Skip to main content
AST

Asset Management

64 controls

Manage Technology Assets, Applications and Services (TAAS) throughout their lifecycle to maintain visibility, accountability, authorization and protection.

SCF # Control Name Weight NIST CSF Frameworks
AST-01 Asset Management Policy 10 — Critical Govern 6
AST-02 Asset Governance 10 — Critical Govern 87
AST-03 Standardized Naming Convention 5 — Medium Identify 3
AST-04 Asset Inventories 10 — Critical Identify 122
AST-04.1 Updates During Installations / Removals 7 — High Identify 34
AST-04.2 Component Duplication Avoidance 2 — Low Identify 35
AST-05 Identify Critical Assets 9 — Critical Recover 62
AST-05.1 Technology Assets, Applications, Services and/or Data (TAASD) Criticality Ratings 8 — High Recover 7
AST-06 Asset-Service Dependencies 5 — Medium Identify 42
AST-07 Stakeholder Identification & Involvement 5 — Medium Identify 31
AST-07.1 Technology Assets, Applications, Services and/or Data (TAASD) Ownership Assignment 8 — High Identify 45
AST-07.2 Accountability Information 5 — Medium Identify 26
AST-08 Comprehensive Asset Inventory Management 8 — High Identify 23
AST-08.1 Configuration Management Database (CMDB) 5 — Medium Identify 49
AST-08.2 Component Assignment 3 — Low Identify 5
AST-09 Asset Discovery 8 — High Identify 14
AST-09.1 Dynamic Host Configuration Protocol (DHCP) Server Logging 3 — Low Identify 5
AST-09.2 Automated Network Asset Discovery 3 — Low Protect 2
AST-09.3 Automated Location Tracking 5 — Medium Identify 7
AST-10 Approved Technologies 7 — High Identify 14
AST-10.1 Authorized To Connect 6 — Medium Identify 2
AST-11 Automated Unauthorized Component Detection 3 — Low Detect 31
AST-12 Prohibited Technology Assets, Applications and/or Services (TAAS) 9 — Critical Protect 6
AST-13 Software Licensing Restrictions 8 — High Identify 19
AST-14 Provenance 8 — High Identify 21
AST-15 Asset Categorization 9 — Critical Identify 9
AST-15.1 High-Risk Technology Assets, Applications and/or Services (TAAS) Categorization 9 — Critical Protect 2
AST-15.2 Categorize Artificial Intelligence (AI)-Related Technology Assets, Applications and/or Services (TAAS) 9 — Critical Identify 2
AST-15.3 Asset Attributes 5 — Medium Protect 1
AST-16 Asset Scope Classification 8 — High Identify 60
AST-16.1 Compliance-Specific Asset Identification 6 — Medium Identify 9
AST-17 Network Diagrams & Data Flow Diagrams (DFDs) 10 — Critical Identify 89
AST-17.1 Control Applicability Boundary Graphical Representation 6 — Medium Identify 14
AST-17.2 Data Action Mapping 9 — Critical Identify 26
AST-18 Security of Assets & Media 8 — High Identify 23
AST-18.1 Management Approval For External Media Transfer 8 — High Protect 13
AST-19 Technology Assets, Applications, Services and/or Data (TAASD) Storage 8 — High Protect 1
AST-19.1 Temporary Asset Storage In Automobiles 7 — High Protect 0
AST-20 Unattended End-User Equipment 9 — Critical Protect 16
AST-21 Kiosks & Point of Interaction (PoI) Devices 8 — High Protect 14
AST-22 Secure Disposal, Destruction or Re-Use of Equipment 10 — Critical Identify 74
AST-23 Return of Assets 8 — High Protect 11
AST-24 Removal of Assets 8 — High Protect 10
AST-25 Use of Personal Devices 10 — Critical Protect 7
AST-26 Use of Third-Party Devices 9 — Critical Protect 5
AST-27 Bring Your Own Device (BYOD) Usage 10 — Critical Identify 18
AST-28 Usage Parameters 7 — High Identify 9
AST-29 Technology Asset Inspections 6 — Medium Detect 30
AST-29.1 Physical Tampering Detection 9 — Critical Detect 18
AST-29.2 Logical Tampering Protection 6 — Medium Protect 27
AST-30 Roots of Trust Protection 4 — Medium Protect 6
AST-31 Telecommunications Equipment 9 — Critical Protect 3
AST-32 Travel-Only Devices 8 — High Protect 4
AST-33 Re-Imaging Devices After Travel 8 — High Protect 4
AST-34 Jump Server 7 — High Protect 9
AST-35 Database Management System (DBMS) 6 — Medium Protect 4
AST-36 Decommissioning 4 — Medium Protect 9
AST-37 Technology Lifecycle Management 7 — High Protect 60
AST-37.1 Stable Versions 8 — High Identify 16
AST-37.2 Removal of Previous Versions 5 — Medium Protect 5
AST-38 Technical Debt Reviews 9 — Critical Protect 9
AST-39 Unsupported Technology Assets, Applications and/or Services (TAAS) 10 — Critical Protect 59
AST-39.1 Alternate Sources for Continued Support 8 — High Protect 31
AST-40 Predictable Failure Analysis 5 — Medium Protect 12

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.