NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-05: Assets are prioritized based on classification, criticality, resources, and impact on the mission

Assets are prioritized based on classification, criticality, resources, and impact on the mission

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 73 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

SOC 2 · 5 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • ADMF-3.3 Apply overarching categorisation considerations
  • ADMF-4.1 Establish a data categorisation matrix
  • ADMF-4.4 Assign datasets to risk tiers
  • ADMF-6.3 Review categories assigned to datasets

FedRAMP High · 4 controls

  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-2 Security Categorization
  • RA-9 Criticality Analysis (RA-9)
  • SA-15(3) Development Process, Standards, and Tools | Criticality Analysis (SA-15(3))

FedRAMP Moderate · 4 controls

  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-2 Security Categorization
  • RA-9 Criticality Analysis (RA-9)
  • SA-15(3) Development Process, Standards, and Tools | Criticality Analysis (SA-15(3))

ISO 27701:2019 · 4 controls

  • 5.2.3 Determining the scope of the information security management system
  • 6.5 Asset management
  • 6.5.1 Responsibility for assets
  • 6.5.2 Information classification
  • ISM-0293 Classifying IT equipment
  • ISM-0323 Classifying media by data held
  • ISM-1633 System boundary, criticality and objectives
  • ASBv3-AM-1 Track asset inventory and their risks
  • ASBv3-DP-1 Discover, classify, and label sensitive data
  • ASBv3-IM-2 Protect identity and authentication systems

ISO 27001:2022 · 3 controls

  • 5.12 Classification of information
  • 5.13 Labelling of information
  • 5.9 Inventory of information and other associated assets

ISO 27002:2022 · 3 controls

  • 5.12 Classification of information
  • 5.13 Labelling of information
  • 5.9 Inventory of information and other associated assets
  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • CPS230-17 Mandatory Minimum Classification of Critical Operations
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation

APRA CPS 234 · 2 controls

  • CPS234-20 Information Asset Classification
  • CPS234-21 Implementation of Information Security Controls
  • SEC07-BP01 Understand your data classification scheme
  • SEC07-BP02 Apply data protection controls based on data sensitivity

CIS Controls v8 · 2 controls

  • CIS-3.12 Segment Data Processing and Storage Based on Sensitivity
  • CIS-3.7 Establish and Maintain a Data Classification Scheme

PCI DSS 4.0 · 2 controls

  • 9.4.2 9.4.2 Classification of media by data sensitivity
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment

C5 (Germany) · 1 control

  • C5-AM-06 Asset Classification and Labelling

CMMC 2.0 · 1 control

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 8.2.2 Business impact analysis

ISO/IEC 42001:2023 · 1 control

  • A.4 Resources for AI systems

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management
  • ID.AM-5 ID.AM-5: Resources (e.g., hardware, devices, data, and software) are prioritized based on their classification, criticality, and business value
  • ID.AM-5 ID.AM-5: Resources (e.g., hardware, devices, data, time, personnel, and software) are prioritized based on their classification, criticality, and business value
  • ID.AM-05 ID.AM-05 Asset priorities and dependencies direct protection, detection, response and recovery
  • 3(c)(vi) Sec. 3(c)(vi) (now 3(a)(vi)) Tell CISA which systems need extra controls or non-disruption periods

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-05 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 73 it maps to, and the evidence behind each claim, over MCP and REST.