Sekit CSF · Asset Management · Policy
RCF-0055CMDB quality
The company formally maintains a configuration management database as the authoritative source of asset information
Mapping at a glance
RCF-0055CMDB qualityAsset Management · Policy
A.5.9Inventory of information and other associated assetsISO/IEC 27001:2022 · Annex A controlsA.5.37Documented operating proceduresISO/IEC 27001:2022 · Annex A controlsID.AM-01Hardware inventory maintainedNIST CSF 2.0ID.AM-02Software inventory maintainedNIST CSF 2.0ID.AM-05Assets prioritized by criticalityNIST CSF 2.0
RCF-0055 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.9Inventory of information and other associated assetsenablesThis policy control designates a single authoritative source of asset and configuration information, the foundation an accurate inventory under A.5.9 is built on.A.5.37Documented operating proceduresenablesThis policy control designates a single authoritative source of asset and configuration information, the foundation operating procedures under A.5.37 reference when describing how systems are run.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.AM-01Hardware inventory maintainedID.AM-02Software inventory maintainedID.AM-05Assets prioritized by criticality
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Hardware asset inventory
The list of all the company's physical devices (computers, laptops, servers, phones, network gear) with who uses them and where they are.
From the Sekit evidence catalog
This topic through the other lenses
All Asset Management controls
Ask Sekura: “What evidence proves RCF-0055?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.