Asset & Configuration Management

Your boundary. Engineered.

You cannot protect what you have not inventoried, and an assessor cannot verify a boundary that is not documented. The Asset Inventory is the authoritative list of hardware in your CUI environment, the foundation of your SSP system description, and the starting point for configuration baseline management.

CM.L2 3.4.1 satisfied
Per asset CUI boundary scoped
SSP System description auto-populated
Capability

What Gets Captured

Each asset record captures name, type, location, operating system, IP address or identifier, whether the asset stores or processes CUI, and its in-scope or out-of-scope status for the assessment boundary. Serial numbers and purchase dates are available as optional fields. Assets are categorized by type (workstations, servers, network devices, storage systems, printers, and portable media) so the inventory gives a complete picture of the hardware environment.

The in-scope or out-of-scope designation is the most consequential field in the record. Assessors verify that in-scope assets are covered by your security controls and that out-of-scope assets are genuinely isolated from the CUI environment. An asset marked out of scope that shares a network segment with in-scope systems is a boundary finding, and it surfaces during the assessment regardless of what the inventory says.

Dashboard Requirements Evidence POA&M Reports
1TEN Asset Inventory listing in-scope assets with scope categorization and baseline linkage
Capability

CUI Data Flow Visualization

Understanding which assets are in scope requires understanding how CUI moves through your environment: which systems create it, which store it, which transmit it, and where it exits. The CUI flow report maps your asset inventory against the data flows you have described, producing a visual representation of the boundary that assessors use to verify that scope is accurate and complete.

This view is especially useful during pre-assessment preparation. Walking your C3PAO assessor through a documented data flow diagram, rather than asking them to reconstruct it from interviews, demonstrates preparation and reduces the likelihood of boundary disputes during the assessment itself.

Inside the Module

What You See Inside

Complete asset records
Name, type, location, OS, IP or identifier, CUI processing status, and boundary designation for every device.
Categorized by type
Workstations, servers, network devices, storage systems, printers, and portable media.
In-scope boundary tagging
In-scope or out-of-scope designation per asset: the field that defines your assessment boundary.
CUI data flow report
Maps how CUI moves through in-scope assets from creation through storage, transmission, and exit.
Linked to config and maintenance
Each asset links to its Configuration Baseline record and its Maintenance Log events.
SSP auto-population and history
The system boundary and asset list in your SSP export draw from this inventory, and every change is logged with date and user.
The problem this solves

The CMMC assessment boundary is defined by where CUI flows, and that boundary is only defensible if you know exactly what hardware is in it. An organization that cannot produce a current, accurate hardware inventory when an assessor asks faces two problems at once: it cannot demonstrate that CM.L2-3.4.1 is satisfied, and it cannot credibly assert that its SSP system description is accurate. No more IT spreadsheets that are out of date before the assessment, no more SSP asset lists frozen in time, no more boundaries the assessor has to reconstruct from interviews.

Reference

Asset Record Fields

Asset name / hostname
Identifies the asset in the inventory and in SSP references.
Required
Asset type
Categorizes hardware for boundary analysis and configuration management.
Required
Location
Physical location in the facility, relevant to PE domain physical access controls.
Required
Operating system
Required for configuration baseline association and patch management tracking.
Required
IP address / identifier
Network identity for boundary documentation and access control verification.
Required
Stores or processes CUI
Drives in-scope designation: assets that touch CUI are in scope by definition.
Required
Boundary status
In-scope or out-of-scope for the CMMC assessment: the key scoping decision.
Required
Serial number
Physical asset tracking, useful for maintenance and disposal documentation.
Optional
Purchase / deployment date
Asset lifecycle tracking and end-of-support date monitoring.
Optional
Practices

Practices Satisfied

Practice IDDescription
CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems.
CA.L2-3.12.4 SSP system boundary and asset description. The Asset Inventory is the authoritative source for the system identification section of the System Security Plan.
Connected Modules

Related Modules

Your SSP. Not a template.

1TEN generates your System Security Plan from your actual documented control implementations. C3PAO-ready.

Request a Demo