-
(a): Identify [hardware components authorized for system use are defined;];
-
(b): Prohibit the use or connection of unauthorized hardware components;
-
(c): Review and update the list of authorized hardware components [frequency at which to review and update the list of authorized hardware components is defined;].
Supplemental
Hardware components provide the foundation for organizational systems and the platform for the execution of authorized software programs. Managing the inventory of hardware components and controlling which hardware components are permitted to be installed or connected to organizational systems is essential in order to provide adequate security.