What should a useful IT inventory for the company include?

You must identify each asset, its user or person responsible, location, function, status, warranty, system, network address when applicable and relationship with critical services. It should also include virtual assets, cloud, licenses and providers, not just computers.

Risks to review

  • Buy duplicate licenses or equipment because you do not know the existence and current assignment.
  • Maintain forgotten devices with network access or business information.
  • Not being able to prioritize patches, renewal or response to a vulnerability.
  • Register information only once and leave it outdated.

Safe recommendations

  1. Define a unique identifier and owner for each asset.
  2. Include hardware, software, network devices, cloud services, domains, certificates and providers.
  3. Record additions, transfers, changes and retirements as part of the operational process.
  4. Validate connected assets monthly and review ownership and criticality quarterly.
  5. Protect the inventory because it contains sensitive infrastructure information.
  6. Use the inventory to plan renewal, licensing, patching and continuity.

When to seek specialized help

  • There are multiple locations, suppliers or networks without a central source of information.
  • Unknown computers are detected or an asset cannot be associated with its manager.
  • Inventory should connect to monitoring, support, purchasing, or vulnerability management.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.