CMDB Defined
A Configuration Management Database (CMDB) is a centralised repository that stores information about all Configuration Items (CIs) in an IT environment — and, critically, the relationships between them. A CI is any component that needs to be managed: servers, applications, databases, network devices, licences, contracts, and the people responsible for them. The CMDB answers the question: "If this server goes down, what else breaks?" It is the foundational dataset that enables effective change management, incident response, and compliance reporting. ITIL 4 defines CMDB as central to the Service Configuration Management practice. ISO/IEC 27001:2022 Annex A.8.9 requires configuration management for all information processing assets.
CMDB Maturity Levels
| Level | State | What You Have | Audit Risk |
|---|---|---|---|
| 0 | None | Spreadsheets, tribal knowledge | Critical failure |
| 1 | Basic | Static inventory list, no relationships | High risk |
| 2 | Managed | CMDB tool, relationships mapped, auto-discovery | Medium risk |
| 3 | Optimised | CMDB integrated with change, incident, monitoring | Audit-ready |
How a CMDB Supports Compliance
- Change Management: Every change request references CIs from the CMDB. Impact analysis — which systems are affected? — is automated.
- Incident Response: During a CERT-In incident, you need to know within hours: what systems were affected, what data they hold, and who owns them. CMDB provides this instantly.
- Audit Evidence: ISO 27001 A.8.9 requires evidence of configuration management. A CMDB with version history, change linkage, and discovery logs is the definitive evidence artefact.
- Vulnerability Management: Vulnerability scanners integrated with CMDB can automatically identify affected CIs when a CVE is published — enabling targeted, rapid patching.
Building a CMDB for an Indian SME
Enterprise CMDB platforms like ServiceNow CMDB or BMC Helix CMDB are designed for large enterprises. For Indian mid-market organisations, practical starting points include: Snipe-IT (open source), Ralph, or NetBox for network CIs. The key is to start with critical assets — production servers, network devices, and databases — before expanding scope.
CMDB Readiness Is Part of Every IGaaS Assessment
InfraVeritas 360 assesses your configuration management maturity as a core IGaaS control — identifying whether your CMDB can support change management, incident response, and ISO 27001 audit evidence requirements.
Assess Your CMDB Maturity →