Asset management is the practice of maintaining an accurate, current inventory of the systems, devices, applications, and data an organization depends on, along with their configurations and relationships. It answers a deceptively hard question: what do we actually have, and which of it matters most.
Within the Preparation phase, asset management is foundational. Defenders cannot protect, monitor, or recover what they do not know exists. Detection coverage, patching, hardening, and incident response all assume a clear view of the estate, so an incomplete inventory quietly undermines every other control. Knowing which assets are critical also lets teams direct limited effort where the impact of compromise would be greatest.
In practice, asset management tracks hardware and software, ownership, business criticality, dependencies, and configuration state. It draws on discovery tools, cloud and identity data, and configuration management databases, and it treats the inventory as a living record that changes as the environment does. Mapping dependencies reveals how a failure in one system propagates to others, which informs both protection and recovery planning. Accurate asset data turns abstract security goals into specific, actionable priorities.
References#
- CIS Critical Security Controls, Inventory of Enterprise Assets and Software
- NIST SP 800-53, Configuration Management controls