CM-7(9)

  • Requirement

    1. Identify [Assignment: organization-defined hardware components authorized for system use];
    2. Prohibit the use or connection of unauthorized hardware components;
    3. Review and update the list of authorized hardware components [Assignment: organization-defined frequency].
  • Discussion

    Hardware components provide the foundation for organizational systems and the platform for the execution of authorized software programs. Managing the inventory of hardware components and controlling which hardware components are permitted to be installed or connected to organizational systems is essential in order to provide adequate security.

More Info

  • Title

    Least Functionality | Prohibiting The Use of Unauthorized Hardware
  • Family

    Configuration Management
  • NIST 800-53B Baseline(s)

    • Related NIST 800-53 ID

    NIST 800-53A Assessment Guidance

    CMMC Training

    Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!