SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.9Inventory of information and other associated assets

Keep an up-to-date inventory of your information and the assets that handle it, each with a named owner. You cannot protect what you have not catalogued.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0037Hardware inventory · PolicysupportsThis policy control requires every company device to be registered in a single inventory from purchase to disposal, covering the hardware slice of the asset inventory A.5.9 requires.RCF-0038Hardware inventory · ProcesssupportsThis process control keeps the hardware register current by recording every purchase, reassignment and disposal as it happens, the operational upkeep A.5.9 expects of an asset inventory.RCF-0039Hardware inventory · TechnicalsupportsThis technical control uses automated discovery such as MDM or network scanning to surface devices the manual register misses, keeping the hardware inventory A.5.9 requires honest.RCF-0040Software inventory · PolicysupportsThis policy control requires all software and SaaS in business use to be recorded and licensed, covering the software slice of A.5.9's asset inventory.RCF-0041Software inventory · ProcesssupportsThis process control maintains a live register of installed software and SaaS with licence status and owner, the ongoing upkeep A.5.9 expects.RCF-0042Software inventory · TechnicalsupportsThis technical control automatically reports installed software across endpoints and flags unlicensed or unexpected applications, keeping the software inventory current for A.5.9.RCF-0043Data inventory · PolicysupportsThis policy control requires all personal and sensitive data to be identified and recorded with location and owner, covering the data slice of A.5.9's asset inventory.RCF-0044Data inventory · ProcesssupportsThis process control keeps the data map current as data flows change, the ongoing accuracy A.5.9 requires of an information inventory.RCF-0045Data inventory · TechnicalsupportsThis technical control uses automated discovery to find sensitive data in unexpected places, keeping the data inventory A.5.9 requires grounded in reality.RCF-0046Service inventory · PolicysupportsThis policy control requires every service the business depends on to be recorded with owner and criticality, extending A.5.9's inventory scope beyond hardware and software to services.RCF-0047Service inventory · ProcesssupportsThis process control maintains a current register of service dependencies with owner and criticality, reviewed for single points of failure, the currency A.5.9 expects.RCF-0048Service inventory · TechnicalsupportsThis technical control monitors availability and security posture of critical external services, keeping the service inventory A.5.9 requires connected to live status.RCF-0049Ownership & custodians · PolicysupportsThis policy control names an accountable owner for every significant asset in an approved document, giving A.5.9's inventory of information and assets the ownership attribute it requires alongside the inventory itself.RCF-0050Ownership & custodians · ProcesssupportsThis process control has each asset owner periodically confirm assets they own are still needed and correctly inventoried, the review cycle A.5.9 expects.RCF-0051Ownership & custodians · TechnicalsupportsThis technical control records asset ownership as structured metadata so alerts reach the right owner automatically, operationalising the ownership A.5.9 requires.RCF-0052Criticality tagging · PolicysupportsThis policy control requires every asset to receive a business-criticality rating on a defined scale, an attribute A.5.9 expects the asset inventory to carry.RCF-0053Criticality tagging · ProcesssupportsThis process control applies and updates criticality ratings as part of routine inventory upkeep, keeping that attribute current for A.5.9.RCF-0054Criticality tagging · TechnicalsupportsThis technical control tags assets with criticality in security and IT tooling to prioritise remediation, putting the criticality A.5.9 requires to practical use.RCF-0055CMDB quality · PolicyenablesThis policy control designates a single authoritative source of asset and configuration information, the foundation an accurate inventory under A.5.9 is built on.RCF-0056CMDB quality · ProcesssupportsThis process control updates the authoritative asset repository as a routine part of every change, keeping the CMDB accuracy A.5.9 requires.RCF-0057CMDB quality · TechnicalsupportsThis technical control connects discovery tooling to the authoritative asset repository so records synchronise automatically with reality, reinforcing A.5.9's currency requirement.RCF-0059Shadow IT discovery · ProcesssupportsThis process control regularly looks for unapproved technology and either formally adopts or retires it, closing the gap A.5.9's inventory would otherwise miss.RCF-0060Shadow IT discovery · TechnicalsupportsThis technical control continuously scans for unauthorised devices, applications and cloud services, catching what a manual A.5.9 inventory alone would not.RCF-0106Data minimization · PolicyrelatedThis policy control commits to collecting and keeping only the personal data needed, a data-minimisation objective distinct from but backed by the same inventory A.5.9 requires.RCF-0107Data minimization · ProcesssupportsThis process control reviews the data inventory on a fixed cycle, deleting or flagging data with no remaining purpose, the currency check A.5.9 expects of a data inventory.RCF-0108Data minimization · TechnicalsupportsThis technical control uses automated discovery to locate sensitive data across storage, grounding the inventory A.5.9 requires in what systems hold.RCF-0127Dependency/SBOM management · PolicysupportsThis policy control mandates that every third-party component in company applications is inventoried, extending A.5.9's asset inventory into software dependencies.RCF-0128Dependency/SBOM management · ProcesssupportsThis process control keeps a current bill of materials per application reviewed against known vulnerabilities, the software-composition layer of A.5.9's inventory requirement.RCF-0233Exposure management · ProcessrelatedThis process control keeps an accurate inventory of internet-facing assets and reduces unjustified exposure, a security-driven use of the same asset inventory A.5.9 requires.RCF-0328Software supply chain (SBOM) · PolicysupportsThis policy control states that software components the company depends on are inventoried to manage third-party risk, matching A.5.9's asset inventory scope.RCF-0418OT asset inventory · PolicysupportsThis policy control requires every OT and ICS device to be identified and recorded in an inventory, extending A.5.9's requirement into operational technology.RCF-0419OT asset inventory · ProcesssupportsThis process control maintains a current OT and ICS inventory and records every environment change, the ongoing accuracy A.5.9 expects in an operational technology context.RCF-0420OT asset inventory · TechnicalsupportsThis technical control uses passive discovery to learn the OT device population from network traffic without disrupting equipment, keeping that inventory current for A.5.9.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Hardware asset inventory
The list of all the company's physical devices (computers, laptops, servers, phones, network gear) with who uses them and where they are.
Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
Data inventory and classification
The record of the personal and sensitive data the company holds, where it lives and how it is classified by sensitivity.
From the Sekit evidence catalog

In practice

In practice this control lives or dies on reconciliation: a spreadsheet listing devices is easy to write and equally easy to let go stale the moment someone buys a new laptop off the books. Auditors ask for the hardware, software and data inventories together and then spot-check them against reality, such as pulling one device from MDM and confirming it appears in the register with a named owner. The common failure mode is a hardware asset inventory that was accurate at creation but has not been reconciled against actual purchases, transfers or disposals in months.

Common gaps

The hardware asset inventory was built once during a project kickoff and has not been reconciled against actual purchases or disposals since.
Software and SaaS in daily use were never approved or added to the inventory, so licence exposure and shadow IT go unnoticed.
Assets appear in the inventory without a named owner, so security alerts about them have nowhere specific to land.

Questions your auditor will ask

Can you show me a current inventory of company hardware, software and data?
The hardware asset inventory, software and SaaS inventory, and data inventory and classification records, each with an owner and last-updated date.
Does every significant asset have a named owner?
Ownership is recorded as structured metadata in the inventory so that alerts and reviews route to a specific accountable person, not a department.
How do you catch devices or software that were never officially approved?
Automated discovery, such as MDM enrolment or network scanning, and periodic shadow IT reviews surface unapproved technology so it can be adopted or removed.
How is asset criticality determined and used?
Each asset carries a criticality rating on a defined scale, and security and IT tooling use that rating to prioritise alert handling and patching.

Where regulation demands it

NIS2 12.4 requires an asset inventory directly, the requirement A.5.9's hardware, software and data registers exist to satisfy.
ENS op.exp.1 requires an inventario de activos, the same asset inventory obligation A.5.9 sets out.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.9?”
Also via MCP, free with account