Asset inventory, technical vulnerability, review
The standard requires a current asset inventory, regular technical vulnerability management (Annex A 8.8) and periodic independent review. The monthly EASM and vulnerability cycle keeps the inventory current and the review evidence dated.