Services /  GRC

Asset Management

You cannot protect, patch or certify what nobody has written down.

The problem

Nobody can answer how many laptops the company has, which cloud accounts exist, or who owns the staging environment that has been running since 2022. Every control you are about to be audited on (patching, access, encryption, backup) depends on an inventory that does not exist.

The method.

01

Build the inventory from authoritative sources

Endpoints from the MDM and EDR consoles; cloud resources from the provider APIs across every account, subscription and region, including the ones nobody remembers opening; SaaS from IdP SSO and OAuth grants; code repositories and CI from the VCS; data stores from the cloud inventory. Manual spreadsheets are the last resort, never the first source.

02

Reconcile the sources against each other

The findings are in the differences: a laptop in the MDM with no EDR agent, a cloud account with no owner, a production database absent from the backup policy, an ex-employee's machine still checking in. Each gap is a control failure with a name attached.

03

Classify and assign ownership

Every asset gets an owner, a classification derived from the data it holds, and an environment tag. Ownership is a person, not a team alias. Classification drives the control set (encryption, access, retention, backup, logging), so it has to be right before anything downstream is.

04

Wire the lifecycle to the processes that already exist

Provisioning creates the record, offboarding retires it, procurement registers it. Inventory maintained as a separate chore rots within a quarter; inventory maintained as a by-product of joiner-mover-leaver and infrastructure-as-code stays true.

05

Track the exceptions to closure

Unowned assets, unmanaged endpoints, orphaned cloud resources and shadow SaaS become a working list with dates. This list is the fastest security win most mid-market companies have available, and it is usually the cheapest.

The inventory is the ROC's ground truth. Continuous reconciliation means a new cloud account, an endpoint that lost its agent, or a SaaS app onboarded without review is raised as it happens, and asset coverage percentages become a live number instead of an audit-week estimate.

Why does ISO 27001 require an asset inventory?

Because every other control depends on it. Patching, access control, encryption, backup, logging and incident response all apply to a defined set of assets. Without a complete inventory there is no way to demonstrate that a control covers everything it is claimed to cover, and coverage is exactly what an auditor tests.

What should a security asset inventory include?

Endpoints and mobile devices, servers, cloud accounts and resources across all providers and regions, SaaS applications and their OAuth grants, code repositories and CI/CD systems, data stores with their classification, and network infrastructure. Each record needs a named owner, an environment, and a data classification.

How do you find assets nobody remembers creating?

By reconciling independent sources rather than trusting any one of them. Cloud provider billing and organisation APIs surface accounts nobody documented; identity provider OAuth grants surface SaaS nobody procured; external attack surface discovery surfaces hosts and subdomains nobody decommissioned. The differences between these sources are where forgotten assets are found.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.