NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-08: Systems, hardware, software, services, and data are managed throughout their life cycles

Systems, hardware, software, services, and data are managed throughout their life cycles

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 111 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 12 controls

CIS Controls v8 · 8 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

ISO 27701:2019 · 7 controls

  • 6.11.1 Security requirements of information systems
  • 6.11.2 Security in development and support processes
  • 6.12.2 Supplier service delivery management
  • 6.9.6 Technical vulnerability management
  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.8 Disposal
  • 8.4.2 Return, transfer or disposal of PII

FedRAMP High · 6 controls

  • CM-12 Information Location (CM-12)
  • CM-3 Configuration Change Control
  • CM-8 System Component Inventory
  • PE-16 Delivery and Removal
  • SA-22 Unsupported System Components (SA-22)
  • SA-3 System Development Life Cycle

FedRAMP Moderate · 6 controls

  • CM-12 Information Location (CM-12)
  • CM-3 Configuration Change Control
  • CM-8 System Component Inventory
  • PE-16 Delivery and Removal
  • SA-22 Unsupported System Components (SA-22)
  • SA-3 System Development Life Cycle

ISO 27001:2022 · 6 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.9 Inventory of information and other associated assets
  • 7.14 Secure disposal or re-use of equipment
  • 8.25 Secure development life cycle
  • 8.32 Change management
  • 8.9 Configuration management
  • PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition
  • PR.IP-2 PR.IP-2: A System Development Life Cycle to manage systems is implemented
  • PR.IP-6 PR.IP-6: Data is destroyed according to policy
  • PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets is performed and logged in a timely manner, with approved and controlled tools
  • PR.MA-2 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access
  • PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition
  • PR.IP-2 PR.IP-2: A System Development Life Cycle to manage systems is implemented
  • PR.IP-6 PR.IP-6: Data is destroyed according to policy
  • PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools
  • PR.MA-2 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access

PCI DSS 4.0 · 5 controls

  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.5.1 6.5.1 Change control procedure for production

CMMC 2.0 · 4 controls

ISO 27002:2022 · 4 controls

  • 5.9 Inventory of information and other associated assets
  • 7.14 Secure disposal or re-use of equipment
  • 8.25 Secure development life cycle
  • 8.32 Change management

ISO/IEC 42001:2023 · 4 controls

  • 8.3 AI risk treatment
  • A.4.5 System and computing resources
  • A.6 AI system life cycle
  • A.6.2.6 AI system operation and monitoring
  • ISM-1549 Media management policy
  • ISM-1550 IT equipment disposal processes and procedures
  • ISM-1551 IT equipment management policy

NIST SP 800-161 Rev 1 · 3 controls

  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

C5 (Germany) · 2 controls

HIPAA Security Rule · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems

APPI · 1 control

  • APPI-A22 Accuracy and Deletion of Personal Data
  • CPS230-P25 Information and Technology Capability and Asset Health

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls
  • AM-3 Ensure security of asset lifecycle management

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

NIST SP 800-172 · 1 control

  • 3.14.4e Refresh Systems and Components from a Trusted Baseline
  • ID.AM-08 ID.AM-08 Life cycle management accounts for cybersecurity and keeps inventories current

UK Cyber Essentials · 1 control

  • CE-SU.4 Remove Out-of-Support Software

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.AM-08 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 111 it maps to, and the evidence behind each claim, over MCP and REST.