Asset and configuration inventory
Record device versions, identities, owners and dependencies in the inventory. Include the recovery information needed to assess changes and investigate incidents.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.
On this page
Overview#
An inventory must support vulnerability triage, flow control, certificate renewal, interoperability, recovery, privacy review and decommissioning. IP address and product name alone don't identify a physical security asset adequately.
Minimum asset record#
| Category | Fields |
|---|---|
| Identity | Stable asset ID, site/zone, role, manufacturer, model, serial, hardware revision |
| Software | Firmware, OS, application, driver/SDK/plugin and dependency versions |
| Interfaces | Physical ports, MAC/IP, serial address, radio identities, cloud tenant/device ID |
| Protocols | Exact versions/profiles, secure mode, role, ports, discovery and enabled options |
| Trust | Certificate fingerprints/serials, issuer, expiry, key purpose, shared key identifier, enrollment owner |
| Access | Admin/operator/service/vendor identities and role/policy mapping |
| Data | Media/events/credentials/biometrics stored or transmitted, retention and destinations |
| Lifecycle | Install, warranty/support end, update source, backup, replacement and disposal status |
| Safety | Actuators/interlocks/egress/fire/elevator dependencies and responsible authority |
| Evidence | Last configuration review, environment validation, deviations, approvals, and source documents |
Don't store passwords, private keys, bearer tokens, biometric templates or full credentials in the inventory. Store references to an approved secret or evidence system.
Configuration baseline#
Capture enabled services, users/roles, network and discovery settings, TLS/certificate policy, protocol/profile options, time, logging, storage/retention, event subscriptions, broker topics/ACLs, integration mappings, update channel, failover/offline behaviour and disabled legacy interfaces. Prefer structured exports where supported, but protect them as sensitive configuration.
Reconciliation#
Reconcile authoritative management inventory with network observation, vendor cloud, controller/server databases, certificate register and physical survey. Discovery can find unexpected assets but must not be treated as the sole inventory because offline, segmented and serial devices may be absent.
Change triggers#
Update inventory after installation, replacement, firmware/software change, role or certificate change, topology/flow change, protocol/profile enablement, cloud ownership transfer, incident, backup restoration and decommissioning. Preserve history sufficient to interpret old events and evidence.
Sources#
- NIST 800 82, NIST SP 800-82 Rev. 3, asset management and OT architecture guidance, accessed 25 August 2026.
- CISA ASSET, CISA Foundations for OT Cybersecurity: Asset Inventory Guidance, accessed 25 August 2026.