FedRAMP Controls / CM
CM-8(3) Automated Unauthorized Component Detection
Family CM
Baselines moderate
Mapped KSIs 2
Control statement
(a) Detect the presence of unauthorized hardware, software, and firmware components within the system using {{ insert: param, cm-8.3_prm_1 }} {{ insert: param, cm-08.03_odp.04 }} ; and
(b) Take the following actions when unauthorized components are detected: {{ insert: param, cm-08.03_odp.05 }}. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-CMT-01 | Log and Monitor Changes Log and monitor modifications to the cloud service offering. | Change Management |
| KSI-SVC-05 | Resource Integrity Use cryptographic methods to validate the integrity of machine-based information resources. | Service Configuration |