NIST SP 800-171 revision 3 outlines security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. It mandates maintaining a comprehensive inventory of all hardware, including make/OEM, model, version, service packs, and the responsible party. This inventory can be maintained in an organizational component database.

Example:  Include or Reference All Hardware