unified
UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
Maintain a documented inventory of all hardware, software, systems, and services, recording owner, location, and the attributes needed for accountability and security management. Update the inventory as part of component installation, removal, and change, and reconcile it at least quarterly to correct discrepancies. Include every in-scope component so the inventory serves as the authoritative record of protected information assets for audit and compliance scoping.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Asset Management & Inventory
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-ASSET-01
- title
- Maintain a complete inventory of systems, hardware, and software
- statement
- Maintain a documented inventory of all hardware, software, systems, and services, recording owner, location, and the attributes needed for accountability and security management. Update the inventory as part of component installation, removal, and change, and reconcile it at least quarterly to correct discrepancies. Include every in-scope component so the inventory serves as the authoritative record of protected information assets for audit and compliance scoping.
- domain
- Asset Management & Inventory
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CM-8
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.AM-01
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.AM-02
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.9
- coverage
- partial
- delta
- inventorying information (data) assets themselves, addressed by the data-inventory control
- relationship
- intersects_with
- framework
- soc2
- control_id
- CC6.1
- coverage
- partial
- delta
- logical access architecture and enforcement addressed by access-control domain
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software maps_to ID.AM-01 — Asset Management: Inventories of hardware managed by the organization are maintained
- framework
- nist-csf-2
- control_id
- ID.AM-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software maps_to CC6.1 — The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.
- framework
- soc2
- control_id
- CC6.1
- coverage
- partial
- delta
- logical access architecture and enforcement addressed by access-control domain
- relationship
- intersects_with
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software mitigates Use of unlicensed, counterfeit or pirated software
- strength
- related
- rationale
- Quarterly software-inventory reconciliation surfaces unlicensed/unauthorized software for remediation.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software mitigates Uncontrolled copying to removable media / unmanaged software installs
- strength
- related
- rationale
- Software-inventory reconciliation against the authorized baseline detects unmanaged/rogue software installs.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software mitigates Incomplete asset inventory and classification
- strength
- primary
- rationale
- Maintaining the authoritative hardware/software/system inventory directly closes the missing-inventory gap this risk describes.
- SOC 2 Trust Services Readiness tests UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
- IT Asset Inventory & Classification Upkeep operates UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software mitigates Theft of equipment, media or unattended devices
- strength
- related
- rationale
- Periodic inventory reconciliation detects missing/stolen assets and scopes what data was exposed.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software maps_to PM-5 — System Inventory
- framework
- nist-800-53
- control_id
- PM-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software maps_to CM-8 — System Component Inventory
- framework
- nist-800-53
- control_id
- CM-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- primary
- rationale
- Member logical-access security over protected assets (SOC2 CC6.1) directly defends against credential-based account takeover.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software maps_to A.5.9 — Inventory of information and other associated assets
- framework
- iso-27001
- control_id
- A.5.9
- coverage
- partial
- delta
- inventorying information (data) assets themselves, addressed by the data-inventory control
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software maps_to ID.AM-02 — Asset Management: Inventories of software, services, and systems managed by the organization are maintained
- framework
- nist-csf-2
- control_id
- ID.AM-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software