Sekit CSF · Asset Management · Policy
RCF-0043Data inventory
All personal and sensitive data held by the company is formally required to be identified and recorded
Mapping at a glance
RCF-0043Data inventoryAsset Management · Policy
A.5.9Inventory of information and other associated assetsISO/IEC 27001:2022A.5.12Classification of informationISO/IEC 27001:2022A.5.34Privacy and protection of personal identifiable information (PII)ISO/IEC 27001:2022ID.AM-03Network data flows mappedNIST CSF 2.0ID.AM-05Assets prioritized by criticalityNIST CSF 2.0
RCF-0043 maps to 9 controls across the published frameworks. +4 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.9Inventory of information and other associated assetssupportsThis policy control requires all personal and sensitive data to be identified and recorded with location and owner, covering the data slice of A.5.9's asset inventory.A.5.12Classification of informationenablesKnowing where personal and sensitive data lives is a precondition for classifying it correctly, making the data inventory a foundation A.5.12's classification scheme depends on.A.5.34Privacy and protection of personal identifiable information (PII)enablesRequiring that all personal and sensitive data be identified, located and owned gives a privacy program the starting inventory this control depends on.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
ID.AM-03Network data flows mappedID.AM-05Assets prioritized by criticalityID.AM-07Data inventory maintained
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
A.4.3Data resourcessupportsRCF-0043 requires personal and sensitive data to be identified and recorded with an owner; A.4.3 needs that identification applied to AI training and grounding datasets specifically, adding licence and quality fields the general control does not track.A.7.2Data for development and enhancement of AI systemsupportsRCF-0043 requires personal and sensitive data to be identified and recorded, which covers the source data, but says nothing about the separate question of permitted AI use once that data is repurposed for training.A.7.5Data provenancesupportsRCF-0043 requires personal and sensitive data to be identified and recorded with an owner, which gives provenance tracking a starting inventory, but it stops at the first system, not the chain of transformations an AI dataset goes through.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Data inventory and classification
The record of the personal and sensitive data the company holds, where it lives and how it is classified by sensitivity.
From the Sekit evidence catalog
This topic through the other lenses
All Asset Management controls
Ask Sekura: “What evidence proves RCF-0043?”
Also via MCP, free with account