Skip to main content

πŸ’Ό ID.AM-02: Inventories of software, services, and systems managed by the organization are maintained

  • Contextual name: πŸ’Ό ID.AM-02: Inventories of software, services, and systems managed by the organization are maintained
  • ID: /frameworks/nist-csf-v2.0/id-am/02
  • Located in: πŸ’Ό Asset Management (ID.AM)

Description​

  1. Maintain inventories for all types of software and services, including commercial-off-the-shelf, open-source, custom applications, API services, and cloud-based applications and services
  2. Constantly monitor all platforms, including containers and virtual machines, for software and service inventory changes
  3. Maintain an inventory of the organization's systems

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-am/02
    • /frameworks/nist-sp-800-53-r5/ac/20
    • /frameworks/nist-sp-800-53-r5/cm/08
    • /frameworks/nist-sp-800-53-r5/pm/05
    • /frameworks/nist-sp-800-53-r5/sa/05
    • /frameworks/nist-sp-800-53-r5/sa/09

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.AM-2: Software platforms and applications within the organization are inventoried46
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AC-20 Use of External Systems5
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-8 System Component Inventory91
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-5 System Inventory1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SA-5 System Documentation5
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SA-9 External System Services811

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (7)​

PolicyLogic CountFlags
πŸ“ AWS Account Config is not enabled in all regions 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS RDS Instance Auto Minor Version Upgrade is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ Azure App Service does not run the latest Java version 🟒🟒 x3
πŸ“ Azure App Service does not run the latest PHP version 🟒🟒 x3
πŸ“ Azure App Service does not run the latest Python version 🟒🟒 x3