited controls |
| 5 | FedRAMP Authorization Documentation | Applicable FedRAMP authorization package, Marketplace listing, authorization level, and supporting documentation |
| 6 | CUI Flow-Down Clauses | Contractual clauses requiring applicable CUI safeguarding requirements to flow down to subcontractors |
| No. | Document or Evidence Requested |
|---|---|
| 1 | Facility Access Procedures |
| 2 | Badge Access Documentation |
| 3 | Visitor Log Procedures |
| 4 | CUI Storage Procedures |
| 5 | Media Destruction and Shredding Procedures |
| 6 | Site Map |
| 7 | Camera Coverage Documentation |
| 8 | Server Room Access Controls |
| 9 | Documentation of Locking Cabinets Used for CUI |
| 10 | Media Storage Area Documentation |
| 11 | Clean-Desk Practices |
| 12 | Physical Destruction Processes, Including Shredders and Destruction Bins |
| No. | Document or Evidence Requested |
|---|---|
| 1 | Physical and/or Logical Network Diagrams |
| 2 | Hardware Device Inventory |
| 3 | Software Allowlist or Whitelist |
| 4 | Data Flow Diagrams |
| 5 | Allowed List of Ports, Protocols, and Services |
| 6 | Firewall Rulesets and Other Boundary-Control Configurations |
| 7 | Recent Vulnerability Scan Reports |
| 8 | Patch Management Procedures |
| 9 | Backup Policy and Procedures |
| 10 | Business Continuity Plan and Disaster Recovery Plan |
| 11 | Change Management Procedures |
| 12 | Configuration Management Procedures |
| 13 | Mobile Device Management Documentation and/or Procedures |
| 14 | Password Policy and/or Procedures |
| 15 | Role-Based Access Control Matrix |
| 16 | User Access List, Including Privileged, Non-Privileged, and Service Accounts |
| No. | Security Requirement Family | Requested Documentation |
|---|---|---|
| 1 | Access Control | Policy, procedures, and plan |
| 2 | Awareness and Training | Policy, procedures, and plan |
| 3 | Audit and Accountability | Policy, procedures, and plan |
| 4 | Assessment, Authorization, and Monitoring | Policy, procedures, and plan |
| 5 | Configuration Management | Policy, procedures, and plan |
| 6 | Contingency Planning | Policy, procedures, and plan |
| 7 | Identification and Authentication | Policy, procedures, and plan |
| 8 | Incident Response | Policy, procedures, and plan |
| 9 | Maintenance | Policy, procedures, and plan |
| 10 | Media Protection | Policy, procedures, and plan |
| 11 | Physical and Environmental Protection | Policy, procedures, and plan |
| 12 | Planning | Policy, procedures, and plan |
| 13 | Program Management | Policy, procedures, and plan |
| 14 | Personnel Security | Policy, procedures, and plan |
| 15 | Risk Assessment | Policy, procedures, and plan |
| 16 | System and Services Acquisition | Policy, procedures, and plan |
| 17 | System and Communications Protection | Policy, procedures, and plan |
| 18 | System and Information Integrity | Policy, procedures, and plan |
| 19 | Supply Chain Risk Management | Policy, procedures, and plan |
| 20 | Records Retention | Records Retention Schedule |
Chickens flickr photo by chumlee10 shared under a Creative Commons (BY-SA 2.0) license
