ID.AM-01 ID · Identify · ID.AM Asset Management

ID.AM-01 — Hardware inventory

Inventories of hardware managed by the organization are maintained.

Also written as ID-AM-01, ID.AM-1, CSF 2.0 ID.AM-01, NIST CSF ID.AM.

What NIST CSF ID.AM-01 means

ID.AM-01 is one of 21 subcategories in the Identify (ID) function, under the Asset Management category (ID.AM). The Core states: “Inventories of hardware managed by the organization are maintained.” Identify outcomes are prerequisites rather than protections — if the underlying inventory or risk analysis is incomplete, every downstream Protect and Detect outcome inherits that gap.

Evidence that supports ID.AM-01

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • Hardware asset inventory / CMDB with owners
  • Automated discovery tool output
  • Periodic inventory reconciliation records

How to implement ID.AM-01

  1. Discover automatically; do not surveyAsking teams what hardware they have produces an inventory of what people remember. Network discovery, endpoint agent reporting and cloud provider APIs produce one of what exists. The delta between the two is itself a useful finding.
  2. Define what counts as hardware in your contextCloud instances, containers running on managed nodes, mobile devices, contractor laptops and network appliances are all in scope for most organisations. A physical-server-only inventory is a 2005 answer to a 2026 outcome.
  3. Record an owner for every assetAn inventory without ownership cannot drive any downstream decision — who patches it, who approves its access, who decommissions it. Ownership is what makes the inventory operational rather than descriptive.
  4. Reconcile sources on a scheduleCompare discovery output against procurement records, MDM enrolment and the endpoint protection console. Each system knows about assets the others do not, and the reconciliation is where unmanaged devices surface.
  5. Close the loop with joiners and leaversDevice assignment and return should be part of the HR lifecycle. Unreturned hardware from leavers is both a common finding and a real risk, and it is invisible without this link.

Common assessment findings for ID.AM-01

What actually gets raised against ID.AM-01, in rough order of how often it comes up:

Assessing ID.AM-01 in a profile

ID.AM-01 is foundational — its completeness caps how well almost every Protect and Detect outcome can score, because you cannot protect or monitor what is not enumerated. If you assess only a handful of subcategories, assess this one first.

ISO 27001 mapping

ID.AM-01 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.9, A.7.9, A.8.1. Evidence collected for one framework typically supports the other.

Map ID.AM-01 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against ID.AM-01 in the Risk Register.

Other Asset Management subcategories

ID.AM-02 Software and service inventory ID.AM-03 Network communication and data flows ID.AM-04 Supplier-provided asset inventory ID.AM-05 Asset prioritization ID.AM-07 Data inventory and classification ID.AM-08 Asset lifecycle management

All 21 Identify subcategories →

Frequently asked questions

Is NIST CSF ID.AM-01 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. ID.AM-01 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is ID.AM-01 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns ID.AM-01?

The Identify function is normally owned by the security or IT function, but ID.AM-01 still needs a specific named owner. Assessors treat an outcome with no owner as not achieved regardless of the tooling behind it, so record ownership in your profile alongside the assessment.

Does NIST CSF ID.AM-01 map to ISO 27001?

Yes — ID.AM-01 corresponds to ISO 27001:2022 Annex A control(s) A.5.9, A.7.9, A.8.1. Evidence collected for one framework typically supports the other, so a single control library can serve both.

What are the most common audit findings for ID.AM-01?

Inventory maintained manually in a spreadsheet, last updated months ago and materially out of date. Cloud and container assets excluded because the inventory was designed around physical hardware.