36 MAC Pt. 1, R. 2.1
System and Physical Device Inventory
Cite as 36 Miss. Admin. Code Pt. 1, R. 2.1
System and Physical Device Inventory
A. Each agency must maintain an accurate and up-to-date inventory of all technology
assets with the potential to store or process information. This should include all assets
with an IP address.
1. Implement a process that requires approval before new assets are installed or
deployed. This process shall include the designation of a person, or persons
authorized to make such approvals, and documentation describing how these
approvals are recorded.
2. The inventory shall include all hardware assets, whether connected to the
agency’s network or not. This includes agency assets owned, operated, or
managed by a third party.
3. The inventory shall be maintained and updated throughout the asset’s lifecycle
(installations, removals, updates, etc.).
i. Unsupported assets/hardware that can no longer receive security
patches must be removed from the network.
4. The inventory information for each asset should include the network address
(if static), hardware address, machine name, data asset owner, and department
for each asset and whether the hardware asset has been approved to connect to
the network. For assets with dynamic addresses provided by DHCP, refer to
ITS’s recommendation on utilizing DHCP.
i. ITS recommends utilizing dynamic host configuration protocol
(DHCP) logging on all DHCP servers or IP address management tools
to update the agency’s hardware asset inventory. Agencies might
consider creating DHCP reservations for all systems with dynamic
addresses in order to keep addresses from changing frequently.
5. ITS recommends maintaining active ports, services, and protocols to the
hardware assets in the asset inventory. Agencies might utilize port scanning
on a regular basis to review all open ports, identify any unauthorized ports,
and develop this portion of the inventory.
B. Each agency must ensure that unauthorized assets are either removed from the
network or receives a documented exception.
1. Employing MAC-based ACL’s or other methods are highly encouraged to
prevent an unauthorized host from connecting to the network. If this can be
employed, reviews should be performed regularly to ensure that it is working
as intended. If such technical controls cannot be implemented, network scans
should be executed on a frequent basis to identify unauthorized hosts.
C. ITS recommends utilizing an active discovery tool, such as a network port scanner,
for updating the hardware asset inventory.
D. ITS recommends utilizing dynamic host configuration protocol (DHCP) logging on
all DHCP servers or IP address management tools to update the agency’s hardware
asset inventory. Agencies might consider creating DHCP reservations for all systems
with dynamic addresses in order to keep addresses from changing frequently.
E. ITS recommends deploying automated mechanisms to support tracking and recovery
of physical devices and systems.