OT/ICS Standards Reference

Maintain an up-to-date inventory of IT and OT assets.

Reference details and direct document links for maintaining current inventories of IT and OT hardware, software, firmware, services, systems, and networked components.

4

Control / Question

Maintain an up-to-date inventory of IT and OT assets. OT system components can include PLCs, sensors, actuators, robots, machine tools, firmware, switches, routers, power supplies, and other connected components. IT components include hardware, software, cloud services, and digital assets.

C2M2 ASSET-1a (MIL1) NIST CSF ID.AM-01 NIST CSF ID.AM-02 NIST SP 800-82r3 ID.AM NIST SP 800-53 CM-8 ISA/IEC 62443-3-3 SR 1.2 ISA/IEC 62443-3-3 SR 7.8 ISA/IEC 62443-2-1 SPE-2, 7.2
DOE C2M2 v2.1

ASSET-1a — IT and OT Asset Inventory

Section 6.1, Asset, Change, and Configuration Management (ASSET), Objective 1

Relevant requirement: IT and OT assets that are important to the delivery of the function are inventoried, at least in an ad hoc manner.

This is the C2M2 baseline for establishing an inventory of important IT and OT assets supporting the function.
NIST Cybersecurity Framework 2.0

ID.AM-01 and ID.AM-02 — Hardware, Software, Services, and Systems Inventory

Appendix A, CSF Core, IDENTIFY Function

Relevant requirement: Inventories of hardware managed by the organization are maintained; inventories of software, services, and systems managed by the organization are maintained.

Use these outcomes to require current inventories of physical devices, software, services, and systems across IT and OT.
NIST SP 800-82 Rev. 3

ID.AM — OT Asset Management Guidance

Section 6.1.1, Asset Management (ID.AM)

Relevant requirement: Organizations should consider the criticality of a complete and accurate asset inventory for managing risk within the OT environment.

This adds OT-specific inventory expectations such as PLCs, sensors, actuators, firmware, network devices, and caution with active discovery methods.
NIST SP 800-53 Rev. 5

CM-8 — System Component Inventory

Configuration Management control family

Relevant requirement: Develop and document an inventory of system components that accurately reflects the system, includes all components, avoids duplicate accounting, provides adequate granularity, and is reviewed and updated.

Use this as the detailed inventory-control requirement for components, ownership, versions, addresses, location, supplier data, and update frequency.
ISA/IEC 62443-3-3

SR 1.2 and SR 7.8

System Security Requirements and Security Levels

Relevant requirement: SR 1.2 and SR 7.8 are cited as supporting references for system identification/account management and control-system backup/resource requirements.

Use the official ISA/IEC landing page as the authoritative document source; the standard itself is not freely downloadable from ISA/IEC.
ISA/IEC 62443-2-1

SPE-2, 7.2

Security Program Requirements for IACS Asset Owners

Relevant requirement: The cited section supports asset-owner security program expectations for defining and maintaining security-program elements.

Use the ISA/IEC 62443 series source as the authoritative pointer for 62443 program-level references.

Assessment focus