Configuration management database (CMDB)

A repository of configuration items (the components that make up IT services) and the relationships between them, used to support change, incident and asset management.

A configuration management database (CMDB) stores records of configuration items (CIs) and of how they depend on one another. A configuration item is any component that has to be managed to deliver a service: servers, applications, network devices, databases and cloud resources. Each record typically holds the item’s attributes, its approved configuration and version, its owner, and its links to other CIs. The CMDB comes from IT service management practice, notably ITIL, and the same idea of controlled configuration items underpins the security-focused configuration management described in NIST SP 800-128.

A CMDB overlaps with an asset inventory without being the same thing. An inventory records what the organisation holds and who owns it; a CMDB adds how each item is configured and what depends on it. Much of its security value shows in change management, which compares a proposed change with the recorded security baseline and uses the relationships to judge its impact. A CMDB that drifts out of date gives false confidence, so discovery tools and change records are commonly used to reconcile it.

Exam relevance: a scenario is likely to ask which record shows what a change will affect, or where approved configurations are kept. Candidates are expected to link the CMDB with configuration and change management, and to distinguish it from a simple list of assets.