Security+Operations
Asset management
Outline only. You cannot protect, patch, or retire what you have not inventoried.
8 min read · Outline, not a finished note
Outline. This module is on the map so you can track it. The page below is a writing checklist, not finished study material.
Objectives
- Define an asset broadly enough to include data and accounts
- Connect inventory to the vulnerability-management loop
TODO
Keep the finished note operational and short.
Checklist
- Assets include hardware, software, data, identities, and the vendors that hold any of those.
- Ownership is part of the record. An asset without an owner does not get patched.
- Classification of data assets belongs with the data-protection note. The inventory says the data exists. The label says how to handle it.
- Discovery has to include cloud accounts and shadow IT or the inventory is a wish.
- Disposal and return of equipment are part of the lifecycle, not an afterthought, and they connect to confidentiality.