# SPA inventory and data-flow

STARTER TEMPLATE. Delete the example rows and replace them with your assets. Not a completed inventory. Not legal advice. Not an assessment.

Use this beside the system security plan, not instead of it. The DoD CMMC Scoping Guide — Level 2 (Version 2.13, September 2024) says to document each in-scope asset in an inventory, and says there is no requirement to embed each asset in the system security plan. The plan documents treatment. The network diagram shows the scope.

A Security Protection Asset provides security functions or capabilities to the CMMC assessment scope (32 CFR § 170.19 Table 3). If the asset processes, stores, or transmits CUI, it is also a CUI asset. FedRAMP, under DFARS 252.204-7012 and Table 4, is the requirement for an external cloud that stores, processes, or transmits CUI. It is not the Table 4 requirement for security protection data without CUI.

Do not paste CUI into this file.

## Inventory

| Row status | Asset name | Provider | Security function | Deployment | Handles CUI? | Holds security protection data? | Asset category | FedRAMP question | Data types | Data locations | Connected systems | In the asset inventory? | SSP treatment reference | On the network diagram? | Requirements relevant to the capability | Owner | Notes |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| EXAMPLE — delete this row | Example log service | Example provider | Central logging | Provider cloud | No — confirm | Yes — logs and configuration | SPA, if the CUI answer stays no | Not the Table 4 FedRAMP cell unless CUI is present | Security logs. Confirm no file contents or message bodies. | Example region. Also name backup and older-log storage. | Example in-scope servers | No | SSP § [fill] | No | [Fill only the requirements this capability supports] | [Name] | Replace every cell |

Add one row per asset. Deployment examples you might use, after you confirm them: software you run, provider cloud, managed service on your systems. Asset category examples you might use, after you confirm them: SPA, CUI asset, both, not yet categorized.

## Data flow

The diagram is still required. This table is a checklist so the diagram and the inventory name the same flows.

| Row status | Flow | From | To | Data | CUI or security protection data or other | Mechanism | Location of this copy | On the diagram? |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| EXAMPLE — delete this row | EXAMPLE-1 | In-scope server | Example log service | Security logs | Security protection data, if you have confirmed there is no CUI in the logs | Encrypted transport to the provider tenant | Live tenant, plus [name the older-log store] | No |

The Level 2 Scoping Guide uses a SIEM as an illustration: if an external provider hosts the service or the log storage, that portion of the provider is in the assessment scope, and longer-term storage of logs is in scope too. Name that location here if you have one.

## Open items

- [ ] CUI answer confirmed for each row, including encrypted content and log lines
- [ ] Backup and longer-term log locations named
- [ ] Subprocessors named
- [ ] Network diagram updated to match this table
- [ ] System security plan treatment section points at this inventory
