Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.04.10OFFICIAL TITLEPENDING NIST SME REVIEW

03.04.10System Component Inventory

03.04 Configuration Management · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires developing and documenting an inventory of system components, reviewing and updating that inventory at an organization-defined frequency, and updating it as part of component installations, removals, and system updates.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

The inventory question, asked at system scope: what components make up this system, written down and kept current — on a schedule, and in the same motion as installs, removals, and updates, rather than in an annual scramble before an assessment.

Across revisions

Split from Rev. 2's 3.4.1: the inventory half becomes a standalone requirement with an explicit update frequency and update-on-change duties; the baseline half stays in 03.04.01.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportHigh confidence

Why: Developing, documenting, and updating a component inventory is this practice's core activity — discovery-driven, reconciled on a cadence, corrected when things are installed and removed. Rev. 3 giving the inventory its own requirement makes this the practice's most direct configuration-management relationship.

What this does not claim: The requirement is scoped to the CUI system's components and wants updates at a defined frequency and as part of installations, removals, and updates — an organizational inventory carries it only when filtered to the system boundary and wired into change control. Supports implementation of the requirement; scope, the defined frequency, and evidence still decide the assessment outcome.

Practice-side activities
  • Reconcile discovered assets against the documented inventory on a defined cadence
  • Maintain an inventory view scoped to the CUI system boundary
  • Update inventory records as part of installation, removal, and update workflows
Evidence this produces
  • The dated component inventory scoped to the system
  • Reconciliation reports at the defined frequency
  • Change records showing inventory updates with installs and removals

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Partial implementation supportModerate confidence

Why: A walked-down, physically verified OT asset list is component inventory work done to a higher evidentiary standard than network discovery reaches — for the OT portion of a CUI boundary, it is exactly the documented inventory this requirement asks for.

What this does not claim: May partially address the requirement, and only where OT assets sit inside the CUI system boundary — many defense manufacturers' boundaries center on enterprise IT, where this practice contributes nothing. The defined update frequency and the update-on-change integration are process commitments the walkdown itself does not establish.

Practice-side activities
  • Walk down and physically verify OT assets against the documented list
  • Record firmware, model, and connectivity attributes that network discovery cannot see
Evidence this produces
  • The validated OT asset list with walkdown dates
  • Reconciliation notes between walkdown findings and the documented inventory

Where this holds: Holds for OT segments within the assessed boundary; enterprise components need the IT-side inventory practice.

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Reuse the organizational asset inventory filtered to the CUI system boundary rather than maintaining a second list that will diverge from the first.
  • Wire updates into change control: an install or decommission that does not touch the inventory is an incomplete change.
  • Choose an update frequency the organization can evidence; quarterly reconciliation against discovery data is realistic for a small estate.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The component inventory, dated and scoped to the system
  • Reconciliation records at the defined frequency
  • Change records showing inventory updates as part of installs and removals

Suggested owners, derived from the mapped practices and artifacts: IT leader · Plant / OT leader · IT leader or compliance lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated