A.5.9 Organizational
Inventory of information and other associated assets
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CM-8mostlyaligns with — Both controls require maintaining an accurate, up-to-date inventory of organizational assets with assigned ownership and sufficient granularity to support security management.
- AC-2partialaligns with — Reassigning asset ownership when personnel change roles or leave supports the account management lifecycle and removal of unnecessary access.
- CM-2partialaligns with — The ISO requirement to keep asset inventories accurate and aligned with other inventories supports the maintenance of approved baseline configurations.
- CM-3partialaligns with — Requiring inventory updates when assets are installed, changed, or removed provides the visibility needed to control configuration changes.
- PM-5partialaligns with — Assigning ownership and maintaining asset inventories at an organizational level contributes to the system inventory used for security program management.
Aligned NIST CSF 2.0 outcomes (13)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-01mostlyaligns with — The ISO control's requirement to maintain accurate, up-to-date inventories of hardware and other assets directly supports the CSF outcome of keeping hardware inventories current.
- ID.AM-02mostlyaligns with — Requiring inventories of software, services, and systems to be maintained and kept consistent mirrors the CSF outcome for software and system inventories.
- ID.AM-05mostlyaligns with — Assigning ownership and classifying assets according to their importance provides the prioritization and criticality assessment the CSF outcome expects.
- ID.AM-08mostlyaligns with — The ISO control's emphasis on managing assets throughout their entire life cycle, including secure disposal and removal from inventory, fulfills the CSF outcome for life-cycle management.
- ID.AM-07partialaligns with — By requiring information assets to be inventoried and classified, the ISO control contributes to the CSF outcome of maintaining data inventories and associated metadata.
- ID.RA-05partialaligns with — The ISO control's requirement that asset owners participate in risk identification and management for their assets supports the CSF outcome of using asset information to inform risk response.
Related OWASP ASVS 5.0 requirements (8)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V15.1.2mostlyaligns with — Maintaining an accurate, up-to-date inventory of software components and their versions directly supports the ISO requirement to keep asset inventories current and consistent.
- V11.1.2partialaligns with — The ISO control's mandate to inventory cryptographic keys, algorithms, and certificates aligns with the ASVS requirement for a maintained cryptographic inventory.
- V13.1.4partialaligns with — Assigning ownership and tracking critical security secrets in the asset inventory corresponds to the ASVS requirement for documenting and rotating important secrets.
- V13.4.1partialaligns with — Including source-control metadata and other assets in the inventory helps ensure they are either removed or properly managed, aligning with the ASVS control on preventing unintended exposure of such metadata.
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialprevents — By requiring owners to classify assets and periodically review access restrictions, the control limits the likelihood that sensitive information will be exposed to unauthorized actors through misclassified or forgotten resources.
- CWE-552partialmitigates — Including asset location and ownership in the inventory, combined with secure disposal procedures, decreases the chance that files or directories remain accessible to external parties after they should have been removed or restricted.
- CWE-284nonemitigates — Assigning explicit owners and maintaining an accurate inventory of assets enables consistent enforcement of access restrictions that match asset classification, reducing the chance that sensitive resources remain accessible without proper authorization.
- CWE-668nonenone — Requiring owners to manage the full asset life cycle and remove assets from the inventory upon secure disposal helps prevent resources from being inadvertently exposed outside their intended security sphere.
- CWE-732nonenone — Asset owners are responsible for ensuring that permissions align with classification and are reviewed regularly, which reduces the probability that critical resources receive overly permissive default or inherited permissions.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — Maintaining an accurate, up-to-date inventory of software assets and their ownership enables organizations to detect unauthorized or misconfigured components before they are exploited.
- A03partialmitigates — Tracking every software component and its owner throughout the asset lifecycle reduces the chance that vulnerable or unapproved third-party code enters production undetected.
- A08nonemitigates — By requiring owners to verify that components supporting technology assets are listed and linked, the control helps ensure that integrity-critical dependencies are known and can be protected.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.