What it should include
Hardware (laptops, servers, network and mobile devices), software and versions, cloud resources, SaaS applications, internet facing systems and domains, important data sets and where they are stored, and key suppliers. Each asset needs an owner, a classification by importance and, where relevant, its location and the data it handles.
Keeping it current
A spreadsheet updated once a year is out of date within weeks. Inventories work best when they are fed automatically: MDM and EDR for devices, the identity provider and SaaS discovery for applications, cloud APIs for cloud resources and attack surface management for what is exposed online. Comparing these sources also uncovers shadow IT.
What depends on it
Patch management, vulnerability scanning, the risk assessment, backups, access reviews and incident response all assume the company knows what it has. Many incidents start on a system nobody remembered.
Where it shows up in compliance
ISO 27001 requires an inventory of information and other associated assets, with owners (Annex A 5.9). The ENS includes an asset inventory measure, and the first two CIS Controls are inventories of hardware and software. It is usually one of the first documents an auditor asks for.




