SCF - AST-02 - Asset Inventories
Mechanisms exist to perform inventories of technology assets that:
- Accurately reflects the current systems, applications and services in use;
- Identifies authorized software products, including business justification details;
- Is at the level of granularity deemed necessary for tracking and reporting;
- Includes organization-defined information deemed necessary to achieve effective property accountability; and
- Is available for review and audit by designated organizational personnel.
Mapped framework controls
ISO 27002
- A.5.9
NIST 800-53
Control questions
Does the organization perform inventories of technology assets that:
- Accurately reflects the current systems, applications and services in use;
- Identifies authorized software products, including business justification details;
- Is at the level of granularity deemed necessary for tracking and reporting;
- Includes organization-defined information deemed necessary to achieve effective property accountability; and
- Is available for review and audit by designated organizational personnel?