Asset inventory

The maintained record of the assets an organisation holds, tangible and intangible, with each one's owner, location, classification and lifecycle state: the starting point for protecting them.

An asset inventory is the maintained list of what the organisation owns or depends on: hardware, software, data stores, cloud services, facilities, and intangible items such as intellectual property. Each record typically carries an identifier, type, location, asset owner, classification and lifecycle state. The ISC2 outline names it under objective 2.3, giving tangible and intangible assets as its examples. The CIS Critical Security Controls (version 8) open with two inventory controls, one for enterprise assets and one for software, and the reasoning is simple: an asset nobody has recorded is unlikely to be patched, monitored or disposed of properly.

An inventory is only useful while it is accurate. Automated discovery, procurement records and reconciliation against network data help keep it current, and the gaps they reveal often point to shadow IT. The inventory differs from a configuration management database, which tracks configuration items and the dependencies between them, and from IT asset management, the wider process of managing assets through their lifecycle, which relies on the inventory as its record.

Exam relevance: a scenario is likely to ask what has to come first in a protection programme. Classification, risk assessment and control selection all depend on knowing what exists, so the inventory tends to be the prerequisite. Candidates are expected to include intangible assets, not only equipment.