You cannot protect, patch, classify, back up or decommission what you have not recorded. Every framework - ISO 27001, the NCA ECC, SAMA CSF, PCI DSS, SOC 2 - requires an asset inventory, because almost every other control depends on it. It is also the control most often found incomplete, which is why experienced auditors test it early: a weak inventory predicts weakness everywhere else.
What counts as an asset
Broader than most first attempts assume:
- Hardware - servers, laptops, mobile devices, network equipment, and anything in an operational technology environment.
- Software and services - applications, SaaS subscriptions, libraries and dependencies.
- Cloud resources - accounts, subscriptions, compute, storage, managed databases.
- Data assets - databases and repositories, with their classification.
- Identities - including service accounts and API keys, which are assets in every meaningful sense.
- Suppliers holding your data or connected to your systems.
The fields that make it useful
A list of hostnames is not an inventory. For each asset record:
- Owner - a named person, not a team.
- Business purpose - what breaks if it stops.
- Classification of the data it holds or processes.
- Criticality, which drives recovery objectives.
- Location - physical site, cloud region, or provider.
- Lifecycle state - in use, being decommissioned, retired.
- Dependencies - what it relies on and what relies on it.
- Last verified date - the field that tells you whether to trust the row.
Ownership is the field that makes the inventory operational. Without a named owner, every downstream control - patching, access review, recovery testing - has nobody to assign it to.
Build the inventory once, use it everywhere
GRC Copilot maintains your asset register and links each asset to the controls, risks and evidence that depend on it - so classification, ownership and criticality flow through your whole programme.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Finding what you do not know about
The assets that hurt you are the ones nobody listed. Cross-reference several sources rather than trusting one:
- Cloud provider APIs - every account and region, not just the main one.
- Identity provider application lists - the fastest route to unknown SaaS.
- Expense and procurement records - shadow IT is usually visible on a card statement before it is visible to IT.
- Network discovery and endpoint management.
- DNS and certificate inventories for forgotten public-facing services.
Keeping it current
Inventories decay from the day they are built. Sustainable approaches share three traits:
- Automated discovery as the default source, with manual entry as the exception.
- Provisioning integration - assets register themselves when created, rather than depending on someone remembering.
- Periodic owner attestation - owners confirm their assets on a cycle, which also produces audit evidence.
Add a decommissioning process. Orphaned assets - a forgotten VM, an unused SaaS tenant, a dormant service account - are simultaneously a security risk, an audit finding and a recurring cost.
What auditors do with it
Expect the inventory to be used as the population for sampling. An auditor picks assets from your register and asks: is it patched, who has access, is it backed up, is it classified, was it in the last review? Two failure modes follow - assets in the register that do not exist, and systems that exist but are not in the register. The second is worse, because it suggests your controls are applied to an incomplete population.
Frequently asked questions
Do we need a full CMDB?
No. A CMDB is one implementation. What frameworks require is an accurate, owned, current record of assets - which a well-maintained register or a GRC platform can provide without a heavyweight CMDB programme.
How often should it be reviewed?
Automated discovery should run continuously; owner attestation quarterly for critical assets and at least annually for the rest.
Should SaaS applications be included?
Yes - and this is where most inventories are weakest. Any service holding company data belongs in the register, whether or not IT procured it.
Where should we start if we have nothing?
Start with what holds sensitive data and what is internet-facing. Complete coverage can follow; those two categories carry most of the risk.
Key takeaways
- Nearly every other control depends on the asset inventory.
- Named ownership is what makes it operational rather than decorative.
- Discover from several sources - expense records expose shadow IT fastest.
- Auditors sample from your register; unlisted systems are the worse finding.