Sekit CSF · Family
Asset Management
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0055CMDB qualityno mappings yetThe company formally maintains a configuration management database as the authoritative source of asset informationRCF-0052Criticality taggingno mappings yetAll assets are formally required to be rated by their importance to business operationsRCF-0043Data inventoryno mappings yetAll personal and sensitive data held by the company is formally required to be identified and recordedRCF-0037Hardware inventoryno mappings yetAll physical devices used by the company are formally required to be recorded and trackedRCF-0049Ownership & custodiansno mappings yetFormal ownership and responsibility is assigned to all significant assets within the companyRCF-0046Service inventoryno mappings yetAll internal and external services the company depends on are formally required to be recordedRCF-0058Shadow IT discoveryno mappings yetThe company formally prohibits the use of unapproved applications and servicesRCF-0040Software inventoryno mappings yetAll software installed or used within the company is formally required to be recorded and licensed
Process
RCF-0056CMDB qualityno mappings yetThe CMDB is consistently updated to reflect changes to assets, configurations and relationshipsRCF-0053Criticality taggingno mappings yetCriticality ratings are consistently applied and updated when assets or business priorities changeRCF-0044Data inventoryno mappings yetData assets are consistently inventoried and the record is kept current as data flows changeRCF-0038Hardware inventoryno mappings yetHardware assets are consistently recorded when purchased, modified or decommissionedRCF-0050Ownership & custodiansno mappings yetAsset owners consistently review and confirm the security status of assets under their responsibilityRCF-0047Service inventoryno mappings yetService dependencies are consistently documented and reviewed for security and availability riskRCF-0059Shadow IT discoveryno mappings yetUnapproved technology is consistently identified and brought into the approved inventory or removedRCF-0041Software inventoryno mappings yetSoftware assets are consistently tracked, licensed and removed when no longer needed
Technical
RCF-0057CMDB qualityno mappings yetTechnical integrations automatically synchronise the CMDB with actual infrastructure and system stateRCF-0054Criticality taggingno mappings yetTechnical tools tag assets with criticality ratings and prioritise alerts and remediation accordinglyRCF-0045Data inventoryno mappings yetTechnical tools automatically discover and classify sensitive data across systems and storage locationsRCF-0039Hardware inventoryno mappings yetTechnical tools automatically discover and maintain an up-to-date inventory of hardware devicesRCF-0051Ownership & custodiansno mappings yetTechnical systems record asset ownership and route security alerts to the appropriate ownerRCF-0048Service inventoryno mappings yetTechnical tools automatically map and monitor service dependencies and their security statusRCF-0060Shadow IT discoveryno mappings yetTechnical tools continuously scan for unauthorised devices, applications and cloud servicesRCF-0042Software inventoryno mappings yetTechnical tools automatically discover installed software and flag unlicensed or unexpected applications
Ask Sekura: “What evidence proves Asset Management?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.