Skip to main content

Information Technology (IT) Equipment and Systems Inventory

Companies that inventory their network systems, IT equipment and devices, as well as the installation and use of software programs and applications, are better able to protect against cyber-attacks. A common practice used by attackers to breach a company’s network is to continuously scan Internet Protocol (IP) addresses of targeted companies looking for vulnerabilities in their equipment or software that can be remotely exploited. Potential vulnerabilities include, but are not limited to:

  • Out of date software patches or anti-virus signatures.
  • Unauthorized software programs installed by employees without adequate testing.
  • Unauthorized personal devices used by employees to connect to the network that are not secure.

Companies that do not inventory their IT equipment and systems and/or the installation and use of programs that run on their computers and other devices may be more vulnerable to these types of attacks. To help minimize this threat, inventory all network systems and network devices and assign an asset owner responsible for each inventoried system or device.

Because the equipment, software and applications are normally purchased directly from contracted suppliers and service providers, they can be an excellent resource for assisting with developing the inventory.

Chief Information Security Officer (CISO)

The CISO should coordinate with the company business managers and your third-party providers to develop and maintain the company IT asset inventory. In addition to maintaining the inventory, the CISO should also be responsible for developing a list of authorized software and equipment that is allowed on the network.

A procedure should also be established to require that all new software or equipment must be reviewed and tested to validate that its installation or use will not disable or bypass network security controls.

Equipment inventory

The equipment inventory should include every device that is on the network or has access to it, including, but not limited to desktops, laptops, mobile devices, servers, network equipment (routers, switches, firewalls, etc.), and printers. Whether physical or virtual, all equipment that has access to the company network should be included in the asset inventory. It should also include the name of a specific person who is responsible for it and its department or location.

Any equipment that you have not authorized should be removed.

Software and applications inventory

Companies should also develop an inventory of all computer software and applications. They should be mapped to the business functions they support and the hardware (including servers, workstations, and laptops) on which they reside.

Any software or applications that you have not authorized should be removed.

IT asset management

A formal IT asset inventory management process can help companies keep track of and routinely monitor all the devices, software and applications on its network from request and procurement to disposal. Inventories should be periodically conducted to confirm accuracy and to confirm no unapproved devices or software were added to the network. Inventories should be updated whenever a device, software or application is added or removed from the network.

Related resources

Cyber Risk and Your Company Website

This bulletin discusses the importance of network security as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Map and Secure Your Network

This article discusses the importance of mapping and securing your network as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Administrator Privileges

An important step in providing security for your network is to establish and enforce administrator privileges. Inappropriate use of administrator privileges is often found to be a major contributory factor to data breaches or corruption of data.