Controls

Terug naar overzicht
Version

SB.1.004 Asset inventory

Asset Management
Low
Low
Low
Organisation
v2.0 (Q1 2024)

Organisations maintain an accurate and up-to-date registry of organisational hardware and software assets in a Configuration Management Database (CMDB).

Specification

Organizationally owned assets are registered with their relevant attributes, lifecycle status, an asset owner and a classification of the information asset. At a minimum the following hardware and software assets used in the processing of information are registered:

• portable and fixed processing units
• network equipment
• user accounts
• operating systems
• packaging and administration software
• business applications (including licenses to SaaS applications)
• certificates and keys
• suppliers
• physical locations relevant to the IT services (including datacentres)

ISO 27001 & 27002:2022

A5.9,
A8.1.1
A8.1.2
A8.9,
A8.19,
A8.32

SURF toetsingskader informatiebeveiliging (NBA-volwassenheidsmodel)

CO.01 Identificatie en onderhoud van configuratie-items