Skip to content

Asset, Inventory & Assessment Scope

This document establishes the organization's policy for identifying and maintaining the set of information resources that constitutes the cloud service offering, and the procedures by which GRC-ITSM executes that policy.

It covers the asset register and the provider integrations that keep it current, the lifecycle of a resource that leaves the environment, the three record types that carry the Minimum Assessment Scope and the field sets they hold, third-party information resources and the measures documented against them, information flows and security categories, the ports, protocols, and services inventory and the reviews that keep it accurate, and the inventory reports that serve agency customers and FedRAMP. It implements the FedRAMP Minimum Assessment Scope (MAS) rule family from the FedRAMP Consolidated Rules for 2026 and the Policy and Inventory Key Security Indicator for generating inventories (KSI-PIY-GIV), with CMMC Level 2 and NIST 800-53 component-inventory and least-functionality lineage.

Quick Summary

The set of information resources that makes up the cloud service offering is held as live records in GRC-ITSM, kept current by provider integrations rather than by hand. Everything in the Minimum Assessment Scope is a Component, a Cloud Asset, or a Hardware Asset, and those records also carry information flows, security categories, and the four-part documentation set required for third-party resources. The ports, protocols, and services inventory is structured data that SSP section 10 renders from directly. Inventory reports in the FedRAMP Integrated Inventory Workbook shape generate live from the register, which is what makes KSI-PIY-GIV demonstrable.

Related documentation

Related documents own the adjacent disciplines. Drift from the approved baseline configuration and the retroactive change path that regularizes it are the Change Management Policy and Procedures. The recurring monthly inventory and least-functionality reviews sit in the recurring task program described in the Continuous Monitoring and Reporting Policy and Procedures. Publication of the inventory report through the trust center is the Certification Data Sharing and Trust Center Policy and Procedures.

Download the KB article (Markdown)


Framework applicability

Framework What this document satisfies
FedRAMP 20x (Classes B, C, and D) MAS provider rules (MAS-CSO-IIR, MAS-CSO-FLO, MAS-CSO-TPR, MAS-CSO-MDI, MAS-CSO-SUP); KSI-PIY-GIV
FedRAMP Rev5 The same MAS provider rules; underlying NIST CM-8, CM-8(1), CM-7, CM-7(1), CM-12, PM-5, with CA-7 touchpoints
CMMC Level 2 CM.L2-3.4.1 (establish and maintain baseline configurations and inventories of organizational systems), with CM.L2-3.4.7 traceability for the ports, protocols, and services discipline

The MAS provider rules apply to Classes B, C, and D. FedRAMP 20x classes differ in validation depth, not in the procedure itself: Class B should evidence each KSI with at least one automated method, Class C must use at least two, and Class D at least four. Class A follows its alternative-framework path.


Policy

  • P-1. The asset register is the inventory of record. The set of information resources to assess is held as live records in GRC-ITSM, not as a maintained spreadsheet or a document table. Providers MUST identify a set of information resources that includes all resources likely to handle federal customer data or likely to impact its confidentiality, integrity, or availability, and that set is the cloud service offering (MAS-CSO-IIR, MUST). The register is that set.
  • P-2. The register is populated by provider integrations, not by hand. Provider integrations synchronize the asset register automatically on a regular schedule, drawing from the authoritative source for each estate. Manual creation is reserved for resources no provider reports.
  • P-3. Synchronization is the reconciliation. Because each synchronization pass rewrites the register from the provider's own view of the estate, the register mirrors the accounts rather than being compared against them. There is no separate reconciliation step and no separate drift-flagging mechanism in this procedure. Unauthorized-resource handling rides the drift discipline in the Change Management Policy and Procedures and the monthly inventory review below.
  • P-4. Resources that leave the environment are retired, not erased. A resource that no longer appears from its provider is marked inactive on the next synchronization pass. Records are never deleted, so inventory history remains available for assessment and for incident reconstruction.
  • P-5. Everything in the Minimum Assessment Scope is a record of one of three types. Every information resource in scope is a Component, a Cloud Asset, or a Hardware Asset. Non-technical resources in scope, including policies, procedures, plans, and standards, are first-class Components rather than references in prose.
  • P-6. Information flows and security categories are documented for every resource or set of resources (MAS-CSO-FLO, MUST). Flows are documented on the records themselves through the three-layer model below, and the system-level narrative and diagram cover sets of resources.
  • P-7. Third-party information resources carry their own documentation set. For each third-party information resource used by the offering, the organization documents general usage and configuration, the explanation or justification for use, the mitigation measures in place to reduce potential impact to federal customer data, and the compensating controls in place for the same purpose (MAS-CSO-TPR, MUST). All four live on the Component record for that resource.
  • P-8. Metadata is in scope. Metadata collected or maintained by the offering, including metadata about federal customer data, is included in the Minimum Assessment Scope (MAS-CSO-MDI, MUST). It is carried on the same records as the resources that hold it rather than in a separate list.
  • P-9. Material about resources outside the offering is separated and marked. Where the organization supplies additional material about resources that are not part of the cloud service offering, it goes in a Certification Package supplement, clearly marked and separated, and is not FedRAMP Certified (MAS-CSO-SUP, MAY).
  • P-10. Ports, protocols, and services are structured data, not a document table. The ports, protocols, and services inventory is held as structured data linked to the system record, and SSP section 10 renders from it. The published table is therefore never out of step with the record.
  • P-11. The ports, protocols, and services inventory is maintained through change control and by direct edit. A change that adds, removes, or alters a port, protocol, or service carries that impact on its Change Request. Corrections and additions may also be made directly against the record. Both paths are legitimate; the record is the destination either way.
  • P-12. Inventories are generated from authoritative sources when needed, not compiled on request. Real-time inventories of all information resources are generated automatically from authoritative sources (KSI-PIY-GIV). The reports render live from the register; no separate compilation step stands between the register and the reader.
  • P-13. The inventory and the least-functionality posture are reviewed monthly. The monthly inventory and scan data review and the monthly unnecessary functions and ports, protocols, and services review are recurring tasks in the continuous monitoring task program, tracked to completion with the rest of that program.
  • P-14. The procedure reviews itself. The ISSO reviews this document for effectiveness on the cadence in the ODV table, together with the monthly review outcomes, and when frameworks, the system, or lessons learned warrant.

Organization-defined values

Value Setting Default Force
Provider integration synchronization cadence [cadence] Daily N/A
Provider estates integrated [estates] Azure, AWS, and Intune with Microsoft 365 N/A
Manual-entry scope [resource classes no integration reports] Non-technical Components and resources with no provider feed N/A
Lifecycle on disappearance from the provider Marked inactive, record retained Inactive on next synchronization; no deletion N/A
Inventory record retention [period] Indefinite (GRC-ITSM default) N/A
Component inventory review At least monthly, and on change Monthly (CM-8) N/A
Unnecessary functions and ports, protocols, and services review At least monthly Monthly (CM-7(1)) N/A
Baseline configuration review At least annually and on significant change Annually (CM-2) N/A
Inventory report format FedRAMP Integrated Inventory Workbook field set IIW (serves the MAS-CSO-IIR inventory artifact) MUST
Periodic inventory submission With the monthly continuous monitoring package Monthly N/A
Supplemental material about out-of-scope resources [material, if any] None by default; marked and separated if supplied (MAS-CSO-SUP) MAY
Security categorization per resource [categories in use] Varies by resource, per the type of information handled or impacted (MAS-CSO-FLO) N/A
CMMC asset categorization values [per contract] Per contract (CM.L2-3.4.1) N/A
Inventory procedure effectiveness review [cadence] Annually, with the monthly review outcomes N/A

Roles and responsibilities

  • ISSO. Owns inventory accuracy and the scope decisions that follow from it: which resources are in the cloud service offering, how each is categorized, and which third-party resources require the MAS-CSO-TPR documentation set. Reviews this document on the cadence in the ODV table.
  • System Owner. Accountable for the Minimum Assessment Scope as declared to FedRAMP and agency customers. Gives final approval on scope changes and authorizes exceptions.
  • Continuous Monitoring team. Executes the monthly inventory and scan data review and the monthly unnecessary functions and ports, protocols, and services review, and records the outcomes as task completions.
  • Implementers (system administrators, engineers). Keep the provider integrations healthy, create and maintain the records no integration reports, and record ports, protocols, and services impact on the Change Requests they raise.
  • Anyone may report an inventory discrepancy. Discrepancies that indicate an unauthorized resource are handled as drift under the Change Management Policy and Procedures.

The asset register

How records arrive

Provider integrations synchronize the asset register automatically on a regular schedule. Each integration reads the authoritative source for its estate: the cloud accounts for cloud infrastructure, and the endpoint and productivity management estate for managed devices and their software. Because the source is authoritative, the register does not need an independent census to be trusted.

Three consequences follow, and they are the reason this procedure claims no separate reconciliation step.

Property What it means in practice
The synchronization is the reconciliation The register is rewritten from the provider's own view of the estate on every pass, so it matches the running environment to within one synchronization interval rather than matching a previously recorded list
Nothing is compared against a shadow copy There is no second inventory to diff against, so no drift-flagging mechanism sits inside this procedure. Unauthorized resources surface through the change-management drift discipline and the monthly review
Disappearance is a state change, not a deletion A resource absent from its provider is marked inactive and kept. The register therefore answers both what is running now and what used to run

Resources that no provider reports are created and maintained directly. Non-technical resources in scope, such as policies, procedures, plans, and standards, always arrive this way.

The three record types

Record type Carries Typical contents
Component The scope taxonomy through its Component Type field, plus CMMC asset type, provider, and baseline Every kind of in-scope resource, technical and non-technical, including third-party services and external connections
Cloud Asset The full FedRAMP Integrated Inventory Workbook field set for cloud infrastructure Unique identifier, URI, IP addresses, fully qualified domain name, location, virtual and public flags, network or VLAN identifier, baseline configuration name, scanned and authenticated-scan flags, in-latest-scan flag, function, end of life
Hardware Asset The same Integrated Inventory Workbook field set for physical resources The fields above plus serial number and MAC address

The Component Type field carries the scope taxonomy. Its values are: System, Interconnection, Software, Hardware, Service, Policy, Physical, Process/Procedure, Plan, Guidance, Standard, Validation, Network, and Document.

Two of those values do specific work under the MAS rules.

  • Service. A third-party information resource used by the offering is a Component of type Service, carrying its Provider and its identity in the component library so the resource is named the same way everywhere it appears.
  • Interconnection. An external connection is a Component of type Interconnection, which makes each connection a record rather than a line in a narrative.

Third-party information resources

Each third-party information resource in scope carries the four-part MAS-CSO-TPR documentation set on its Component record: general usage and configuration, the explanation or justification for use, the mitigation measures in place to reduce potential impact to federal customer data, and the compensating controls in place for the same purpose. Keeping all four on the resource record means the third-party inventory and the third-party risk documentation cannot separate from each other.

Security categorization varies by resource as appropriate to the type of information each one handles or affects, including for third-party resources.


Information flows and security categories

Flows and security categories are documented for all information resources or sets of resources (MAS-CSO-FLO, MUST). Three layers carry them, and every flow in scope is covered by at least one.

Layer Record What it documents
1. Connection Component of type Interconnection The flow as a first-class record: source, destination, direction, data types carried, and the protection applied in transit
2. Resource Any Component The flow context for that specific resource, in its Description and Purpose, so a reader of one record sees how it participates
3. System System information The Data Flow narrative and the accompanying diagram, covering sets of resources and the boundary they cross

Flow documentation at layers 1 and 2 is explanatory prose on structured records rather than separately queryable flow fields. That satisfies MAS-CSO-FLO, which requires flows to be clearly identified, documented, and explained.


Ports, protocols, and services

The ports, protocols, and services inventory is structured data linked to the system record. SSP section 10 renders its table directly from that data, so the published table and the record are the same thing observed twice.

Maintenance runs on two paths, both legitimate.

  1. Through change control. A change that adds, removes, or alters a port, protocol, or service carries that impact on its Change Request, so the reason for the entry is traceable to the change that introduced it.
  2. By direct edit. Corrections, additions found during review, and entries for resources that arrived outside a Change Request are made directly against the record.

The monthly review is the periodic review. The recurring monthly unnecessary functions and ports, protocols, and services review examines the inventory for entries that are no longer needed, entries that are missing, and functions enabled without a documented need. Findings are corrected by direct edit where the correction is to the record, and raised as Change Requests where the correction is to the running system. The task definition matches what the change-control path now requires of it, so the review checks the same things the Change Request captures.


Inventory reporting

Both inventory outputs render from the register. Neither is separately maintained, and neither can disagree with the other.

Output Audience and cadence Content
Inventory report, Integrated Inventory Workbook format Agency customers and FedRAMP through the trust center, live The current state of the register in the IIW field set, generated when the reader requests it
Integrated Inventory Report in the monthly continuous monitoring package All necessary parties, monthly The same register content as the periodic submission for that month

KSI-PIY-GIV is demonstrated by the pair. Authoritative sources populate the register automatically on a regular schedule, and the IIW-format inventory generates live from that register when needed. That is what the indicator asks for: authoritative sources used to automatically generate real-time inventories of all information resources when needed. The scheduled synchronization supplies the authoritative-source half and the live report supplies the real-time-generation half.

Publication mechanics, access control, and the trust center surfaces that serve the report are the Certification Data Sharing and Trust Center Policy and Procedures.


Relationship to the SSP spine and control coverage

Records in the register link into the SSP asset spine, so the inventory is not a parallel artifact to the control documentation. Components roll up to the Capabilities they serve, and the Control Implementations, Implemented Requirements, and Implementation Statements that describe control coverage attach to the same records the inventory reports. A resource added to the register is therefore visible to control coverage without being entered a second time, and SSP regeneration reads the current register.


Recurring reviews

Review Cadence Source
Inventory and scan data review Monthly CM-8, RA-5
Unnecessary functions and ports, protocols, and services review Monthly CM-7(1)
Component inventory At least monthly, and on change CM-8
Baseline configuration At least annually and on significant change CM-2
Third-party information resource documentation set (usage, justification, mitigations, compensating controls) Annually, and on any change to the third-party relationship MAS-CSO-TPR, SA-9
Information flow and security categorization accuracy Annually, and on significant change MAS-CSO-FLO
Effectiveness of these inventory procedures Annually, with the monthly review outcomes CA-7

Records, retention, and metrics

The register retains, per resource: its unique identifier, the record type and Component Type, the security categorization, the provider and library identity where applicable, the Integrated Inventory Workbook field set for cloud and hardware resources, the flow documentation, the third-party documentation set where applicable, and the active or inactive state with its history. Inventory records are retained indefinitely and are never deleted.

Monthly metrics: resource count by record type and Component Type, count of resources newly active and newly inactive, count of resources created outside a provider integration, third-party resources with an incomplete documentation set, ports, protocols, and services entries added or removed with their originating Change Requests, and monthly review completion against its due date.


Authority, review, and revision

Issued under the authority of the System Owner and binding on all personnel with access to the system. Exceptions require written System Owner approval and are documented.

The ISSO reviews this document for effectiveness on the cadence in the ODV table, together with the monthly review outcomes, and when frameworks, the system, or lessons learned warrant; the System Owner gives final approval.


FedRAMP coverage

MAS provider rules: Identify Information Resources (MUST), Information Flows and Security Categories (MUST), Third-Party Information Resources (MUST), Metadata Inclusion (MUST), Supplemental Information (MAY) (MAS-CSO). KSI-PIY-GIV, Generating Inventories. Underlying NIST: CM-8, CM-8(1), CM-7, CM-7(1), CM-2, CM-12, PM-5, SA-9, RA-5, CA-7. CMMC: CM.L2-3.4.1, with CM.L2-3.4.7 traceability for the ports, protocols, and services discipline.