List of All Production Systems (Servers, VMs, Data Stores)
Provide a system-generated list of all in-scope production system assets.
Evidence should demonstrate:
Whether or not the resource is related to production or development
Whether that asset stores or accesses customer or sensitive data
How the production inventory was produced
Additional Guidance
Formal system inventories are used to effectively assign ownership of assets and ensure that all in-scope production systems follow your security policies and standards.
If you use a CSP, you can use your CSP to generate a list of your in-scope production system assets.
For example, AWS allows users to make API calls to generate an asset list of their AWS resources (e.g., EC2 instances, VPCs, data stores).
Related Articles
Example Evidence
AWS (EC2 Instances and RDS)
Associated Unified Control ID | Associated Framework Control |
CTRL-435 | LCL-39 |