Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
IT-02IT SYSTEMSOFFICIAL INTENTEXPERT REVIEWED

Comprehensive Asset Inventory Management

You defend what you can see. A comprehensive inventory covers hardware, cloud and on-prem software, and — increasingly — identities and service accounts. Build it from authoritative sources, reconcile the sources against each other, and keep it current through change control rather than an annual scramble.

EXPLAINER · 5 SCENES · ≈40 SEC · CAPTIONS, NO AUDIO

IT-02 in 40 seconds

The problem, the plain-words meaning, three key moves, and what “done” looks like.

Official intent

What the campaign asks for

Maintain a comprehensive, current inventory of the devices, identities, and applications you defend. The official source remains authoritative.

Read the official campaign ↗

Why it matters

Unknown assets are unmanaged assets: unpatched, unmonitored, and often still trusted on the network. Almost every other basic — patching, MFA coverage, segmentation, backup — silently assumes a complete list. When the inventory is wrong, those controls have blind spots you never chose.

Minimum / Strong / Advanced

1
Minimum

A single current list of hardware and software exists, with an owner and a review date.

2
Strong

Devices, cloud and SaaS applications, and identities are inventoried from authoritative sources and reconciled; new assets are added through onboarding.

3
Advanced

Discovery is continuous and automated; unmanaged assets are detected and investigated, and the inventory drives licensing, patching, and access decisions.

Implementation timeline

First 24 hours
  • Name an inventory owner
  • Pull existing lists from MDM, identity provider, and procurement
Next 30 days
  • Merge the sources into one record
  • Flag devices with no owner or no management agent
Next 60 days
  • Add cloud/SaaS applications and privileged service accounts
  • Reconcile the identity provider against HR joiners and leavers
By day 90
  • Tie every add/change/retire to onboarding and offboarding
  • Set a monthly reconciliation and quarterly review

Implementation steps

  1. Assign an accountable inventory owner with authority across IT and cloud.
  2. Seed the inventory from authoritative sources: MDM/endpoint manager, identity provider, DNS/DHCP, cloud consoles, and procurement.
  3. Reconcile the sources against each other and investigate anything that appears in one but not the others.
  4. Extend beyond hardware to SaaS applications, service accounts, and privileged identities.
  5. Connect the inventory to onboarding, offboarding, and change control so it stays current by default.

Validation

  • Pick ten devices from the network at random; all ten must appear in the inventory with an owner.
  • Compare the identity provider's active accounts against the HR leaver list — there should be no orphaned accounts.
  • Confirm the last device added to the network appears in the inventory.

Evidence to retain

Governance

Inventory policy naming the owner, sources, and cadence

Configuration

Inventory export covering hardware, software, cloud apps, and identities

Operations

Monthly reconciliation report with investigated discrepancies

Validation

Quarterly review sign-off and joiner/leaver reconciliation

Common failure modes

What looks done but is not

A spreadsheet updated once a year, hardware counted but SaaS and identities ignored, and orphaned accounts from departed staff left active. A list nobody reconciles is a guess, not an inventory.

Framework mappings

Independent mappings are aids, not authoritative equivalence or compliance determinations.

FrameworkRequirementRelationshipConfidence
NIST SP 800-1713.4.1DirectHigh
CMMC Level 2CM.L2-3.4.1DirectHigh
CIS Controls v8.11.1DirectHigh