Critical Information Asset Inventory, Data Classification
LOW, MOD, HIGH
P1
Yes
August 24, 2016
The information resource owner shall develop and document an inventory of all components for an Agency-owned information resource, which accurately reflects the current information resource and all components within the authorization boundary of the information resource. The information resource owner shall review and update the component inventory at least annually.
Information and assets associated with information processing facilities are not owned by a designated part of the organization.
The organization:
a. Develops and documents an inventory of information system components that:
1. Accurately reflects the current information system;
2. Includes all components within the authorization boundary of the information system;
3. Is at the level of granularity deemed necessary for tracking and reporting; and
4. Includes [Assignment: organization-defined information deemed necessary to achieve effective information system component accountability]; and
b. Reviews and updates the information system component inventory [Assignment: organization-defined frequency].
The organization has an inventory of information system components and a process to keep the information current.
The state organization develops, documents, and maintains a current inventory of the components of the information system and relevant ownership information.
Obtain configuration management policy; procedures addressing information system component inventory; information system inventory records; security plan; component installation records; other relevant documents or records and ascertain if :
(I)the organization develops and documents an inventory of the components of the information system:
-that is at the level of granularity deemed appropriate by the organization for the components included in the inventory that are subject to tracking and reporting.
-that includes any information determined to be necessary by the organization to achieve effective property accountability.
-that is consistent with the accreditation boundary of the system.
(ii)the organization maintains the inventory of the components of the information system to reflect the current state of the system.
(iii)the organization updates the inventory of information system components as an integral part of component installations.