Asset inventory
An asset inventory is a listing of software and hardware assets at your company. It can be as simple as a spreadsheet with the software versions, hardware with serial numbers, and an asset owner. Who wants to have to manually keep up with this information? You will definitely want to use a product to help with keeping an accurate list of your company’s assets. Having a good asset inventory will enable you to do the following:
- Quickly search the assets you own and figure out if a CVE applies to your company
- Have asset owners assigned for each hardware asset
- Understand if an unauthorized asset is on your network
An asset inventory is mandatory for all compliance. Many times, companies don’t get serious about their asset inventory until it is time for the company to be compliant, whether it’s SOC 2, ISO 27001, or HIPAA. See Table 9.1 to see a mapping of asset inventory to various compliance standards and frameworks: