NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-01: Inventories of hardware managed by the organization are maintained

Inventories of hardware managed by the organization are maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 75 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 7 controls

  • CM-12 Information Location (CM-12)
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-8 System Component Inventory
  • CM-8(1) Updates During Installation and Removal
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • PE-16 Delivery and Removal
  • SR-11 Component Authenticity (SR-11)

FedRAMP Moderate · 7 controls

  • CM-12 Information Location (CM-12)
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-8 System Component Inventory
  • CM-8(1) Updates During Installation and Removal
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • PE-16 Delivery and Removal
  • SR-11 Component Authenticity (SR-11)

CIS Controls v8 · 6 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-1.2 Address Unauthorized Assets
  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-5.1 Establish and Maintain an Inventory of Accounts

PCI DSS 4.0 · 6 controls

  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.2.2 11.2.2 Inventory of authorized wireless access points
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 9.4.5 9.4.5 Inventory logs of electronic media
  • 9.5.1.1 9.5.1.1 Current register of POI devices
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware

NIST SP 800-53 Rev 5 · 4 controls

  • ISM-0336 Networked IT equipment register
  • ISM-1807 Fortnightly automated asset discovery
  • ISM-1869 Non-networked IT equipment register

ISO 27701:2019 · 3 controls

  • 6.5 Asset management
  • 6.5.1 Responsibility for assets
  • 6.8.2 Equipment
  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram
  • ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment

C2M2 · 2 controls

  • ASSET-1 Manage IT and OT Asset Inventory
  • ASSET-2 Manage Asset Configuration and Changes

CMMC 2.0 · 2 controls

  • CSL-Art21 Multi-Level Protection Scheme (MLPS) - Art. 21
  • CSL-Art31 Critical Information Infrastructure Designation - Art. 31

ISO 27002:2022 · 2 controls

  • 5.9 Inventory of information and other associated assets
  • 8.1 User endpoint devices

ISO/IEC 42001:2023 · 2 controls

  • A.4.2 Resource documentation
  • A.4.5 System and computing resources
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • AESCSF-ACM-1 Asset inventory
  • BIMCO-1.4 Differences between IT and OT systems

C5 (Germany) · 1 control

  • CIRCIA-2240 Definitions: Covered Entity, Covered Cyber Incident, Ransom Payment
  • DSL-Art21 Hierarchical Data Classification, Core Data and Important Data Catalogue (Art. 21)

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.9 Inventory of information and other associated assets

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management
  • ID.AM-1 ID.AM-1: Physical devices and systems within the organization are inventoried
  • ID.AM-1 ID.AM-1: Physical devices and systems within the organization are inventoried

NIST SP 800-172 · 1 control

  • 3.4.3e Automated Inventory of System Components
  • ID.AM-01 ID.AM-01 Current, automatically updated hardware inventories available to responders

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.