ISO 27043
ISO 27043: Asset Management

ISO 27043 08: Information classification and labeling

Information classification and labeling. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.

What else in your programme already covers this

This control maps to 86 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

ISO/SAE 21434 · 3 controls

NIST SP 800-61 · 3 controls

  • NISTSP61-1 Incident Response Policy, Plan, and Procedures
  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence
  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

ISO/IEC 27010:2015 · 2 controls

MITRE ATT&CK · 2 controls

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 2 controls

  • NISTSP92-2 Log Generation: OS, Application, Security Tools, Network, Cloud, Required Event Content
  • NISTSP92-7 Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations
  • QRCM-1.1 Cryptographic Asset Inventory
  • QRCM-1.3 Data Classification for Migration

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

API 1164 · 1 control

BSI IT-Grundschutz · 1 control

  • BSI-15 Security categorization
  • QMSR-820.45 Device labelling and packaging controls (§820.45)

IEC 62443 · 1 control

ISO 27017 · 1 control

ISO 27017:2015 · 1 control

  • 8.2 Information classification

ISO 27018 · 1 control

ISO 27019 · 1 control

ISO 27701:2019 · 1 control

  • 6.5.2 Information classification

Japan AI Guidelines · 1 control

MTCS (Singapore) · 1 control

  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIS2I-6 Access Control, Asset Management, and Physical Security

NIST SP 1800-32 · 1 control

  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

NIST SP 800-137 · 1 control

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment

NIST SP 800-144 · 1 control

  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-7 Privacy, Records Retention, and User-Controlled Wallets

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OWASP MASVS · 1 control

  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • PASONE-1 Security Triage Process, Asset Sensitivity Classification, and Threat Assessment

PTES · 1 control

SASB Standards · 1 control

SLSA · 1 control

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ISO 27043: Asset Management

Query this from an agent

The graph holds this control, the 86 it maps to, and the evidence behind each claim, over MCP and REST.