NIST CSF 2.0 · derived mapping target
ID.AM-02Software inventory maintained
Maintain a current inventory of the software, services, and systems you run. Knowing what is installed is the first step to keeping it patched and authorized.
Mapping at a glance
ID.AM-02Software inventory maintainedNIST CSF 2.0
ID.AM-02 is covered by 15 Sekit CSF controls. +10 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0037Hardware inventory · PolicyRCF-0038Hardware inventory · ProcessRCF-0039Hardware inventory · TechnicalRCF-0040Software inventory · PolicyRCF-0041Software inventory · ProcessRCF-0042Software inventory · TechnicalRCF-0049Ownership & custodians · PolicyRCF-0050Ownership & custodians · ProcessRCF-0051Ownership & custodians · TechnicalRCF-0055CMDB quality · PolicyRCF-0056CMDB quality · ProcessRCF-0057CMDB quality · TechnicalRCF-0058Shadow IT discovery · PolicyRCF-0059Shadow IT discovery · ProcessRCF-0060Shadow IT discovery · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves ID.AM-02?”
Also via MCP, free with account