Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-ID.AM-08 NIST Cybersecurity Framework 2.0
ID - Identify
NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-08: Systems, hardware, software, services, and data are managed throughout their life cycles Systems, hardware, software, services, and data are managed throughout their life cycles
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 111 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory CIS-1.5 Use a Passive Asset Discovery Tool CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-15.7 Securely Decommission Service Providers CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-2.2 Ensure Authorized Software is Currently Supported CIS-4.6 Securely Manage Enterprise Assets and Software CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients 6.11.1 Security requirements of information systems 6.11.2 Security in development and support processes 6.12.2 Supplier service delivery management 6.9.6 Technical vulnerability management 7.4.5 PII de-identification and deletion at the end of processing 7.4.8 Disposal 8.4.2 Return, transfer or disposal of PII CM-12 Information Location (CM-12) CM-3 Configuration Change Control CM-8 System Component Inventory PE-16 Delivery and Removal SA-22 Unsupported System Components (SA-22) SA-3 System Development Life Cycle CM-12 Information Location (CM-12) CM-3 Configuration Change Control CM-8 System Component Inventory PE-16 Delivery and Removal SA-22 Unsupported System Components (SA-22) SA-3 System Development Life Cycle 5.22 Monitoring, review and change management of supplier services 5.9 Inventory of information and other associated assets 7.14 Secure disposal or re-use of equipment 8.25 Secure development life cycle 8.32 Change management 8.9 Configuration management PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition PR.IP-2 PR.IP-2: A System Development Life Cycle to manage systems is implemented PR.IP-6 PR.IP-6: Data is destroyed according to policy PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets is performed and logged in a timely manner, with approved and controlled tools PR.MA-2 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition PR.IP-2 PR.IP-2: A System Development Life Cycle to manage systems is implemented PR.IP-6 PR.IP-6: Data is destroyed according to policy PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools PR.MA-2 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access 12.3.4 12.3.4 Annual review of hardware and software technologies 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.2 6.3.2 Inventory of bespoke software and components 6.5.1 6.5.1 Change control procedure for production 5.9 Inventory of information and other associated assets 7.14 Secure disposal or re-use of equipment 8.25 Secure development life cycle 8.32 Change management 8.3 AI risk treatment A.4.5 System and computing resources A.6 AI system life cycle A.6.2.6 AI system operation and monitoring ISM-1549 Media management policy ISM-1550 IT equipment disposal processes and procedures ISM-1551 IT equipment management policy AUCDR-IS-3 Securely manage information assets over their lifecycle AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data SOC2-CC6.5 CC6.5 Protecting data on assets until disposal SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure E8-PATCHOS-ML1 Patch Operating Systems (ML1) ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems APPI-A22 Accuracy and Deletion of Personal Data CPS230-P25 Information and Technology Capability and Asset Health CPS234-21 Implementation of Information Security Controls AM-3 Ensure security of asset lifecycle management Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure 3.14.4e Refresh Systems and Components from a Trusted Baseline ID.AM-08 ID.AM-08 Life cycle management accounts for cybersecurity and keeps inventories current CE-SU.4 Remove Out-of-Support Software Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ID - Identify You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-08 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 111 it maps to, and the evidence behind each claim, over MCP and REST.