Back to glossary

Asset inventory

1 min read

An asset inventory is an authoritative and current list of the systems, services, accounts and data an organisation owns. In security it is the control everything else depends on, because scope, patching, monitoring and incident response all resolve against it: you cannot defend what is not on the list.

July 24, 2026
Compartir:

Authoritative and current are the two words doing the work. Most organisations have several partial lists that disagree: a spreadsheet from the last audit, the cloud provider’s console, the endpoint agent’s console, the directory, and the billing report. Each is complete for its own domain and blind outside it, and the gaps between them are exactly where shadow IT and forgotten hosts live.

What makes an inventory usable for security is not the field count but ownership and freshness. An entry needs a named owner, a business criticality, an exposure state and a date it was last confirmed by something automated. Entries that only a human updates decay immediately.

The inventory is also the first thing that gets contradicted on an engagement. It is routine for external discovery to return hosts that appear on no list, and for those hosts to be the weakest ones, because nothing that runs against the inventory has ever touched them. That contradiction is the finding, and it is written against the process rather than the host. Feeding attack surface management results back into the register is what closes it, and rebuilding a defensible register is a standing task in the due diligence work where the inventory is the first thing we rebuild.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.