GlossaryCompliance operations

Asset inventory

Short answer

An asset inventory is an up to date record of the information assets an organisation has, such as devices, software, cloud and SaaS services, data and accounts, with an owner for each. It is the foundation of security: what is not known cannot be protected, patched or monitored.

What it should include

Hardware (laptops, servers, network and mobile devices), software and versions, cloud resources, SaaS applications, internet facing systems and domains, important data sets and where they are stored, and key suppliers. Each asset needs an owner, a classification by importance and, where relevant, its location and the data it handles.

Keeping it current

A spreadsheet updated once a year is out of date within weeks. Inventories work best when they are fed automatically: MDM and EDR for devices, the identity provider and SaaS discovery for applications, cloud APIs for cloud resources and attack surface management for what is exposed online. Comparing these sources also uncovers shadow IT.

What depends on it

Patch management, vulnerability scanning, the risk assessment, backups, access reviews and incident response all assume the company knows what it has. Many incidents start on a system nobody remembered.

Where it shows up in compliance

ISO 27001 requires an inventory of information and other associated assets, with owners (Annex A 5.9). The ENS includes an asset inventory measure, and the first two CIS Controls are inventories of hardware and software. It is usually one of the first documents an auditor asks for.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub