Information Technology (IT) Equipment and Systems Inventory
Companies that inventory their network systems, IT equipment and devices, as well as the installation and use of software programs and applications, are better able to protect against cyber-attacks. A common practice used by attackers to breach a company’s network is to continuously scan Internet Protocol (IP) addresses of targeted companies looking for vulnerabilities in their equipment or software that can be remotely exploited. Potential vulnerabilities include, but are not limited to:
- Out of date software patches or anti-virus signatures.
- Unauthorized software programs installed by employees without adequate testing.
- Unauthorized personal devices used by employees to connect to the network that are not secure.
Companies that do not inventory their IT equipment and systems and/or the installation and use of programs that run on their computers and other devices may be more vulnerable to these types of attacks. To help minimize this threat, inventory all network systems and network devices and assign an asset owner responsible for each inventoried system or device.
Because the equipment, software and applications are normally purchased directly from contracted suppliers and service providers, they can be an excellent resource for assisting with developing the inventory.
Chief Information Security Officer (CISO)
The CISO should coordinate with the company business managers and your third-party providers to develop and maintain the company IT asset inventory. In addition to maintaining the inventory, the CISO should also be responsible for developing a list of authorized software and equipment that is allowed on the network.
A procedure should also be established to require that all new software or equipment must be reviewed and tested to validate that its installation or use will not disable or bypass network security controls.
Equipment inventory
The equipment inventory should include every device that is on the network or has access to it, including, but not limited to desktops, laptops, mobile devices, servers, network equipment (routers, switches, firewalls, etc.), and printers. Whether physical or virtual, all equipment that has access to the company network should be included in the asset inventory. It should also include the name of a specific person who is responsible for it and its department or location.
Any equipment that you have not authorized should be removed.
Software and applications inventory
Companies should also develop an inventory of all computer software and applications. They should be mapped to the business functions they support and the hardware (including servers, workstations, and laptops) on which they reside.
Any software or applications that you have not authorized should be removed.
IT asset management
A formal IT asset inventory management process can help companies keep track of and routinely monitor all the devices, software and applications on its network from request and procurement to disposal. Inventories should be periodically conducted to confirm accuracy and to confirm no unapproved devices or software were added to the network. Inventories should be updated whenever a device, software or application is added or removed from the network.