# PM-05 System Inventory

NIST SP 800-53 control. Family: PM Program Management. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Develop and update [Assignment: organization-defined frequency] an inventory of organizational systems.
Guidance: [OMB A-130] provides guidance on developing systems inventories and associated reporting requirements. System inventory refers to an organization-wide inventory of systems, not system components as described in CM-8.

## Enhancements (1)
- PM-05(01) Inventory of Personally Identifiable Information. Baselines: privacy
Each enhancement's statement: /api/v1/controls/PM-05?fields=enhancements

## Patterns that use it (3)
- Critical (1): SP-046 External Attack Surface Management
- Important (2): SP-038 Vulnerability Management and Patching; SP-040 Post-Quantum Cryptography and Quantum Readiness

## Clauses by framework (44 frameworks)
- iso_27001_2022: A.5.9. OSA's own, not in NIST's crosswalk: A.5.9
- iso_27002_2022: 5.9
- cobit_2019: BAI09
- nist_csf_2: ID.AM-01, ID.AM-02, ID.AM-04. OSA's own, not in NIST's crosswalk: ID.AM-04
- cis_controls_v8: CIS 1, CIS 3.2, CIS 6.6, CIS 15.1
- finos_ccc: CCC-C06
- nis2: Art. 21(2)(i)
- apra_cps_234: Para 21
- pra_op_resilience: SS2/21-13.1
- bio2: 5.9
- rbi_csf: Annex1.1, ITGRCA.9
- fisc: FISC.O1
- lgpd_bcb: BCB.Art.20
- mlps_2: 8.1.10.1
- dnb_good_practice: DNB.5.2, DNB.6.1, DNB.19.3
- cra: CRA.II.1, CRA.Info.7
- nca_ecc: 2-1
- qatar_nia: AM, GV
- sama_csf: 2.1
- uae_ia: T4
- bog_cisd: CISD-V
- bom_ctrm: 2.1
- cbe_csf: CRM-2
- cbn_csf: Part3.1
- sa_js2: JS2-6.1
- bcbs_239: Principle 4, Principle 8
- cpmi_pfmi: CG.ID, PFMI.P3
- eba_ict: 3.3.2, 3.5(a)
- ecb_croe: CROE.2.2.1, CROE.2.2.2
- ffiec_is: II.C.1, II.C.5, II.C.13(e)
- nydfs_500: 500.3, 500.13
- sebi_cscrf: ID.AM
- doe_c2m2: ASSET
- awia: AWWA Sec 2
- isae_3402: Clause 1, Clause 9
- hitrust_csf: 00.a, 00.c, 04.b, 07.a
- iso_27799: 8.1
- naic_ds: 3, 4-asset
- nhs_dspt: NDG-5.3, NDG-8.1, NDG-8.3
- pra_ss1_23: P1.1
- csa_ccm_v4: DSP-03, DSP-06
- csa_aicm: DSP-03, DSP-06
- ccss_v9: 1.02.3
- dpdpa: Act.11
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PM-05
- Clauses only: /api/v1/controls/PM-05?fields=mappings
- Page for people: /controls/pm-05/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
