{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Asset Management & Inventory","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-01","description":"Maintain a documented inventory of all hardware, software, systems, and services, recording owner, location, and the attributes needed for accountability and security management. Update the inventory as part of component installation, removal, and change, and reconcile it at least quarterly to correct discrepancies. Include every in-scope component so the inventory serves as the authoritative record of protected information assets for audit and compliance scoping.","details":{"control_category":"administrative","control_type":"preventive","domain":"Asset Management & Inventory","guidance":[],"members":[{"control_id":"CM-8","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"ID.AM-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"ID.AM-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.5.9","coverage":"partial","delta":"inventorying information (data) assets themselves, addressed by the data-inventory control","framework":"iso-27001","relationship":"intersects_with"},{"control_id":"CC6.1","coverage":"partial","delta":"logical access architecture and enforcement addressed by access-control domain","framework":"soc2","relationship":"intersects_with"}],"statement":"Maintain a documented inventory of all hardware, software, systems, and services, recording owner, location, and the attributes needed for accountability and security management. Update the inventory as part of component installation, removal, and change, and reconcile it at least quarterly to correct discrepancies. Include every in-scope component so the inventory serves as the authoritative record of protected information assets for audit and compliance scoping.","title":"Maintain a complete inventory of systems, hardware, and software","unified_id":"UC-ASSET-01"},"id":"uc:UC-ASSET-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-01","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1644cb8958d87e0106f61ca2526d59265c8bfb1eb90378b8069a3475939b0eab","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","targetId":"uc:UC-ASSET-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:190655334f229ff68cd5525575e230e8214aa1a2abca5bc4971dbb8e1d8d2337","properties":{"control_id":"ID.AM-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-am-01-b4536829.json","targetId":"ctrl:nist-csf-2:ID.AM-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20eeaaa70c3d13f426d734d1fd904439aac7d50aff227060a9c8f6190f54b204","properties":{"control_id":"CC6.1","coverage":"partial","delta":"logical access architecture and enforcement addressed by access-control domain","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-1-683a2035.json","targetId":"ctrl:soc2:CC6.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:232c97fa0350db0986af80588c18f037e25056fda721bcfbb8cbd1b766c8fd31","properties":{"rationale":"Quarterly software-inventory reconciliation surfaces unlicensed/unauthorized software for remediation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/risk-tech-unlicensed-counterfeit-software-91025350.json","targetId":"risk:tech-unlicensed-counterfeit-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:38f2240418a85fa85e465cfa80a9a20621aa60e298e83b828591f08d6222e288","properties":{"rationale":"Software-inventory reconciliation against the authorized baseline detects unmanaged/rogue software installs.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/risk-asset-uncontrolled-copying-removable-media-4a9604c7.json","targetId":"risk:asset-uncontrolled-copying-removable-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41a41b2054adcbbaa667bcebefeb8b8ac9db3a5154c6d5979cd79351ebd5b41f","properties":{"rationale":"Maintaining the authoritative hardware/software/system inventory directly closes the missing-inventory gap this risk describes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/risk-asset-inventory-gap-e18c7e73.json","targetId":"risk:asset-inventory-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:45668902a47978e7911b9bcee89a4a588d3547a521c994b99e84d0d3d8fd8e30","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","targetId":"uc:UC-ASSET-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9e5015e0fd8f4a77bdfbe124ba7c509b7a854b381d105d24827f409dd308a55","properties":{},"sourceDetailPath":"/data/v1/records/wf-c38-485b6728.json","sourceId":"wf:C38","targetDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","targetId":"uc:UC-ASSET-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aa4fbb706e03c3ce73014efdcc24cd6372a58b978b422e2294fd0c9a6872ff25","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","targetId":"uc:UC-ASSET-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:afd9bf57a64a2dd6b676a6c3493fb4212f1b30f880b3d3818c503295a85124f9","properties":{"rationale":"Periodic inventory reconciliation detects missing/stolen assets and scopes what data was exposed.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b2fe6fbb0f9ba05cafc352a7ca32815eb808077a8d882240112b7de99d99bd0f","properties":{"control_id":"PM-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-5-d6d87d75.json","targetId":"ctrl:nist-800-53:PM-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d0ea89650d6c0179809d1fef5a3584ceaeeee59d78450193d0b2c71a83fc4608","properties":{"control_id":"CM-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-8-d6b0ba27.json","targetId":"ctrl:nist-800-53:CM-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d53c701c43ab6a4b4b04a464375427c010fca2d05266dd96abac0fad6dbe248f","properties":{"rationale":"Member logical-access security over protected assets (SOC2 CC6.1) directly defends against credential-based account takeover.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/risk-fraud-external-c3ce412f.json","targetId":"risk:fraud-external","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e115412b6dbd6e8acfd6e03c6f5a8f3d855469e2439b614314f3c5731fa7e439","properties":{"control_id":"A.5.9","coverage":"partial","delta":"inventorying information (data) assets themselves, addressed by the data-inventory control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-9-64706ee7.json","targetId":"ctrl:iso-27001:A.5.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e8f7698c474b3564155f867b60178a9e822091b77a444708777b94a0a0943728","properties":{"control_id":"ID.AM-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-am-02-3ca090c1.json","targetId":"ctrl:nist-csf-2:ID.AM-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f464ca474e0bad6c4c103131d0eeeb2d81c8d3e7e453f1ba7f2a8d8bbd9231f5","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","targetId":"uc:UC-ASSET-01","type":"oversees"}],"schemaVersion":1}
