IT asset management (ITAM)

The practice of tracking IT hardware, software and related contracts across their lifecycle, from request and purchase through use and maintenance to retirement and disposal.

IT asset management keeps an accurate, current record of an organisation’s technology assets and manages each one from acquisition to disposal. It usually divides into hardware asset management (HAM), which follows physical devices, and software asset management (SAM), which follows installations and licence entitlements. The ISO/IEC 19770 family sets out requirements and data standards for ITAM. The ISC2 exam outline lists asset inventory and asset management under objective 2.3.

ITAM matters to security because an asset that is not recorded is unlikely to be patched, monitored or sanitised. It is commonly confused with a configuration management database (CMDB): ITAM tracks what is owned, what it cost, who owns it and where it is in its lifecycle, while a CMDB tracks configuration items and how they depend on one another to deliver services. ITAM also holds lifecycle dates such as end of support, and feeds decommissioning and media sanitisation. Unrecorded purchases and shadow IT are typical gaps.

Exam relevance: a scenario may describe an unknown or unpatched device found on the network and ask what failed first. Candidates are expected to see a complete asset inventory as a precondition for many other controls, and to keep ITAM (ownership and lifecycle) apart from the CMDB (configuration and relationships).