Why: A reconciled inventory of devices, accounts, and applications is what makes 'identify every user, process, and device' checkable at all — the practice produces the reference list this requirement's coverage is measured against.
What this does not claim: The inventory itself identifies nothing at authentication time. It provides the evidence base for the requirement; the identification mechanisms are separate work, and coverage must be evaluated within the organization's defined system boundary.
- Reconcile identity-store accounts against the personnel and asset lists on a cadence
- Register machine identities and service principals alongside hardware assets
- Reconciliation report between directory and inventory
- Machine-identity register with owners
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06