MCP Server Inventory and Configuration Baseline
Added September 2026
Keep an inventory of every MCP server (the connectors that let AI agents use tools and data) in the organization. Hold each one to a baseline for authentication, permissions, logging, and data-loss coverage.
Objective
Make sure every connection between AI agents and company tools or data is known, securely set up, and visible to data-loss controls, instead of spreading unseen across teams.
Maturity Levels
Initial
Teams install MCP servers as needed. There is no list of which ones exist, who runs them, or what they connect to.
Developing
Some MCP servers are known to the security team, but there is no required configuration and data-loss prevention tools do not see traffic passing through them.
Defined
All MCP servers are recorded in an inventory with an owner, the data they expose, and their authentication method. Each must meet a written baseline before agents may connect to it.
Managed
Network scans find unregistered MCP servers. Baseline compliance is checked on a schedule against an external benchmark, and data-loss rules cover MCP traffic.
Optimizing
Only MCP servers from an approved catalog can be installed. Every tool call is logged against an identity and scope, and baseline checks run automatically when a server changes.
Evidence Requirements
What an auditor or assessor would expect to see for this control.
- —MCP server inventory with owner, exposed systems and data, authentication method, and permitted clients
- —Written MCP configuration baseline and completed checks for each server, mapped to the CIS MCP benchmark
- —Network or endpoint scan results showing discovery of unregistered MCP servers and follow-up actions
- —DLP rule configuration or equivalent server-side checks covering MCP traffic
- —Sample tool-call logs showing identity, tool, parameters, and outcome
Implementation Notes
What MCP is, in plain terms
The Model Context Protocol (MCP) is a common standard for connecting AI agents to tools and data. An MCP server is a small program that exposes something, such as a database, a file share, or a ticketing system, to any agent that connects. Because MCP servers are easy to set up, they spread quickly and often without review. In September 2026, organizations in Australia and New Zealand reported data exposure through MCP connections that their data-loss prevention (DLP) tools never saw. CIS also published a 55-point MCP security benchmark.
Inventory
Record for each MCP server:
- Owner and hosting location
- What it exposes: the systems, data types, and actions available
- How agents authenticate to it, and whether it passes the user's own identity through
- Which agents and users are allowed to connect
Find unregistered servers with network scans and endpoint checks on developer machines, where many MCP servers run locally.
Baseline configuration
Require at minimum:
- Authentication: no anonymous access; tokens scoped to the specific server and short-lived.
- Least privilege: each tool exposes only the actions the use case needs, with limits on parameters, such as read-only queries or row caps.
- Logging: every tool call recorded with the calling identity, the tool, the parameters, and the result status.
- Data-loss coverage: MCP traffic is routed where DLP rules can inspect it, or the server applies equivalent checks itself.
- Change control: updates to a server's tools or permissions trigger re-review.
Use the CIS MCP benchmark as the external reference for baseline checks, and treat third-party MCP servers as supply-chain components under AGT-019.
Example Implementation
Software company where engineering teams had installed MCP servers independently
MCP Server Baseline Check: jira-mcp (internal)
| Baseline item | Status | Note |
|---|---|---|
| Registered owner | Pass | Developer Productivity team |
| Anonymous access disabled | Pass | OAuth, tokens expire after 1 hour |
| Tools limited to use case | Fail | Exposes delete_issue; agents only need read and comment |
| Tool-call logging | Pass | Sent to central log store with user identity |
| DLP coverage | Fail | Traffic bypasses the DLP proxy |
| CIS MCP benchmark score | 41 / 55 | Two high-severity findings open |
Decision: agents may keep read access. Write tools stay disabled until delete_issue is removed and traffic is routed through the DLP proxy. Target date 2026-10-15.
