Why: A current baseline configuration can only be developed and kept current for components the organization knows it has, and the practice's reconciled inventory of hardware, software, and applications is that substrate. The relationship was seeded against Rev. 2's 3.4.1, where baselines and inventories were one requirement.
What this does not claim: Rev. 3 narrows this requirement to the baseline configuration itself — the inventory half of Rev. 2's 3.4.1 now lives in 03.04.10, where this practice maps on its own terms. Inventory work identifies what exists; it does not author, version, or review the baseline documents this requirement is about, and it does not satisfy the requirement on its own.
- Maintain the authoritative component list baseline documents are scoped against
- Flag inventory changes — new hardware, new software — that should trigger a baseline review
- Inventory reports aligned to baseline document scope
- Change records showing inventory-triggered baseline updates
Where this holds: The relationship is to the baseline's factual substrate, not its authorship; baseline documentation and review are separate work whatever the inventory's quality.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06