Sekit CSF · Family
Asset Management
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0055CMDB quality5 mappingsThe company formally maintains a configuration management database as the authoritative source of asset informationRCF-0052Criticality tagging4 mappingsAll assets are formally required to be rated by their importance to business operationsRCF-0043Data inventory9 mappingsAll personal and sensitive data held by the company is formally required to be identified and recordedRCF-0037Hardware inventory4 mappingsAll physical devices used by the company are formally required to be recorded and trackedRCF-0049Ownership & custodians5 mappingsFormal ownership and responsibility is assigned to all significant assets within the companyRCF-0046Service inventory5 mappingsAll internal and external services the company depends on are formally required to be recordedRCF-0058Shadow IT discovery5 mappingsThe company formally prohibits the use of unapproved applications and servicesRCF-0040Software inventory6 mappingsAll software installed or used within the company is formally required to be recorded and licensed
Process
RCF-0056CMDB quality5 mappingsThe CMDB is consistently updated to reflect changes to assets, configurations and relationshipsRCF-0053Criticality tagging4 mappingsCriticality ratings are consistently applied and updated when assets or business priorities changeRCF-0044Data inventory8 mappingsData assets are consistently inventoried and the record is kept current as data flows changeRCF-0038Hardware inventory4 mappingsHardware assets are consistently recorded when purchased, modified or decommissionedRCF-0050Ownership & custodians6 mappingsAsset owners consistently review and confirm the security status of assets under their responsibilityRCF-0047Service inventory6 mappingsService dependencies are consistently documented and reviewed for security and availability riskRCF-0059Shadow IT discovery6 mappingsUnapproved technology is consistently identified and brought into the approved inventory or removedRCF-0041Software inventory8 mappingsSoftware assets are consistently tracked, licensed and removed when no longer needed
Technical
RCF-0057CMDB quality6 mappingsTechnical integrations automatically synchronise the CMDB with actual infrastructure and system stateRCF-0054Criticality tagging5 mappingsTechnical tools tag assets with criticality ratings and prioritise alerts and remediation accordinglyRCF-0045Data inventory6 mappingsTechnical tools automatically discover and classify sensitive data across systems and storage locationsRCF-0039Hardware inventory4 mappingsTechnical tools automatically discover and maintain an up-to-date inventory of hardware devicesRCF-0051Ownership & custodians6 mappingsTechnical systems record asset ownership and route security alerts to the appropriate ownerRCF-0048Service inventory5 mappingsTechnical tools automatically map and monitor service dependencies and their security statusRCF-0060Shadow IT discovery8 mappingsTechnical tools continuously scan for unauthorised devices, applications and cloud servicesRCF-0042Software inventory7 mappingsTechnical tools automatically discover installed software and flag unlicensed or unexpected applications
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in ISO/IEC 42001:2023 — Annex A
This family in Cyber Essentials
Ask Sekura: “What evidence proves Asset Management?”
Also via MCP, free with account