Every vulnerability management program has the same blind spot: it only covers the assets it knows about. A scanner scans the IP ranges you give it. A patch tool updates the devices enrolled in it. Anything outside those lists is never checked, never patched and never reported. An accurate asset inventory closes that gap, and it's why CIS Controls v8 puts enterprise assets (Control 1) and software assets (Control 2) at the very top of its list.

The practical answer is to combine several discovery sources, reconcile them regularly, and make sure every asset has an owner who is responsible for fixing it.

What is an asset inventory?

An asset inventory is a current record of the hardware, virtual machines, cloud resources and software your organization runs, along with the details you need to manage them. At a minimum, that means what the asset is, where it lives, who owns it and whether it's supposed to be there.

It has two halves:

  • Enterprise assets: laptops, desktops, servers, mobile devices, network equipment, printers, IoT devices, virtual machines and cloud instances.
  • Software assets: operating systems, applications, and increasingly the services and libraries those applications depend on.

Both halves matter for vulnerability management. You need to know a server exists before you can scan it, and you need to know what's installed on it before you can tell whether a new vulnerability affects you.

Why does vulnerability management depend on asset inventory?

Unknown assets tend to be the riskiest ones. The forgotten test server, the cloud instance a contractor started for a demo, the old network switch in a branch office cupboard. Nobody patches them because nobody remembers they exist.

A good inventory also supplies the context that turns a long list of findings into a prioritized one:

  • Exposure: is the asset reachable from the internet?
  • Criticality: does it support a key business process?
  • Data: does it store or process sensitive information?
  • Ownership: who will actually apply the fix?

Without that context, every vulnerability looks the same, and teams end up chasing CVSS scores instead of real risk.

What do CIS Controls v8 Controls 1 and 2 require?

The Center for Internet Security released CIS Controls v8 in May 2021. The first two controls are about inventory, and they're a sensible baseline for organizations of any size.

Control 1: Inventory and Control of Enterprise Assets

Control 1 covers end-user devices (including portable and mobile ones), network devices, non-computing and IoT devices, and servers. It applies whether those assets are physical, virtual, remote or in the cloud.

Safeguard Title Starts at Frequency in the safeguard
1.1 Establish and Maintain Detailed Enterprise Asset Inventory IG1 Review and update bi-annually, or more frequently
1.2 Address Unauthorized Assets IG1 Weekly
1.3 Utilize an Active Discovery Tool IG2 Run daily, or more frequently
1.4 Use DHCP Logging to Update Enterprise Asset Inventory IG2 Review weekly, or more frequently
1.5 Use a Passive Asset Discovery Tool IG3 Review at least weekly, or more frequently

Safeguard 1.1 expects the inventory to record details such as network address, hardware address, machine name, owner, department and whether the asset is approved to connect. Safeguard 1.2 expects you to deal with unauthorized assets by removing them, blocking them from connecting remotely or quarantining them.

Control 2: Inventory and Control of Software Assets

Safeguard Title Starts at Frequency in the safeguard
2.1 Establish and Maintain a Software Inventory IG1 Review and update bi-annually, or more frequently
2.2 Ensure Authorized Software is Currently Supported IG1 Review at least monthly, or more frequently
2.3 Address Unauthorized Software IG1 Review monthly, or more frequently
2.4 Utilize Automated Software Inventory Tools IG2 Not specified
2.5 Allowlist Authorized Software IG2 Reassess bi-annually, or more frequently
2.6 Allowlist Authorized Libraries IG2 Reassess bi-annually, or more frequently
2.7 Allowlist Authorized Scripts IG3 Reassess bi-annually, or more frequently

The "Starts at" column shows the lowest Implementation Group that includes each safeguard. Implementation Group 1 (IG1) is the CIS baseline for essential cyber hygiene. For a small organization, safeguards 1.1, 1.2, 2.1, 2.2 and 2.3 are the place to start. Mid-sized organizations should aim for the IG2 safeguards as well, especially automated discovery and automated software inventory.

Where does asset data come from?

No single source sees everything. Each one has blind spots, so the goal is to combine sources that cover each other's gaps.

Source What it finds What it misses
Active network scans Anything that responds on the ranges you scan Devices that are offline, behind host firewalls or on ranges you didn't include
DHCP logs Any device that requests an address Devices with static addresses; cloud resources
Passive network monitoring Devices seen talking on monitored segments Segments without a sensor
EDR and endpoint agents Managed devices, with detailed software data Anything without the agent installed
Mobile device management (MDM) Enrolled phones, tablets and laptops Personal or unenrolled devices
Directory services Domain-joined computers and their last sign-in Non-joined devices; stale accounts for machines long gone
Cloud provider APIs Instances, storage, databases, load balancers, public IPs Accounts and subscriptions you don't know exist
Purchasing and finance records Hardware, leases and software subscriptions you pay for Free tools, trials and devices bought on personal cards

Purchasing data is often overlooked. It's the only source that tells you about assets before they're deployed, and it's a good way to find cloud and software-as-a-service subscriptions that no technical tool will report.

For cloud, pull the list of accounts or subscriptions from your provider's organization-level management features first. An inventory that covers every resource in the accounts you know about still misses the ones you don't.

How do you reconcile multiple inventory sources?

Collecting data is the easy part. The value comes from comparing sources and acting on the differences.

Pick matching keys

Decide which attributes identify the same asset across sources: serial number, hardware (MAC) address, hostname, cloud instance ID or agent ID. None is perfect. Hostnames change, and modern phones and laptops can randomize their Wi-Fi MAC addresses. Use more than one key and define which source is authoritative for each attribute.

Look for the gaps

The differences between sources are where the findings are:

  • Seen on the network but no endpoint agent: an unmanaged device. Investigate, then enroll, remove or isolate it, in line with Safeguard 1.2.
  • In the directory but not seen on the network for a long time: probably a stale record. Confirm and retire it.
  • In purchasing records but never seen anywhere: either sitting in a cupboard or deployed somewhere your tools can't see.
  • Running in the cloud with no owner tag: find out who started it.

Run this comparison on a schedule, weekly if you can, and track the number of unexplained assets over time. A falling number is a good sign the process is working.

How do you keep a CMDB clean?

Many organizations hold their inventory in a configuration management database (CMDB). A CMDB is only useful if people trust it, and trust disappears quickly once records go stale.

A few habits keep it healthy:

  • Automate the feeds. Manual entry falls behind within weeks. Import from discovery sources on a schedule.
  • Keep required fields short. Owner, location, environment, criticality and status. Add more only when someone actually uses them.
  • Track lifecycle states. Ordered, in stock, deployed, retired and disposed. A retired asset should drop out of scanning scope and licensing counts at the same time.
  • Record "last seen" from every source. Flag anything not seen by any source for 30 days for review.
  • Tie decommissioning to the inventory. Removing a server should also remove its DNS records, firewall rules, backup jobs and monitoring.
  • Spot-check it. Pick a random sample each quarter and verify the records physically or through the console.

What about cloud and ephemeral assets?

Cloud resources can appear and disappear in minutes. Autoscaling groups, containers and serverless functions may never exist long enough for a weekly scan to find them.

For these assets, inventory the patterns rather than every instance:

  • Track images and templates. If every instance launches from the same image, scanning and patching the image covers the fleet.
  • Enforce tags at creation. Require owner, environment and data classification tags, and block or flag resources created without them.
  • Query cloud APIs frequently. Daily at a minimum, or subscribe to change events so new resources appear in near real time.
  • Watch what's public. Internet-facing addresses, open storage buckets and exposed management ports deserve their own report, because misconfiguration there causes serious exposure.

Who should own each asset?

An asset without an owner is an asset nobody will patch. Every item in the inventory should have two named owners:

  • A business owner, accountable for the asset and able to approve downtime or accept risk.
  • A technical owner, responsible for configuration, patching and decommissioning.

Assign ownership as part of provisioning, not afterwards. Tie it to something that updates automatically, such as a department, cost center, directory group or cloud tag, so it doesn't break every time someone changes roles. When an owner leaves, their assets should land in a queue for reassignment rather than silently becoming orphans.

Frequently asked questions

How often should an asset inventory be updated?

Continuously, through automated feeds. CIS Safeguard 1.1 sets a bi-annual review as the minimum, but the IG2 safeguards expect active discovery to run daily and DHCP logs to be reviewed weekly. For vulnerability management, stale data is almost as unhelpful as no data.

Is a spreadsheet good enough?

For a very small organization, a well-maintained spreadsheet can meet the IG1 inventory safeguards. Once you have more than a few dozen devices or any cloud footprint, manual updates can't keep pace and you'll need automated discovery feeding a central record.

Should printers, cameras and other IoT devices be included?

Yes. Control 1 explicitly includes non-computing and IoT devices. They run software, sit on your network and have vulnerabilities, and they're often the assets nobody is watching.

Next steps

  • Start with CIS Safeguards 1.1, 1.2, 2.1, 2.2 and 2.3 if you don't have a working inventory today.
  • List your current discovery sources and note what each one can't see.
  • Reconcile at least two sources this month and investigate every unexplained asset.
  • Make owner a required field, and assign one to every asset that's missing it.
  • Add every cloud account and subscription to your inventory scope, not just the ones you manage day to day.