Skip to main content

The CMDB/CMS in the Digital Age: More Present Than You Might Think

Dennis Drogseth

Insofar as news and media comes and goes in waves, rising and falling on areas of attention that sometimes engender self-created storms (positive and negative), the configuration management database (CMDB) is currently residing in a valley, not a crest. As tech headlines flash across my email, at least, the CMDB, and its federated equivalent, the configuration management system (CMS), are almost never mentioned. And yet when I do research, dialog with IT, or support our consulting team, the CMDB/CMS many times still remains paramount.

Why the Disconnection?

To be honest I don't have all the answers, but some of it has to do with how markets get defined — rigidly and academically — so that attention often gets directed to only a subset of what's needed, and then quickly becomes frozen in time. This did a great deal to hinder the CMDB's evolution and effectiveness, and still puts it in a far smaller box than it deserves to be in.

Another reason is that when industry attention peaked a decade ago, in many respects CMDB technology wasn't up to the task. This factor was exacerbated by a general trend to see the CMDB vision as a monolithic answer to every possible IT concern, without attention to use case, relevance, and currency. As such many IT organizations imagined that putting all their data in one place would, in and of itself, turn out to be transformative, something like buying a car without knowing how to drive or even how to fill it with gas.

And finally, all the attention given to cloud, microservices and agile has at times seemed to challenge the validity of the CMDB, in particular given the need for dynamic currency.

Why the CMDB/CMS is More Present Than You Might Think

But as I hope to make clear in a webinar on July 24, the CMDB, the CMS, and effective discovery and dependency mapping (DDM) are actually more relevant now than ever. CMDB/CMS/DDM technology has evolved considerably in the last decade, and is continuing to evolve, to become far more dynamic, and in some cases truly real-time.

And where do these technologies play?

■ Collectively these technologies can become lynch pins for more effective change, asset, performance, and capacity management.

■ They can help accelerate DevOps effectiveness, including pre-production provisioning, managing cloud compliance issues, and ensuring that operations and development really are on the same team.

■ In recent EMA research, the CMDB/CMS was shown to be a valuable asset in unifying security and operations teams for more efficient SecOps initiatives.

■ And both in EMA consulting and multiple aspects of EMA research, investments in the CMDB/CMS and DDM have become pivotal for effective cloud migration and optimization of cloud resources on an ongoing basis over time.

A Few More Proof Points

Here are just a few specifics taken in large part from EMA's consulting practice. When asked about "why invest in CMDB/CMS and DDM," top priorities included:

■ Decreases time to resolve technical problems

■ Breaks down barriers between technology silos

■ Allows automation and advanced analytics to be implemented

■ Facilitates an enterprise IT dashboard

■ Reduces long-term costs of IT services

And some specific examples of benefits taken as well from EMA's history with CMDB/CMS deployments:

■ US Financial Services company reduced MTTR by 70% by providing consistent and holistic services map with asset and inventories.

■ US MSP able to reconcile disputes regarding infrastructure spends. $9M spend over 3 years reduced by $2.5M by better understanding inventory.

■ US Healthcare organization reduced MTTR, downtime, and outages by 40% by implementing a CMDB. Savings returned 300% ROI over several years.

And from EMA's 2017 research on IT service management:

■ Those who were "extremely successful" in their ITSM-related initiatives were twice as likely to own a CMDB/CMS than "somewhat successful" or "unsuccessful."

■ They were also three times more likely to federate.

■ They were considerably more aggressive in exploring CMDB/CMS-related use cases.

■ They were seven times more likely to have plans to associate discovery and dependency mapping with the CMDB/CMS.

■ And they were significantly more likely to have deployed DDM capabilities.

So on to the Webinar

These are just a few examples of data I will be sharing in the webinar on July 24 referenced above. Beyond sharing more specifics of how CMDB/CMS can and has achieved value, I'll also provide an introduction to our deployment methodology achieved over the years through our consulting practice. Looking forward to your thoughts and comments.

Hot Topics

The Latest

For fifteen years, observability lived downstream of everything else. Code shipped, something broke, an engineer went to the dashboards. The job was forensic. The pillars we built, such as logs, metrics, and traces, were designed for that role: tell a human what just happened, fast enough that they can make it stop. That role has quietly ended ...

Hybrid IT has become the standard operating model for enterprises — but that companies are still looking for the right hybrid IT mix, according to the 2026 State of the Data Center Report from CoreSite. After years of cloud migration and hybrid adoption, organizations are shifting their focus from deciding whether to use cloud, colocation or on-premises infrastructure to determining which workloads belong in each environment ...

Pilots are everywhere, stakeholders are seeking results, businesses are pushing for new tools, and IT teams are being asked to make AI secure, reliable, and useful at scale. But as organizations move from testing AI to operationalizing it, many are discovering that the biggest barrier is not the model, the use case, or even the budget. It is the file data foundation within ...

Fast or cheap? For most of my career in engineering, speed and quality sat on opposite ends of a seesaw. The "OR" in "fast or cheap" was non-negotiable. It was expected that pushing for faster releases meant that something in quality would give way. Tightening quality controls meant the schedule slipped. Every engineering leader I know has lived some version of that tradeoff ... The seesaw is starting to level out ...

I have been building enterprise software for more than 20 years ... One thing stays true across all of it: You do not find out your foundation is wrong during the crisis. You find out when the debt comes due. For a lot of organizations, that bill is arriving now. New research ... puts hard numbers on something practitioners have been sensing for a while. The telemetry problem isn't coming. It's already here ...

The rapid growth of AI workloads is pushing traditional log management approaches to their limits, according to The State of Log Management 2026 report from Dynatrace. Modern logs have become critical to understanding, validating, and securing AI-driven decisions, helping organizations ensure reliability, compliance, and performance at scale. However, the volume and complexity of AI telemetry are overwhelming legacy tools ...

For years, secure connectivity has relied on a familiar pattern: route traffic back to centralized gateways, inspect it, and then allow access. This model worked when applications lived in a handful of data centers and users were largely confined to offices. That model is now under strain. Applications are distributed across clouds, users connect from everywhere, and real-time workloads demand performance that centralized inspection points struggle to deliver. As traffic volumes grow and latency expectations shrink, routing everything through a small number of control points has become both a performance bottleneck and a resilience risk. The future of secure connectivity requires a different approach ...

The AI experimentation phase is over, and the private cloud is where enterprise AI workloads are being deployed for security and scale, according to Private Cloud Outlook 2026, a new report from Broadcom ... 2026 marks an acceleration into a full AI tipping point. The shift is being shaped by three forces — costs, complexity, and control — that public cloud environments are increasingly failing to address for production AI at scale. Key findings from the report include ...

44% of organizations have reported an outage in the past year tied to suppressed or ignored alerts, and 78% had at least one incident where no alert was fired at all ... Engineers learned about failures from customers. That gap between what our tools report and what our customers experience is the problem DevOps teams have been quietly solving with GenAI tooling, even as most enterprises continue to run their NOCs on manual alert triage ...

Cloud outages are usually described as technical failures. When a service goes down, a dependency breaks, or a region has issues, the focus immediately shifts to infrastructure. But if you look closely at how these incidents actually unfold, the root cause is rarely the technology itself. It is almost always tied to decisions made earlier, during design, implementation, or day-to-day operations. The system behaves the way it was built. The real question is how it was built ...

The CMDB/CMS in the Digital Age: More Present Than You Might Think

Dennis Drogseth

Insofar as news and media comes and goes in waves, rising and falling on areas of attention that sometimes engender self-created storms (positive and negative), the configuration management database (CMDB) is currently residing in a valley, not a crest. As tech headlines flash across my email, at least, the CMDB, and its federated equivalent, the configuration management system (CMS), are almost never mentioned. And yet when I do research, dialog with IT, or support our consulting team, the CMDB/CMS many times still remains paramount.

Why the Disconnection?

To be honest I don't have all the answers, but some of it has to do with how markets get defined — rigidly and academically — so that attention often gets directed to only a subset of what's needed, and then quickly becomes frozen in time. This did a great deal to hinder the CMDB's evolution and effectiveness, and still puts it in a far smaller box than it deserves to be in.

Another reason is that when industry attention peaked a decade ago, in many respects CMDB technology wasn't up to the task. This factor was exacerbated by a general trend to see the CMDB vision as a monolithic answer to every possible IT concern, without attention to use case, relevance, and currency. As such many IT organizations imagined that putting all their data in one place would, in and of itself, turn out to be transformative, something like buying a car without knowing how to drive or even how to fill it with gas.

And finally, all the attention given to cloud, microservices and agile has at times seemed to challenge the validity of the CMDB, in particular given the need for dynamic currency.

Why the CMDB/CMS is More Present Than You Might Think

But as I hope to make clear in a webinar on July 24, the CMDB, the CMS, and effective discovery and dependency mapping (DDM) are actually more relevant now than ever. CMDB/CMS/DDM technology has evolved considerably in the last decade, and is continuing to evolve, to become far more dynamic, and in some cases truly real-time.

And where do these technologies play?

■ Collectively these technologies can become lynch pins for more effective change, asset, performance, and capacity management.

■ They can help accelerate DevOps effectiveness, including pre-production provisioning, managing cloud compliance issues, and ensuring that operations and development really are on the same team.

■ In recent EMA research, the CMDB/CMS was shown to be a valuable asset in unifying security and operations teams for more efficient SecOps initiatives.

■ And both in EMA consulting and multiple aspects of EMA research, investments in the CMDB/CMS and DDM have become pivotal for effective cloud migration and optimization of cloud resources on an ongoing basis over time.

A Few More Proof Points

Here are just a few specifics taken in large part from EMA's consulting practice. When asked about "why invest in CMDB/CMS and DDM," top priorities included:

■ Decreases time to resolve technical problems

■ Breaks down barriers between technology silos

■ Allows automation and advanced analytics to be implemented

■ Facilitates an enterprise IT dashboard

■ Reduces long-term costs of IT services

And some specific examples of benefits taken as well from EMA's history with CMDB/CMS deployments:

■ US Financial Services company reduced MTTR by 70% by providing consistent and holistic services map with asset and inventories.

■ US MSP able to reconcile disputes regarding infrastructure spends. $9M spend over 3 years reduced by $2.5M by better understanding inventory.

■ US Healthcare organization reduced MTTR, downtime, and outages by 40% by implementing a CMDB. Savings returned 300% ROI over several years.

And from EMA's 2017 research on IT service management:

■ Those who were "extremely successful" in their ITSM-related initiatives were twice as likely to own a CMDB/CMS than "somewhat successful" or "unsuccessful."

■ They were also three times more likely to federate.

■ They were considerably more aggressive in exploring CMDB/CMS-related use cases.

■ They were seven times more likely to have plans to associate discovery and dependency mapping with the CMDB/CMS.

■ And they were significantly more likely to have deployed DDM capabilities.

So on to the Webinar

These are just a few examples of data I will be sharing in the webinar on July 24 referenced above. Beyond sharing more specifics of how CMDB/CMS can and has achieved value, I'll also provide an introduction to our deployment methodology achieved over the years through our consulting practice. Looking forward to your thoughts and comments.

Hot Topics

The Latest

For fifteen years, observability lived downstream of everything else. Code shipped, something broke, an engineer went to the dashboards. The job was forensic. The pillars we built, such as logs, metrics, and traces, were designed for that role: tell a human what just happened, fast enough that they can make it stop. That role has quietly ended ...

Hybrid IT has become the standard operating model for enterprises — but that companies are still looking for the right hybrid IT mix, according to the 2026 State of the Data Center Report from CoreSite. After years of cloud migration and hybrid adoption, organizations are shifting their focus from deciding whether to use cloud, colocation or on-premises infrastructure to determining which workloads belong in each environment ...

Pilots are everywhere, stakeholders are seeking results, businesses are pushing for new tools, and IT teams are being asked to make AI secure, reliable, and useful at scale. But as organizations move from testing AI to operationalizing it, many are discovering that the biggest barrier is not the model, the use case, or even the budget. It is the file data foundation within ...

Fast or cheap? For most of my career in engineering, speed and quality sat on opposite ends of a seesaw. The "OR" in "fast or cheap" was non-negotiable. It was expected that pushing for faster releases meant that something in quality would give way. Tightening quality controls meant the schedule slipped. Every engineering leader I know has lived some version of that tradeoff ... The seesaw is starting to level out ...

I have been building enterprise software for more than 20 years ... One thing stays true across all of it: You do not find out your foundation is wrong during the crisis. You find out when the debt comes due. For a lot of organizations, that bill is arriving now. New research ... puts hard numbers on something practitioners have been sensing for a while. The telemetry problem isn't coming. It's already here ...

The rapid growth of AI workloads is pushing traditional log management approaches to their limits, according to The State of Log Management 2026 report from Dynatrace. Modern logs have become critical to understanding, validating, and securing AI-driven decisions, helping organizations ensure reliability, compliance, and performance at scale. However, the volume and complexity of AI telemetry are overwhelming legacy tools ...

For years, secure connectivity has relied on a familiar pattern: route traffic back to centralized gateways, inspect it, and then allow access. This model worked when applications lived in a handful of data centers and users were largely confined to offices. That model is now under strain. Applications are distributed across clouds, users connect from everywhere, and real-time workloads demand performance that centralized inspection points struggle to deliver. As traffic volumes grow and latency expectations shrink, routing everything through a small number of control points has become both a performance bottleneck and a resilience risk. The future of secure connectivity requires a different approach ...

The AI experimentation phase is over, and the private cloud is where enterprise AI workloads are being deployed for security and scale, according to Private Cloud Outlook 2026, a new report from Broadcom ... 2026 marks an acceleration into a full AI tipping point. The shift is being shaped by three forces — costs, complexity, and control — that public cloud environments are increasingly failing to address for production AI at scale. Key findings from the report include ...

44% of organizations have reported an outage in the past year tied to suppressed or ignored alerts, and 78% had at least one incident where no alert was fired at all ... Engineers learned about failures from customers. That gap between what our tools report and what our customers experience is the problem DevOps teams have been quietly solving with GenAI tooling, even as most enterprises continue to run their NOCs on manual alert triage ...

Cloud outages are usually described as technical failures. When a service goes down, a dependency breaks, or a region has issues, the focus immediately shifts to infrastructure. But if you look closely at how these incidents actually unfold, the root cause is rarely the technology itself. It is almost always tied to decisions made earlier, during design, implementation, or day-to-day operations. The system behaves the way it was built. The real question is how it was built ...