- Device export from the endpoint manager (or the honest list built by hand if none exists)
- Device and account registrations from the identity provider
- Purchase, lease, and disposal records from finance
- For OT assets: a physical walkdown with the process owner, not a network scan
Hardware and Software Asset Inventory
Two working tables — one for every device, one for every installed application — plus the reconciliation routine that keeps them honest: endpoint manager against identity provider against purchase records, with every mismatch explained or investigated.
Purpose, inputs, and completion
Purpose. You cannot defend, patch, back up, or retire what you do not know you have — every other practice inherits its scope from this document. This inventory holds the device and software lists in one owned place and, more importantly, forces the monthly reconciliation that keeps them true. An inventory that is never compared against another source of truth is a list of what you believed last quarter.
When to use it. Complete the scope section first so it is explicit which sites, networks, and asset classes this inventory claims to cover. Fill the hardware table from same-day exports of your endpoint manager and identity provider, and the software table from the endpoint manager's installed-software report. Then run the reconciliation checklist and log every unexplained difference in the final section with an owner and a date. Repeat the reconciliation monthly; repeat the full verification — including the OT walkdown — annually.
- Export devices from the endpoint manager and registrations from the identity provider on the same day, then merge into the hardware table — same-day exports are the only ones worth comparing.
- Walk the software table from what is actually installed (endpoint manager software report), not from what was purchased; the difference between the two lists is the finding.
- For OT assets, verify by walkdown during a maintenance window with the process owner present — never by active scanning, which can disrupt production equipment.
- Mark every device or application you cannot attribute to an owner as INVESTIGATE with a date; an unowned asset is an unmanaged asset.
- Record support status and end-of-life dates as you go — the EOL column is the feeder for technical-debt retirement planning.
Evidence, validation, and failure modes
- A dated, owned hardware inventory with support status and verification dates a reviewer can sample against reality
- A software inventory that separates authorized from discovered-and-unauthorized software
- A reconciliation record showing the deltas between endpoint manager, identity provider, and purchase records — and what was done about each
- Pick five devices at random from the endpoint manager and five from the identity provider; every one must appear in the hardware table with an owner and a last-verified date.
- Pick three rows from the hardware table and physically locate the devices (or confirm disposal paperwork); a row you cannot walk to or explain is a stale row.
- The inventory is an export, not a reconciliation — three tools each hold a different device count and nobody has explained the difference.
- OT assets are 'inventoried' from a network scan that missed everything serially connected or air-gapped — and disrupted a PLC in the process.
- Software rows record what was bought, not what is installed; the unauthorized remote-access tool on two machines never appears.
Practices and requirements this artifact relates to
Brilliant at the Basics practices
NIST SP 800-171 Rev. 2
NIST SP 800-171 Rev. 3
Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain twelve months of reconciled monthly snapshots plus every annual verification; the trend of unexplained deltas is evidence of whether the inventory actually operates.
Preview — exactly what prints
Hardware and Software Asset Inventory
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
You cannot defend, patch, back up, or retire what you do not know you have — every other practice inherits its scope from this document. This inventory holds the device and software lists in one owned place and, more importantly, forces the monthly reconciliation that keeps them true. An inventory that is never compared against another source of truth is a list of what you believed last quarter.
How to use it
Complete the scope section first so it is explicit which sites, networks, and asset classes this inventory claims to cover. Fill the hardware table from same-day exports of your endpoint manager and identity provider, and the software table from the endpoint manager's installed-software report. Then run the reconciliation checklist and log every unexplained difference in the final section with an owner and a date. Repeat the reconciliation monthly; repeat the full verification — including the OT walkdown — annually.
Inventory scope and method
State what this inventory covers and where each column's data comes from, so the next person can rebuild it without you.
Scope and sources
| Sites and networks covered | Asset classes covered (IT endpoints, servers, network gear, OT, mobile) | Systems of record used (endpoint manager, identity provider, purchase records) | Deliberately excluded, and why |
|---|---|---|---|
IT assets are verified from management tooling; OT assets are verified by walking the floor. Both belong in the same hardware table so that nothing falls between the two owners — the managed-by column records which track each row follows.
Hardware asset inventory
One row per device that stores, processes, or transmits company or contract information — including OT equipment, network gear, and anything a backup touches.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Asset tag / ID | Type | Make and model | OS / firmware version | Owner | Location | Managed by | Support status / EOL date | Sensitive data authorized? | Last verified |
|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE: LT-0042 | Laptop | Dell Latitude 5550 | Windows 11 24H2 | J. Rivera (Engineering) | Main site / mobile | Internal IT — endpoint manager | Supported; warranty to 2028-03 | Yes — CUI project library | 2026-07-15 |
| EXAMPLE: CNC-07 | OT controller (CNC) | Haas NGC | Firmware 21.04 | Plant leader | Shop floor, cell 3 | Vendor support contract | EOL 2027-12 — replacement planned | No | 2026-06-20 (walkdown) |
Do not run discovery or vulnerability scans against production equipment to populate this table — active scanning can stall controllers and stop lines. OT rows are verified by physical walkdown with the process owner during a scheduled maintenance window, and vendor-managed equipment is confirmed with the vendor's own service records.
Software asset inventory
One row per application actually installed or in use — from the endpoint manager's installed-software report, not from the purchasing spreadsheet.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Software name | Version(s) in use | Publisher | Install count | Business owner | Support status | Authorized? |
|---|---|---|---|---|---|---|
| EXAMPLE: SolidWorks | 2025 SP3 | Dassault Systèmes | 8 | Engineering lead | Supported | Yes |
| EXAMPLE: TeamViewer (free edition) | 15.x | TeamViewer SE | 2 | None identified | Unsupported edition | No — remove; found during reconciliation |
Software with no business owner, or marked unauthorized, does not stay in limbo: it gets a removal date or an authorization decision, logged in the follow-ups section. Unsupported versions feed the technical-debt retirement plan — the support-status column is where that plan starts.
Reconciliation against source records
The inventory earns its keep here. Three sources, compared on the same day, with every difference explained or assigned.
Monthly reconciliation routine
Run in order; record counts and deltas in the follow-ups section.
- Export the device list from the endpoint manager and the device/account registrations from the identity provider on the same day.
- Compare: every device in the identity provider but not the endpoint manager is either unmanaged or unenrolled — investigate each one.
- Compare both against purchase and disposal records: purchased-but-never-seen suggests shadow deployment or theft; seen-but-never-purchased suggests personal or vendor equipment.
- Classify every mismatch: EXPLAINED (with the reason written down) or INVESTIGATE (with an owner and date in the follow-ups section).
- Record the three source counts and the number of unexplained deltas; the month-over-month trend of that last number is the health of this inventory.
Gaps and follow-ups
Every INVESTIGATE from the tables and the reconciliation lands here with an owner and a date. This section is the difference between an inventory and a to-do list nobody reads.
Open items
| Item (device, software, or delta) | What is unexplained | Owner | Resolve by |
|---|---|---|---|
Document control, version history, and approval
An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.
| Field | Entry |
|---|---|
| Document owner (named person) | |
| Suggested owner role | IT leader |
| Approval authority | Executive sponsor |
| Review frequency | Monthly reconciliation against source systems; full verification annually and at every acquisition, disposal, or site change |
| Next scheduled review | |
| Storage location of the completed document | |
| Retention | Retain twelve months of reconciled monthly snapshots plus every annual verification; the trend of unexplained deltas is evidence of whether the inventory actually operates. |
Version history
| Version | Date | Author | Summary of change | Approved by |
|---|---|---|---|---|
Review and approval
| Reviewed by | Role | Date | Signature / initials |
|---|---|---|---|
Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.
This is independent educational material. Completing it documents your work and produces records a reviewer can examine — it does not, by itself, implement a safeguard, satisfy any NIST SP 800-171 requirement, establish compliance with DFARS or CMMC, or replace your own analysis within your defined system boundary. Requirement references are mapped relationships, not equivalence claims. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.