Official intent
Maintain a comprehensive, current inventory of the devices, identities, and applications you defend. The official source remains authoritative.
Read the official campaign ↗Why it matters
Unknown assets are unmanaged assets: unpatched, unmonitored, and often still trusted on the network. Almost every other basic — patching, MFA coverage, segmentation, backup — silently assumes a complete list. When the inventory is wrong, those controls have blind spots you never chose.
Minimum / Strong / Advanced
A single current list of hardware and software exists, with an owner and a review date.
Devices, cloud and SaaS applications, and identities are inventoried from authoritative sources and reconciled; new assets are added through onboarding.
Discovery is continuous and automated; unmanaged assets are detected and investigated, and the inventory drives licensing, patching, and access decisions.
Implementation timeline
- Name an inventory owner
- Pull existing lists from MDM, identity provider, and procurement
- Merge the sources into one record
- Flag devices with no owner or no management agent
- Add cloud/SaaS applications and privileged service accounts
- Reconcile the identity provider against HR joiners and leavers
- Tie every add/change/retire to onboarding and offboarding
- Set a monthly reconciliation and quarterly review
Implementation steps
- Assign an accountable inventory owner with authority across IT and cloud.
- Seed the inventory from authoritative sources: MDM/endpoint manager, identity provider, DNS/DHCP, cloud consoles, and procurement.
- Reconcile the sources against each other and investigate anything that appears in one but not the others.
- Extend beyond hardware to SaaS applications, service accounts, and privileged identities.
- Connect the inventory to onboarding, offboarding, and change control so it stays current by default.
Validation
- Pick ten devices from the network at random; all ten must appear in the inventory with an owner.
- Compare the identity provider's active accounts against the HR leaver list — there should be no orphaned accounts.
- Confirm the last device added to the network appears in the inventory.
Evidence to retain
Inventory policy naming the owner, sources, and cadence
Inventory export covering hardware, software, cloud apps, and identities
Monthly reconciliation report with investigated discrepancies
Quarterly review sign-off and joiner/leaver reconciliation
Common failure modes
A spreadsheet updated once a year, hardware counted but SaaS and identities ignored, and orphaned accounts from departed staff left active. A list nobody reconciles is a guess, not an inventory.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.