Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
ATL-011INVENTORYEDITORIAL REVIEW COMPLETE

Hardware and Software Asset Inventory

Two working tables — one for every device, one for every installed application — plus the reconciliation routine that keeps them honest: endpoint manager against identity provider against purchase records, with every mismatch explained or investigated.

Using this artifact

Purpose, inputs, and completion

Purpose. You cannot defend, patch, back up, or retire what you do not know you have — every other practice inherits its scope from this document. This inventory holds the device and software lists in one owned place and, more importantly, forces the monthly reconciliation that keeps them true. An inventory that is never compared against another source of truth is a list of what you believed last quarter.

When to use it. Complete the scope section first so it is explicit which sites, networks, and asset classes this inventory claims to cover. Fill the hardware table from same-day exports of your endpoint manager and identity provider, and the software table from the endpoint manager's installed-software report. Then run the reconciliation checklist and log every unexplained difference in the final section with an owner and a date. Repeat the reconciliation monthly; repeat the full verification — including the OT walkdown — annually.

Required inputsHave these before you start
  • Device export from the endpoint manager (or the honest list built by hand if none exists)
  • Device and account registrations from the identity provider
  • Purchase, lease, and disposal records from finance
  • For OT assets: a physical walkdown with the process owner, not a network scan
Completion instructionsIn order
  • Export devices from the endpoint manager and registrations from the identity provider on the same day, then merge into the hardware table — same-day exports are the only ones worth comparing.
  • Walk the software table from what is actually installed (endpoint manager software report), not from what was purchased; the difference between the two lists is the finding.
  • For OT assets, verify by walkdown during a maintenance window with the process owner present — never by active scanning, which can disrupt production equipment.
  • Mark every device or application you cannot attribute to an owner as INVESTIGATE with a date; an unowned asset is an unmanaged asset.
  • Record support status and end-of-life dates as you go — the EOL column is the feeder for technical-debt retirement planning.
Keeping it honest

Evidence, validation, and failure modes

Evidence this producesWhat a reviewer could examine
  • A dated, owned hardware inventory with support status and verification dates a reviewer can sample against reality
  • A software inventory that separates authorized from discovered-and-unauthorized software
  • A reconciliation record showing the deltas between endpoint manager, identity provider, and purchase records — and what was done about each
Validation checksRun these before calling it complete
  • Pick five devices at random from the endpoint manager and five from the identity provider; every one must appear in the hardware table with an owner and a last-verified date.
  • Pick three rows from the hardware table and physically locate the devices (or confirm disposal paperwork); a row you cannot walk to or explain is a stale row.
What looks done but is not
  • The inventory is an export, not a reconciliation — three tools each hold a different device count and nobody has explained the difference.
  • OT assets are 'inventoried' from a network scan that missed everything serially connected or air-gapped — and disrupted a PLC in the process.
  • Software rows record what was bought, not what is installed; the unauthorized remote-access tool on two machines never appears.
Mapped relationships

Practices and requirements this artifact relates to

Brilliant at the Basics practices

NIST SP 800-171 Rev. 2

NIST SP 800-171 Rev. 3

Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain twelve months of reconciled monthly snapshots plus every annual verification; the trend of unexplained deltas is evidence of whether the inventory actually operates.

Full document

Preview — exactly what prints

INVENTORY · ASSET MANAGEMENTv1.0 · REVIEWED 2026-08-06

Hardware and Software Asset Inventory

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

You cannot defend, patch, back up, or retire what you do not know you have — every other practice inherits its scope from this document. This inventory holds the device and software lists in one owned place and, more importantly, forces the monthly reconciliation that keeps them true. An inventory that is never compared against another source of truth is a list of what you believed last quarter.

How to use it

Complete the scope section first so it is explicit which sites, networks, and asset classes this inventory claims to cover. Fill the hardware table from same-day exports of your endpoint manager and identity provider, and the software table from the endpoint manager's installed-software report. Then run the reconciliation checklist and log every unexplained difference in the final section with an owner and a date. Repeat the reconciliation monthly; repeat the full verification — including the OT walkdown — annually.

Inventory scope and method

State what this inventory covers and where each column's data comes from, so the next person can rebuild it without you.

Scope and sources

Sites and networks coveredAsset classes covered (IT endpoints, servers, network gear, OT, mobile)Systems of record used (endpoint manager, identity provider, purchase records)Deliberately excluded, and why
    
One inventory, two tracks

IT assets are verified from management tooling; OT assets are verified by walking the floor. Both belong in the same hardware table so that nothing falls between the two owners — the managed-by column records which track each row follows.

Hardware asset inventory

One row per device that stores, processes, or transmits company or contract information — including OT equipment, network gear, and anything a backup touches.

Rows beginning EXAMPLE: show the expected shape — replace them with your own.

Asset tag / IDTypeMake and modelOS / firmware versionOwnerLocationManaged bySupport status / EOL dateSensitive data authorized?Last verified
EXAMPLE: LT-0042LaptopDell Latitude 5550Windows 11 24H2J. Rivera (Engineering)Main site / mobileInternal IT — endpoint managerSupported; warranty to 2028-03Yes — CUI project library2026-07-15
EXAMPLE: CNC-07OT controller (CNC)Haas NGCFirmware 21.04Plant leaderShop floor, cell 3Vendor support contractEOL 2027-12 — replacement plannedNo2026-06-20 (walkdown)
          
          
          
          
Verify OT rows on the floor, in a window

Do not run discovery or vulnerability scans against production equipment to populate this table — active scanning can stall controllers and stop lines. OT rows are verified by physical walkdown with the process owner during a scheduled maintenance window, and vendor-managed equipment is confirmed with the vendor's own service records.

Software asset inventory

One row per application actually installed or in use — from the endpoint manager's installed-software report, not from the purchasing spreadsheet.

Rows beginning EXAMPLE: show the expected shape — replace them with your own.

Software nameVersion(s) in usePublisherInstall countBusiness ownerSupport statusAuthorized?
EXAMPLE: SolidWorks2025 SP3Dassault Systèmes8Engineering leadSupportedYes
EXAMPLE: TeamViewer (free edition)15.xTeamViewer SE2None identifiedUnsupported editionNo — remove; found during reconciliation
       
       
       
       

Software with no business owner, or marked unauthorized, does not stay in limbo: it gets a removal date or an authorization decision, logged in the follow-ups section. Unsupported versions feed the technical-debt retirement plan — the support-status column is where that plan starts.

Reconciliation against source records

The inventory earns its keep here. Three sources, compared on the same day, with every difference explained or assigned.

Monthly reconciliation routine

Run in order; record counts and deltas in the follow-ups section.

  • Export the device list from the endpoint manager and the device/account registrations from the identity provider on the same day.Step 1
  • Compare: every device in the identity provider but not the endpoint manager is either unmanaged or unenrolled — investigate each one.Step 2
  • Compare both against purchase and disposal records: purchased-but-never-seen suggests shadow deployment or theft; seen-but-never-purchased suggests personal or vendor equipment.Step 3
  • Classify every mismatch: EXPLAINED (with the reason written down) or INVESTIGATE (with an owner and date in the follow-ups section).Step 4
  • Record the three source counts and the number of unexplained deltas; the month-over-month trend of that last number is the health of this inventory.Step 5

Gaps and follow-ups

Every INVESTIGATE from the tables and the reconciliation lands here with an owner and a date. This section is the difference between an inventory and a to-do list nobody reads.

Open items

Item (device, software, or delta)What is unexplainedOwnerResolve by
    
    
    
    
    

Document control, version history, and approval

An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.

FieldEntry
Document owner (named person) 
Suggested owner roleIT leader
Approval authorityExecutive sponsor
Review frequencyMonthly reconciliation against source systems; full verification annually and at every acquisition, disposal, or site change
Next scheduled review 
Storage location of the completed document 
RetentionRetain twelve months of reconciled monthly snapshots plus every annual verification; the trend of unexplained deltas is evidence of whether the inventory actually operates.

Version history

VersionDateAuthorSummary of changeApproved by
     
     
     
     

Review and approval

Reviewed byRoleDateSignature / initials
    
    
Complete this offline — and mind what you write down

Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.

Hardware and Software Asset Inventory · version 1.0 · reviewed 2026-08-06 · file name batb-hardware-software-asset-inventory

Generated from the live artifact library at brilliantatthebasics.us/templates/hardware-software-asset-inventory. Independent educational material published by inDirectIT, Inc. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.