Risk managers are continuously reminded by regulatory bodies and framework developers of the importance of maintaining an accurate, complete, and relevant IT asset inventory. The rationale for this recommendation and warning is quite simple: How can you mitigate the risk of an asset that you don’t even know you have? This warning is supported by successful cyber-attacks that exploited forgotten assets that victim organizations either neglected or were not aware that they were responsible for. This is especially frustrating for audit committee members and others with financial backgrounds who appreciate the challenges and needs of maintaining asset inventories. Many of them struggle to understand why the organization is able to maintain accurate inventories of goods and services yet cannot do the same for technology assets.
Lack of Knowing Assets Results in Breaches
Public media, including stories from the Equifax breach, have highlighted the critical security need to maintain an IT asset inventory. Examples include New Jersey’s Cybersecurity & Communications Integration Cell’s (NJCCIC) “Information Asset Management” (https://tinyurl.com/3sjrdx3x). The cell uses Equifax’s misunderstanding of the assets it had to protect to state that “The greatest information security team in the world has no chance of effectively managing cybersecurity risk without an accurate and current inventory of their organization’s technology assets. That inventory is not just a count of systems, but of their configurations, applications, operating systems and software versions, patch levels, dependencies, and interconnections with other systems—direct and indirect.”
Best Practices and Regulatory Expectations Require an Inventory
The importance of asset inventories is emphasized in key cybersecurity publications and guidance. As part of the NIST Cybersecurity Framework, under the identify function, the asset management (ID.AM) category states that “Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization’s risk strategy” (https://tinyurl.com/4umw8zb2). The Center for Internet Security, a respected cybersecurity knowledge sharing organization, identified inventory of assets as the two of the most important cybersecurity controls (https://tinyurl.com/yx8dnw4v). Other recognized frameworks and standards including, but not limited to, ISO and CoBIT (International Organization for Standardization and Control Objectives for Information and Related Technologies), also emphasize the need for inventorying the technology environment.
Regulators have also recognized and expanded expectations that entities effectively understanding their IT environment in order to properly manage cybersecurity risk. Although final rules have yet to be adopted, The US Department of Health and Human Services (DHHS) “HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information” identified the importance of IT asset management by incorporating its requirement into the proposed rules (https://tinyurl.com/2awz656s). The proposed rules “Require the development and revision of a technology asset inventory and a network map that illustrates the movement of ePHI throughout the regulated entity’s electronic information system(s) on an ongoing basis, but at least once every 12 months and in response to a change in the regulated entity’s environment or operations that may affect ePHI.” Other financial regulators, including the Federal Financial Institutions Examination Council (FFIEC), have long requested IT asset inventories when assessing the effectiveness and ability of a financial institution to sufficiently understand the risk that needs to be managed. Other standards, such as those to comply with payment card industry and defense contracting-related activities, also require an inventory.
Unsurprisingly, there are many vendor software options to assist with the requisite tasks of maintaining an inventory. These tools, at least the more moderately priced ones, tend to focus on day-to-day management of IT assets by operations and provide the capability to detect assets that may not have been properly identified prior to placement in the organization’s environment.
Why Isn’t it Happening?
With benefits accruing to different parts of an organization, many senior executives and audit committee members may assume that this would be a control that would be readily welcomed by everyone. Yet, realistic challenges remain. These can include, but are not limited to:
- Differences in defining the inventory. Some take a limited view that restricts the asset inventory to traditional hardware and software directly under its control. Others take a more expansive view that tries to identify any asset, whether in the cloud or outsourced on internal, including automated, interfaces, which can impact cybersecurity through various vectors.
- The software may not serve its purpose. There are many software options with various purposes and prices. Items to consider include the scope of inventory efforts, the extent to which the software reflects this goal, and how the organization will address any gaps.
- The software may be misconfigured or outdated. In some cases, software is purchased but not configured or used properly.
- A manual solution is used. Although a manual approach to identifying assets on a network (a key detective control) that is time-consuming and tedious may not by itself be a problem (assuming compensating controls for discovery), a lack of resources devoted to maintaining the asset is.
- No semblance of any inventory exists. This can also indicate poor or negligent management of technology asset resources.
- Potential control weaknesses. Such weakness can also impact IT general controls evaluations, whereby moving IT assets into production circumvents established change control processes.
What Should an Inventory Contain
Understanding what is actually on an organization’s network, or where confidential data entrusted to the organization is located, represents the minimum needed for an inventory. The NJCCIC further suggests that the inventory should include systems and their configurations, applications, operating systems and software versions, patch levels, dependencies, and interconnections with other systems, both direct and indirect. It includes sensitive data inventories. For any IT asset inventory to be effective, it must also be correlated to an equally current and accurate account management inventory: to include user, administrator, and service accounts, and to what applications, systems, networks, and information they have authorized access.
Unfortunately, many small and medium-sized businesses (SMB) do not maintain such an inventory, thereby increasing their risk, both from a cybersecurity and non-compliance standpoint, with foundational regulatory expectations such as the Federal Trade Commission’s (FTC) Safeguards Rules (which applies to an expanded list of financial institutions including tax preparers). As it relates to IT asset inventories, the rule requires “a periodic inventory of data, noting where it’s collected, stored, or transmitted. Keep an accurate list of all systems, devices, platforms, and personnel” (https://tinyurl.com/bdedw7vb).
Resolving the Issue
Efforts relating to resolving the IT asset management issue will depend upon both the organization’s objectives and its current status. Fortunately, guidance exists that can help organizations facilitate their efforts. Such guidance is typically geared toward larger organizations that either need to comply with regulatory issues or have national infrastructure risks. Software exists as well, but it’s best that the organization first defines its needs before choosing the appropriate tool. SMBs can use the reputable guidance below as a checklist to understand generic expectations, and to adapt recommendations to satisfy their risk appetite and stakeholder obligations. Both of these publications focus on cybersecurity aspects of an IT Asset Management program, rather than cost management.
“Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators” (https://tinyurl.com/y3mn6345) was developed by the cybersecurity agencies of a number of key western countries. This is a very thorough guide that SMBs should prioritize. Although originally written for critical infrastructure, it does provide an overall process for how to develop and maintain an inventory. The NIST’s “SP 1800-5, IT Asset Management,” provides a more robust framework with a more general appeal (https://doi.org/10.6028/NIST.SP.1800-5). Originally targeted to the financial services sector, per the publication “The security characteristics in our IT asset management platform are derived from the best practices of standards organizations, including the Payment Card Industry Data Security Standard (PCI DSS).” Because it includes the PCIDSS standards, the NIST’s publication may resonate more with SMBs.
Knowledge to Protect
The often-used phrase “you can’t protect what you don’t know you have” continues to ring true. Many organizations may understand the cost to maintain an inventory but unfortunately do not understand the cost of not maintaining one. Often, not maintaining an inventory can also be a symptom of an organization not maintaining appropriate internal controls.




























