Skip to content

Asset Inventory

What is Asset Inventory?

A comprehensive and up-to-date register of all hardware, software, data, and network resources owned or managed by an organisation. Required by most security frameworks including CIS Controls and ISO 27001.

Information Security

Each of these is named in at least one of the same controls as asset inventory. The number is how many controls name both.

What the standards actually require on asset inventory

Requirements naming asset inventory across 6 standards, quoted from the control text.

CIS Controls v83 controls

Use DHCP logging on all DHCP servers or Internet Protocol (IP) address management tools to update the enterprise’s asset inventory. Review and use logs to update the enterprise’s asset inventory weekly, or more frequently.

CIS-1.4 · Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory

Maintain an inventory of ICS assets, categorise asset criticality, identify security risks, determine potential impact, tailor and implement security controls, and monitor and adjust.

CISA-ICS-DID-22 · Asset Inventory and Risk Characterization
API 11641 control

Maintain a current inventory of SCADA assets including controllers, RTUs, HMIs, network devices, and software with criticality classification.

API1164-04 · Asset Inventory

Maintain a current inventory of IT and OT assets including SCADA, PLCs, HMIs, sensors, and supporting networks.

AWWA-G430-2 · Asset Inventory and Classification

Maintain an inventory of IT and OT assets important to the delivery of the energy function.

AESCSF-ACM-1 · Asset inventory

Track the asset inventory by discovering and querying all cloud resources, organising them by tagging and grouping, and giving the security organisation access to a continuously updated view.

ASBv3-AM-1 · Track asset inventory and their risks

Questions people ask about asset inventory

What is Asset Inventory?
A comprehensive and up-to-date register of all hardware, software, data, and network resources owned or managed by an organisation. Required by most security frameworks including CIS Controls and ISO 27001.
Why is Asset Inventory important for compliance?
Asset Inventory is a key concept in Information Security. Understanding asset inventory helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Asset Inventory?
Asset Inventory appears in the requirement text of CIS Controls v8, CISA Industrial Control Systems (ICS) Security Guidance, API 1164, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), Australian Energy Sector Cyber Security Framework (AESCSF). Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Asset Inventory?
Explore our compliance framework pages to see how asset inventory applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Asset Inventory applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.