{
  "node_id": "cyber-nist-csf-2",
  "title": "Asset Management Strategy (NIST CSF 2.0 ID.AM)",
  "domain": "Cybersecurity",
  "version": "1.1.0",
  "last_updated": "2026-04-09",
  "bluf": "Effective governance over the enterprise environment necessitates a comprehensive asset management strategy grounded in the NIST Cybersecurity Framework 2.0 Identify function. This approach mandates the maintenance of detailed hardware and software inventories, achieving a minimum coverage threshold of 95 percent for each category, consistent with CIS Controls v8. To ensure inventory integrity, asset discovery scans must execute at a maximum frequency of every 24 hours, and automated CMDB synchronization is required. Security posture is reinforced by enabling unauthorized asset alerting, with a strict mandate to quarantine any discovered rogue device within 60 minutes. In alignment with ISO/IEC 27001:2022 principles, mandatory data classification tags are required for all assets, facilitating risk-based management and supporting GDPR Article 30 record-keeping obligations. All designated critical assets must undergo a formal review at a maximum interval of 30 days. The strategy addresses the full asset lifecycle by requiring end-of-life and end-of-support tracking. Adherence to SOC 2 criteria and modern security practices like those in PCI DSS v4.0 is achieved through enforced mobile device management, enabled shadow IT discovery, and continuous external attack surface mapping, ensuring all logical and physical components are identified and managed.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "cis-controls-v8",
    "iso-27001-2022",
    "nist-sp-1800-5-it-asset-management",
    "nist-sp-800-53-r5"
  ],
  "primary_citations_count": 7
}