Skip to main content

πŸ’Ό ID.AM-04: Inventories of services provided by suppliers are maintained

  • Contextual name: πŸ’Ό ID.AM-04: Inventories of services provided by suppliers are maintained
  • ID: /frameworks/nist-csf-v2.0/id-am/04
  • Located in: πŸ’Ό Asset Management (ID.AM)

Description​

  1. Inventory all external services used by the organization, including third-party infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS) offerings; APIs; and other externally hosted application services
  2. Update the inventory when a new external service is going to be utilized to ensure adequate cybersecurity risk management monitoring of the organization's use of that service

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-am/04
    • /frameworks/nist-sp-800-53-r5/ac/20
    • /frameworks/nist-sp-800-53-r5/sa/09
    • /frameworks/nist-sp-800-53-r5/sr/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.AM-4: External information systems are catalogued
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AC-20 Use of External Systems5
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SA-9 External System Services811
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags