Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-ID.AM-04 NIST Cybersecurity Framework 2.0
ID - Identify
NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-04: Inventories of services provided by suppliers are maintained Inventories of services provided by suppliers are maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 144 controls across 75 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
6.12 Supplier relationships 6.12.1 Information security in supplier relationships 6.12.2 Supplier service delivery management 7.2.6 Contracts with PII processors 8.5.3 Records of PII disclosure to third parties 8.5.6 Disclosure of subcontractors used to process PII 8.5.7 Engagement of a subcontractor to process PII 5.20 Addressing information security within supplier agreements 5.21 Managing information security in the information and communication technology (ICT) supply chain 5.22 Monitoring, review and change management of supplier services 5.23 Information security for use of cloud services SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk SOC2-P6.2 P6.2 Record of authorised disclosures SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-39 Register of Material Service Providers CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability P2-S1 Partnership CIS-15.1 Establish and Maintain an Inventory of Service Providers CIS-15.2 Establish and Maintain a Service Provider Management Policy CIS-15.3 Classify Service Providers IEC62443-21 Supply chain risk management for critical components IEC62443-22 Configuration management for OT systems IEC62443-23 Change management procedures ISO-20400-7.3 Supplier selection ISO-20400-7.4 Contract management and review ISO-20400-7.5 Reviewing and learning 5.19 Information security in supplier relationships 5.22 Monitoring, review and change management of supplier services 5.23 Information security for use of cloud services ISO27019-22 Configuration management for OT systems ISO27019-23 Change management procedures ISO27019-24 Vulnerability assessment for critical systems RMI-DD-3 Red Flag Review RMI-MS-2 Cobalt Standard RMI-RMAP-2 Risk-Based Audit Approach SII-P2-09 Outsourcing Requirements SII-P2-12 Written Policies SII-P3-06 SFCR Section B: System of Governance CPG-6.A Vendor and Supplier Incident Reporting CPG-6.B Supply Chain Incident Reporting SA-9 External System Services SR-5 Acquisition Strategies, Tools, and Methods (SR-5) SA-9 External System Services SR-5 Acquisition Strategies, Tools, and Methods (SR-5) A.1 Point-of-Care Testing Additional Requirements ISO-15189-6.8 Externally provided products and services ISO28001-PC-03 Supply Chain Incident Reporting ISO28001-PC-04 Supply Chain Continuity Planning ISO27003-4.2 Understanding the needs and expectations of interested parties ISO27003-8.1 Operational planning and control 4.2 Understanding the needs and expectations of interested parties A.10 Third-party and customer relationships 12.8.1 12.8.1 List of third-party service providers 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs SASB-1 Business Model + Innovation (BMI) SASB-BMI-3 Supply Chain Management CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records AS9100D-8.4 Control of Externally Provided Processes, Products, Services Clause 3 Suppliers and service providers ACQ.4 Supplier Monitoring Mat 03 Responsible Sourcing of Materials C5-SSO-03 Directory of service providers and suppliers CFTC-SS-29 Recovery Plan Accounts for Essential Service Providers CJIS-19 Supply Chain Risk Management Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain ISO22316-14 Supply chain continuity ISO-26000-6.6 Fair operating practices ISO-41001-8.4 Control of outsourced processes and services ISO-50001-8.3 Procurement ISO23894-A.6 AI System Security 27010-15.1 Incident Management 27011-5.6 Supplier relationships and telecom supply chain ISO22317-14 Supply chain continuity ISO22318-14 Supply chain continuity Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider ID.AM-4 ID.AM-4: External information systems are catalogued ID.AM-4 ID.AM-4: External information systems are catalogued NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring ID.AM-04 ID.AM-04 Current inventories of supplier-provided services available to responders NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification OECDMNE-5 Environment, Climate, and Biodiversity PASONE-3 Personnel Security, Vetting, Awareness, and Training PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain IM8-TPM.4 Supply Chain Risk Management ISMSP-PI-03 Third-Party Provision and Outsourcing GT-3 Supply Chain Compromise UKOPRES-5 Third-Party Risk, Concentration Risk UKGAMBLE-4 Resilience and Incident Response SEMD-PS-3 Supply Chain Security UK-TSA-NET-03 Supply Chain Security Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ID - Identify NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-ID.IM-01 Improvements are identified from evaluations NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 144 it maps to, and the evidence behind each claim, over MCP and REST.