AI Governance Institute
← Agentic AI
AGT · Agentic AIAGT-030Medium effortAgent-relevant

MCP Server Inventory and Configuration Baseline

Added September 2026

Keep an inventory of every MCP server (the connectors that let AI agents use tools and data) in the organization. Hold each one to a baseline for authentication, permissions, logging, and data-loss coverage.

Objective

Make sure every connection between AI agents and company tools or data is known, securely set up, and visible to data-loss controls, instead of spreading unseen across teams.

Maturity Levels

1

Initial

Teams install MCP servers as needed. There is no list of which ones exist, who runs them, or what they connect to.

2

Developing

Some MCP servers are known to the security team, but there is no required configuration and data-loss prevention tools do not see traffic passing through them.

3

Defined

All MCP servers are recorded in an inventory with an owner, the data they expose, and their authentication method. Each must meet a written baseline before agents may connect to it.

4

Managed

Network scans find unregistered MCP servers. Baseline compliance is checked on a schedule against an external benchmark, and data-loss rules cover MCP traffic.

5

Optimizing

Only MCP servers from an approved catalog can be installed. Every tool call is logged against an identity and scope, and baseline checks run automatically when a server changes.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —MCP server inventory with owner, exposed systems and data, authentication method, and permitted clients
  • —Written MCP configuration baseline and completed checks for each server, mapped to the CIS MCP benchmark
  • —Network or endpoint scan results showing discovery of unregistered MCP servers and follow-up actions
  • —DLP rule configuration or equivalent server-side checks covering MCP traffic
  • —Sample tool-call logs showing identity, tool, parameters, and outcome

Implementation Notes

What MCP is, in plain terms

The Model Context Protocol (MCP) is a common standard for connecting AI agents to tools and data. An MCP server is a small program that exposes something, such as a database, a file share, or a ticketing system, to any agent that connects. Because MCP servers are easy to set up, they spread quickly and often without review. In September 2026, organizations in Australia and New Zealand reported data exposure through MCP connections that their data-loss prevention (DLP) tools never saw. CIS also published a 55-point MCP security benchmark.

Inventory

Record for each MCP server:

  • Owner and hosting location
  • What it exposes: the systems, data types, and actions available
  • How agents authenticate to it, and whether it passes the user's own identity through
  • Which agents and users are allowed to connect

Find unregistered servers with network scans and endpoint checks on developer machines, where many MCP servers run locally.

Baseline configuration

Require at minimum:

  • Authentication: no anonymous access; tokens scoped to the specific server and short-lived.
  • Least privilege: each tool exposes only the actions the use case needs, with limits on parameters, such as read-only queries or row caps.
  • Logging: every tool call recorded with the calling identity, the tool, the parameters, and the result status.
  • Data-loss coverage: MCP traffic is routed where DLP rules can inspect it, or the server applies equivalent checks itself.
  • Change control: updates to a server's tools or permissions trigger re-review.

Use the CIS MCP benchmark as the external reference for baseline checks, and treat third-party MCP servers as supply-chain components under AGT-019.

Example Implementation

Software company where engineering teams had installed MCP servers independently

MCP Server Baseline Check: jira-mcp (internal)

Baseline itemStatusNote
Registered ownerPassDeveloper Productivity team
Anonymous access disabledPassOAuth, tokens expire after 1 hour
Tools limited to use caseFailExposes delete_issue; agents only need read and comment
Tool-call loggingPassSent to central log store with user identity
DLP coverageFailTraffic bypasses the DLP proxy
CIS MCP benchmark score41 / 55Two high-severity findings open

Decision: agents may keep read access. Write tools stay disabled until delete_issue is removed and traffic is routed through the DLP proxy. Target date 2026-10-15.

Control Details

Control ID
AGT-030
Typical owner
CISO / Head of AI Platform
Implementation effort
Medium effort
Agent-relevant
Yes

Tags

MCPagentic AIagent toolsdata loss preventionconfiguration baselineAI inventory

Get control updates weekly

New and updated controls, maturity guidance, and the regulatory changes behind them. Every Thursday.

Powered by Buttondown.