Asset Inventory
No contributors yet. Be the first to contribute!
🔑 Key Takeaway: You cannot protect what you do not inventory. Document assets, owners, and criticality—and refresh the list on a fixed cadence.
An asset inventory means having information about everything related to your project, meaning for example contracts, hardware, software, cloud providers, dependencies and network components. This is important, as if you don't have awareness of your assets then how are you going to be able to protect them?
You should at the very least document as much as you can with regards to your assets, and update this on a regular basis. It is highly recommended to also assign ownership of each asset, so that someone ensures the safety of this asset. Classifying them based on their criticality and sensitivity also helps you prioritize them with regards to security measures.
Further Reading
- Infrastructure overview: how the pages of this framework fit together
- Cloud Infrastructure: where much of the inventory actually lives
- Dependency Awareness: inventorying the software supply chain too
- CIS Control 1: Inventory and Control of Enterprise Assets: a reference process for building and refreshing the list