July 2, 2026 · KeyCaliber
Why Every Framework Starts With Control 1: Know Your Assets
NYDFS, CMMC, PCI, HIPAA — they all demand an asset inventory first. There's a reason. In the CIS Controls, inventory is literally Control 1, and every other control depends on it.
Read enough security regulations and you notice they open the same way. NYDFS wants a complete asset inventory. CMMC scopes its whole assessment around one. PCI DSS makes it Requirement 12.5.1. The proposed HIPAA Security Rule would make it mandatory. Different industries, different regulators — same first step.
That’s not a coincidence. It’s the CIS Controls showing through.
Control 1, Safeguard 1.1
The CIS Critical Security Controls are the security community’s consensus on what actually reduces risk, ordered by priority. The list is deliberately sequenced, and asset inventory isn’t somewhere in the middle. It is Control 1: Inventory and Control of Enterprise Assets.
Its first safeguard, 1.1, requires you to “establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data” — end-user devices including mobile, network devices, non-computing and IoT devices, and servers, across physical, virtual, remote, and cloud environments. Each record is expected to carry the asset’s network address, hardware address, machine name, owner, department, and whether it’s approved to connect to the network. Reviewed and updated at least twice a year, or more often.
The principle underneath is stated just as plainly: enterprises cannot defend what they do not know they have.
Why it’s first, not fifth
The ordering is the argument. Nearly every other control assumes Control 1 is already done. You cannot patch what you haven’t inventoried. You cannot configure a baseline on an unknown host, control access to accounts you can’t see, deploy endpoint protection to assets you never enumerated, or scope an incident against a list you don’t trust. Get Control 1 wrong and the error propagates into all 17 controls that follow.
This is exactly why the regulations echo it. They lead with asset inventory because the frameworks they’re built on lead with it. Control 1 is the common root:
| Framework | Applies to | Asset-inventory mandate |
|---|---|---|
| CIS Controls v8 | Any organization | Control 1 / Safeguard 1.1 |
| NYDFS 23 NYCRR 500 | NY financial services | §500.13 |
| CMMC (NIST SP 800-171) | Defense contractors | Level 2 scoping inventory |
| PCI DSS 4.0 | Anyone handling card data | Requirement 12.5.1 |
| HIPAA Security Rule | Healthcare | Proposed technology asset inventory |
Different industries, different regulators, one shared first step.
The leverage of doing it once
That shared root is also an opportunity. Because every framework’s inventory requirement is asking for the same underlying thing — an accurate, current, attributed list of everything you have — a single authoritative inventory pays down compliance debt across all of them at once. Do Control 1 well and you’re not just satisfying CIS; you’re satisfying the asset-inventory requirement in every regulation you’re subject to, with one source of truth instead of a different spreadsheet per auditor.
The catch is the same one every framework runs into: “accurate and up-to-date” is where inventories die. The information CIS wants — address, owner, department, approval status — is scattered across tools that don’t agree, and a list reviewed twice a year is wrong the other 363 days.
Where KeyCaliber fits
KeyCaliber builds the Control 1 inventory from the tools you already run. It connects by API to your EDR, vulnerability scanners, CMDB, identity, and cloud, and correlates what each sees into a single validated picture of every asset — managed, unmanaged, and unknown — kept continuously current instead of refreshed twice a year.
- Owner, department, location, and network and hardware addresses are pulled from the systems that already hold them and reconciled into one record per asset — the fields Safeguard 1.1 asks for.
- The unmanaged and unknown assets Control 1 exists to catch are surfaced by correlating signals no single tool sees on its own.
- Its coverage-gap detection turns the inventory into action — showing which assets are missing EDR or other controls — and its retained source payloads make it defensible to any auditor, under any framework.
Every regulation you’ll ever face starts by asking the same question: what do you have? Control 1 is the discipline of always having the answer. Build that inventory once, keep it alive, and the compliance requirements that depend on it stop being separate problems — and start being one.
← All articles