Sekit CSF · Familia
Asset Management
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0055CMDB quality5 mapeosThe company formally maintains a configuration management database as the authoritative source of asset informationRCF-0052Criticality tagging4 mapeosAll assets are formally required to be rated by their importance to business operationsRCF-0043Data inventory9 mapeosAll personal and sensitive data held by the company is formally required to be identified and recordedRCF-0037Hardware inventory4 mapeosAll physical devices used by the company are formally required to be recorded and trackedRCF-0049Ownership & custodians5 mapeosFormal ownership and responsibility is assigned to all significant assets within the companyRCF-0046Service inventory5 mapeosAll internal and external services the company depends on are formally required to be recordedRCF-0058Shadow IT discovery5 mapeosThe company formally prohibits the use of unapproved applications and servicesRCF-0040Software inventory6 mapeosAll software installed or used within the company is formally required to be recorded and licensed
Proceso
RCF-0056CMDB quality5 mapeosThe CMDB is consistently updated to reflect changes to assets, configurations and relationshipsRCF-0053Criticality tagging4 mapeosCriticality ratings are consistently applied and updated when assets or business priorities changeRCF-0044Data inventory8 mapeosData assets are consistently inventoried and the record is kept current as data flows changeRCF-0038Hardware inventory4 mapeosHardware assets are consistently recorded when purchased, modified or decommissionedRCF-0050Ownership & custodians6 mapeosAsset owners consistently review and confirm the security status of assets under their responsibilityRCF-0047Service inventory6 mapeosService dependencies are consistently documented and reviewed for security and availability riskRCF-0059Shadow IT discovery6 mapeosUnapproved technology is consistently identified and brought into the approved inventory or removedRCF-0041Software inventory8 mapeosSoftware assets are consistently tracked, licensed and removed when no longer needed
Técnica
RCF-0057CMDB quality6 mapeosTechnical integrations automatically synchronise the CMDB with actual infrastructure and system stateRCF-0054Criticality tagging5 mapeosTechnical tools tag assets with criticality ratings and prioritise alerts and remediation accordinglyRCF-0045Data inventory6 mapeosTechnical tools automatically discover and classify sensitive data across systems and storage locationsRCF-0039Hardware inventory4 mapeosTechnical tools automatically discover and maintain an up-to-date inventory of hardware devicesRCF-0051Ownership & custodians6 mapeosTechnical systems record asset ownership and route security alerts to the appropriate ownerRCF-0048Service inventory5 mapeosTechnical tools automatically map and monitor service dependencies and their security statusRCF-0060Shadow IT discovery8 mapeosTechnical tools continuously scan for unauthorised devices, applications and cloud servicesRCF-0042Software inventory7 mapeosTechnical tools automatically discover installed software and flag unlicensed or unexpected applications
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en ISO/IEC 42001:2023 — Annex A
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra Asset Management?»
También vía MCP, gratis con cuenta