NIST CSF 2.0 · derived mapping target
ID.AM-08Assets managed through lifecycle
Manage systems, hardware, software, services, and data across their whole life, from acquisition to secure disposal, so nothing is forgotten and left exposed.
Mapping at a glance
ID.AM-08Assets managed through lifecycleNIST CSF 2.0
ID.AM-08 is covered by 9 Sekit CSF controls. +4 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0058Shadow IT discovery · PolicyRCF-0059Shadow IT discovery · ProcessRCF-0060Shadow IT discovery · TechnicalRCF-0127Dependency/SBOM management · PolicyRCF-0128Dependency/SBOM management · ProcessRCF-0129Dependency/SBOM management · TechnicalRCF-0328Software supply chain (SBOM) · PolicyRCF-0329Software supply chain (SBOM) · ProcessRCF-0330Software supply chain (SBOM) · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Hardware asset inventory
The list of all the company's physical devices (computers, laptops, servers, phones, network gear) with who uses them and where they are.
Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
Data retention and disposal procedure
The rules on how long data is kept and how it is securely destroyed when no longer needed.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves ID.AM-08?”
Also via MCP, free with account