Assets, Inventories, and Configuration Baselines
Networking devices, servers and application servers have both inventory and configuration control requirements. Configuration baseline refers to the minimum secure configuration applied to any device at build. Changes to the configuration beyond this point are associated to business requirements, product release and project management. Data Center Operations and Support manage an inventory of items and baseline configuration. These records are tables in Facilitated Compliance Management but are scheduled to be moved into [Name of core product or service].
Where configuration records include IP addressing and other information that could be used to compromise network security, the information is not made available beyond person's who support and networking and [Name of core product or service] platform availability.
When Do I Need to Create a Controlled Server Object?
Consider whether the following statements are true.
Figure 15. Should I document a controlled server in our system inventory database?
Where Are Devices Inventoried as Assets?
Controlled Server Records will reside in [Name of core product or service] but are currently staged in Facilitated Compliance Management
Where Do I Find Server Control Records?
\\...\pal\Facilitated Compliance Management\Shortcut to Controlled Servers in Facilitated Compliance Management2000FCM.MAT [links are for example and are not enabled over the internet]
Figure 16. Controlled Server Form
Figure 17. Each controlled item has associated security exemptions and standard OS and Application build
Which Tools Store Server and Application Information?
The data center maintains a list of devices and tools or applications with their respective controls and resource owners. This information is maintained in Facilitated Compliance Management.
All systems, applications or Tools are inventoried assets
Where Is the List of Tools and Tool Types?
Tools and Tool types are listed in the Tools and Tool Type table in the Facilitated Compliance Management2000FCM database. Servers and devices are recorded in the Controlled Server Form, located in the Facilitated Compliance Management database.
Controls and Key Controls
When Do I Need to Document a Control Object?
Controls practices provide reasonable assurance that business rules exist and are optimized such that negative impact of undesirable events are captured, responded to and mitigated. IT Control is the right mixture of policies, procedures, practices and organizational structures that assure business objectives are met, while preventing, detecting or correcting any or all undesired events.
Control Definitions exist within each process and are an inherent feature in policy.
Control Over Process Is Demonstrated When:
- It Communicates Repeatable Intention
- Executes As Planned (Implementation Plan)
- Measures (Risk Measurement & Impact Analysis)
- Records (Management Reporting & KPI)
- Archives (Defined Data Retention)
- Control Items capture
- Control Name
- Owner
- Control Method
- Automation or Manual
- Program
- Frequency
- Test Information
- Activity Definition
- Location of Test and Test Evidence
- Information Processing Objective
- Sequence ID and Key Tracking
For more information, review section Document Elements: Flow Diagram, "Visio Shapes and Custom Properties for Evidence of Process Controls"
Where Are Controls Catalogued?
Controls are cataloged by Name, Associated Processes, and Owners within Technology's [Name of core product or service] system. The information is used for ongoing Control Self-Assessment and Compliance Documentation.
Controls are cataloged in Facilitated Compliance Management and in [Name of core product or service]. Controls are also identified within every Process Flow Diagram and Program Definition. Key Controls align to the CobiT framework and are visible on the CobiT Assessment form within Facilitated Compliance Management.
Figure 18. What Process Engineering, Auditors, and Quality Gather Regarding Corporate Key Controls
Figure 19. Process Diagrams call information from the Facilitated Compliance Management database. Key controls pull information from the Key Controls Table.







Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics