2.3 Secure Provisioning & Asset Management
Secure Provisioning & Asset Management at a glance
An organisation cannot reliably secure assets it does not know exist, cannot locate or cannot assign responsibility for.
Secure provisioning and asset management ensure that information, hardware, software and services are identified, authorised, recorded, assigned appropriate ownership and managed throughout their lifecycle.
Know the Asset
Identify what exists and maintain an appropriate inventory.
What do we have?Know the Owner
Establish accountability for important information and assets.
Who is responsible?Manage the Lifecycle
Track assets from acquisition through operation and eventual retirement.
What state is it in?Secure asset provisioning flow
1 What does Secure Provisioning mean? Introduce assets into the environment in a controlled way
Provisioning is the process of preparing and making an information resource, device, system, service or other asset available for an authorised business purpose.
Secure provisioning means security is considered before or as the asset enters service rather than attempting to discover and secure it later.
A controlled provisioning process may include
A new server is required for a customer application.
Instead of simply connecting it to the network, the organisation:
- approves the business requirement;
- records the server in the asset inventory;
- assigns an owner;
- identifies which business service it supports;
- applies an approved secure configuration;
- enables appropriate monitoring;
- then places it into production.
An asset discovered only after it has been operating for six months has already spent six months outside normal asset-management processes.
2 What is Asset Management? Know what exists and manage it throughout its lifecycle
Asset management provides visibility and accountability for resources that have value to the organisation.
Security asset management helps answer questions such as:
You cannot reliably protect what you do not know you have.
3 Tangible and Intangible Assets Asset inventory extends beyond physical equipment
Assets with physical form.
Assets that have value but may not exist as a physical object.
A laptop is a tangible asset.
The customer database, software licence, source code and intellectual property accessible through that laptop are intangible assets.
Asset management must consider both categories.If a question says "asset inventory," do not think only about serial numbers attached to computers.
4 Information and Asset Ownership Every important asset needs accountability
Important information and assets should have appropriate ownership so somebody has authority and accountability for decisions concerning their use and protection.
Has authority over specified information and is responsible for determining or establishing appropriate protection requirements.
Is accountable for an asset's business use, importance and appropriate management according to organisational processes.
Performs operational activities and implements controls according to requirements established by owners and policy.
Uses the asset for an authorised business purpose and follows applicable handling and security requirements.
Finance owns a financial-reporting application because it understands the business purpose and consequences of failure.
The infrastructure team operates the servers supporting it.
Operating the technology does not automatically make infrastructure the business owner of the application.Operational responsibility can be delegated while accountability remains with an appropriate owner.
๐ค What might an Asset Owner do? Ownership should lead to decisions
Exact responsibilities vary between organisations, but asset ownership commonly supports decisions such as:
A database administrator knows how a customer database operates.
The customer-services business owner understands how the database affects customers and business processes.
Different responsibilities require different types of knowledge.Owner vs Custodian memory aid
Owner = ACCOUNTABILITY ยท Custodian = OPERATION
5 Asset Inventory Create reliable visibility of organisational assets
An asset inventory records assets that the organisation needs to manage.
The inventory should contain enough information to support security, operational and business decisions.
Possible inventory fields
Asset: PAYMENTS-DB-01
Type: Production database
Owner: Payments Service Owner
Business Service: Customer Payments
Classification: Confidential
Criticality: Critical
Environment: Production
A list containing only hostnames may be useful technically, but it is far more valuable when assets can also be connected to owners, services, criticality and business context.
๐ What should be inventoried? Modern asset inventories contain more than computers
Servers, laptops, phones, network devices, IoT, OT and removable media.
Operating systems, applications, packages and installed software.
Business applications and technology platforms.
SaaS, PaaS, IaaS, APIs, managed services and other external services.
Important information sets, repositories and designated data types.
Virtual machines, containers and cloud resources.
A cloud database or SaaS platform can be an important organisational asset even though the organisation owns no physical hardware associated with it.
๐ป Hardware Asset Management Know which physical devices are authorised
Hardware asset management provides visibility of physical devices operating within or on behalf of the organisation.
Examples include
Useful information may include
- manufacturer and model;
- serial number;
- unique asset identifier;
- assigned user or owner;
- physical or logical location;
- business purpose;
- operating status;
- support status.
Security monitoring identifies an unknown server communicating on the corporate network.
The device is not present in the authorised hardware inventory.
This discrepancy should be investigated rather than assuming the server is legitimate.๐ฟ Software Asset Management Know what software is running
Software is also an organisational asset and should be appropriately inventoried and managed.
Software inventory may include
A critical vulnerability affects Version 4.2 of a widely used application.
An accurate software inventory can help determine which endpoints or systems have that version installed.
Knowing that a vulnerability exists is much less useful if the organisation cannot determine where the affected software exists.
โ๏ธ Cloud and Service Assets Inventory services you use, not just infrastructure you own
Organisations increasingly depend on externally hosted services that should also be visible within asset-management processes.
The marketing department purchases a cloud campaign-management platform using a corporate credit card.
Customer information is uploaded to it, but the security and technology teams do not know the service exists.
The organisation now has an unmanaged external asset and data dependency.The organisation does not need to physically own the infrastructure for the service to be important to its security and business operations.
6 Asset Identification and Tagging Give assets identities that can be tracked
Assets may be assigned identifiers that allow them to be reliably distinguished and tracked.
Examples include
Two identical laptops are issued to different employees.
Manufacturer and model alone cannot distinguish them.
Unique identifiers allow each device to be separately recorded, assigned and tracked.
An asset is easier to manage when the organisation can reliably distinguish it from every other similar asset.
7 Secure Provisioning Checklist Before an asset enters production
Why does the organisation need the asset?
Has the appropriate acquisition or deployment been approved?
Can the asset be identified and tracked?
Who is accountable for its business use?
What sensitivity and criticality apply?
Has the asset been prepared according to appropriate security standards?
Who is authorised to administer or use it?
Is appropriate security and operational visibility available?
Can the organisation track future changes to the asset?
๐ก๏ธ Secure Configuration During Provisioning Do not deploy assets with unnecessary exposure
Secure provisioning often includes applying an approved baseline or required configuration before an asset enters service.
Examples may include
A manufacturer ships a network appliance with a default administrator password.
The device is connected directly to production without changing the credential.
The asset was acquired, but it was not securely provisioned.Detailed configuration-management concepts are covered elsewhere in the CISSP domains, but asset security begins by ensuring assets do not enter service unmanaged or insecurely configured.
โ Authorised vs Unauthorised Assets Presence does not equal permission
Known to the organisation and permitted for the relevant business purpose.
Present or being used without appropriate organisational approval.
An employee connects a personal wireless access point to the corporate network because Wi-Fi coverage is poor.
The device functions perfectly.
Functionality does not make it an authorised organisational asset.Assets detected in the environment that do not match authorised inventory records may require investigation.
๐ป Shadow IT Business technology operating outside normal governance
Shadow IT refers broadly to technology, applications or services used for business purposes outside expected organisational approval or management processes.
Examples
A team needs a project-management tool immediately.
They sign up for a SaaS service without informing technology, procurement or security teams.
Project plans and customer information are uploaded.
The organisation may now lack visibility of the service, data, supplier risk and access arrangements.If an asset is unknown, it may also be absent from vulnerability management, access reviews, monitoring, retention and incident response.
8 Inventory vs Discovery What should exist vs what actually exists
Records assets the organisation knows about and manages.
Detects assets that actually exist in an environment.
Inventory says what SHOULD exist.
Discovery helps show what DOES exist.
Inventory contains 950 corporate endpoints.
Network discovery identifies 975 endpoints.
The additional 25 devices should be investigated.๐ Asset Reconciliation Keep records aligned with reality
Asset information can become inaccurate as environments change.
Reasons include
An asset inventory says a laptop belongs to Employee A.
Employee A left six months ago and the laptop was reassigned to Employee B, but the inventory was never updated.
The inventory exists, but its information is unreliable.An outdated inventory can create false confidence.
9 Asset Assignment and Accountability Know who has custody of organisational assets
Physical and logical assets may be assigned to individuals, teams or services.
An employee receives:
- a laptop;
- a mobile phone;
- a hardware security token;
- a building access card.
Each asset can be associated with the employee so accountability and eventual recovery are easier.
๐ Asset Location Know where important assets reside
Location may be relevant to physical security, data protection, resilience, regulatory obligations and incident response.
Location may mean
An organisation knows it owns 5,000 laptops.
It cannot determine which employees hold 400 of them.
Quantity alone is not sufficient asset visibility.๐ Asset Relationships and Dependencies Assets rarely operate alone
Understanding relationships between assets can make an inventory much more useful for security and resilience.
A vulnerable server appears to be a low-value infrastructure asset.
Asset relationships reveal that it supports the database behind a critical payment service.
Understanding relationships adds important business context.๐๏ธ Asset Inventory and CMDB Related concepts, but not necessarily identical
Organisations may use several systems to manage asset information.
Focuses on identifying and tracking organisational assets.
A Configuration Management Database may record configuration items and relationships between components supporting services.
An asset-management system may record that the organisation owns Server 12345.
A CMDB may additionally record that Server 12345 supports Database A, which supports Application B, which provides Business Service C.
CISSP questions are usually more concerned with understanding and managing assets than with selecting a particular commercial database product.
โ๏ธ Dynamic and Ephemeral Assets Modern assets may exist only briefly
Traditional asset management often focused on physical devices that remained in use for years.
Modern environments can create and remove assets automatically.
A development pipeline automatically creates 100 containers in the morning and destroys them that afternoon.
A manual spreadsheet updated once per year cannot provide useful visibility of this environment.Highly dynamic infrastructure may require automated discovery and inventory updates.
10 Asset Changes Inventory should change when the asset changes
Asset records may need to be updated when important attributes change.
A new business owner becomes accountable.
The asset moves between sites or environments.
The sensitivity of information changes.
The asset begins supporting a different business process.
Software or hardware is upgraded or replaced.
Production, maintenance, storage or retirement status changes.
An inventory created once and never maintained gradually becomes a historical record rather than a reliable representation of the environment.
11 The Asset Lifecycle Manage assets from acquisition through retirement
Secure provisioning is only the beginning. Asset information and controls need to remain relevant throughout the period in which the asset is used.
End of Life and End of Support are covered specifically in CISSP objective 2.5, so retirement is introduced here without duplicating that lesson.
๐ถ Asset Lifecycle States Know whether an asset is active, stored or leaving service
Asset inventories can be more useful when they record an asset's current lifecycle state.
Approved but not yet received.
Being prepared for authorised use.
Currently operating.
Temporarily undergoing servicing or change.
Retained but not currently operational.
No longer authorised for normal operational use.
Actual lifecycle labels vary between organisations.
๐จ Lost, Stolen and Missing Assets Inventory improves incident response
When an asset is lost or stolen, reliable inventory information can help the organisation understand what has happened.
Useful questions include
An employee reports a laptop stolen.
The asset inventory identifies the serial number, assigned employee, device-management record and business classification.
This information can support incident investigation and response.๐ฉน Asset Management and Vulnerability Management Find the vulnerable technology before you can fix it
Asset management provides important context for vulnerability management.
Security identifies a critical vulnerability affecting a specific database version.
Accurate inventory data shows:
- 12 affected databases;
- their owners;
- which are production;
- which support critical services;
- which are already scheduled for retirement.
๐ Asset Management and Incident Response Know what the compromised asset actually does
During a security incident, responders may need rapid information about an affected asset.
Malware is detected on server APP-327.
Without asset-management context, the SOC sees only a hostname.
The asset record reveals that APP-327 supports the organisation's online payment service.
Incident priority and response decisions can now reflect the business importance of the server.โ Orphaned Assets What happens when nobody owns the asset?
An asset may remain operational even after its original owner, team or project disappears.
A temporary application is created for a two-year project.
The project ends and the team is dissolved.
Three years later, the application is still running but nobody knows who is responsible for patching, access reviews or retirement.
The organisation has an orphaned asset.If an owner leaves or a team changes, important assets should be reassigned rather than becoming unmanaged.
๐ Periodic Asset Review Does this asset still need to exist?
Organisations should periodically or event-driven review important assets and inventory information.
Questions include
Review finds a development server that has not been used for 18 months.
It remains connected to the network and continues to require vulnerability management and monitoring.
Removing unnecessary assets can reduce both cost and attack surface.๐ช Retiring an Asset Removing an asset from service is part of asset management
Asset-management processes should continue when an asset leaves operational use.
Retirement may involve
A server is powered off permanently.
However, its administrator credentials remain active, DNS records remain configured and the inventory continues to list it as a production system.
Technical shutdown alone does not complete the asset-management lifecycle.End of Life, End of Support and asset-retention decisions are covered in detail in CISSP objective 2.5.
๐ What makes a good Asset Inventory? Complete, accurate, current and useful
Relevant assets are represented.
Recorded information reflects reality.
Changes are reflected within an appropriate timeframe.
Important assets have accountable owners.
Records contain enough business information to support decisions.
Security and operational processes can consume the information.
Inventory quality memory aid
Complete. Accurate. Current.
๐งฉ Asset Management vs Configuration Management Related but not identical
Focuses on assets, their ownership, value, lifecycle and accountability.
Think: What do we HAVE?
Focuses more specifically on the configuration and controlled changes of systems and components.
Think: How is it CONFIGURED?
Asset management records that Server A exists, belongs to Service X and is owned by Team Y.
Configuration management may record the approved operating system, installed components and configuration state of Server A.
Reliable cybersecurity needs visibility of both the asset itself and, where necessary, how that asset is configured.
โ ๏ธ Common mistakes Asset-management concepts people frequently misunderstand
Asset management can include hardware, software, services, systems, information and other tangible and intangible assets.
Functionality does not prove that the asset is authorised, inventoried, owned or appropriately secured.
Technical administration and business ownership are different responsibilities.
Services and cloud resources can still be important organisational assets and dependencies.
Asset environments change continuously. Inventories need to remain accurate and current.
Discovery detects what exists. Inventory records what the organisation knows about and manages.
Unknown assets should be reconciled against approved inventory and investigated as appropriate.
Highly dynamic environments may require automated discovery and inventory processes.
Business ownership, criticality, classification and service relationships provide additional context needed for risk decisions.
Access, credentials, data, inventory records, licences and disposal may still require action.
Unknown technology can bypass security assessment, monitoring, vulnerability management, data controls and supplier-risk processes.
Business dependency, information sensitivity, operational impact and other consequences may make an inexpensive asset extremely important.
Think visibility, ownership and lifecycle
CISSP questions may describe an unknown device, unowned application, inaccurate inventory or new asset entering an environment.
Look for the answer that creates authorisation, accountability and reliable asset visibility before jumping immediately to a technical security product.
๐ Visibility clues
๐ค Ownership clues
๐ Inventory clues
๐ก๏ธ Provisioning clues
๐ Lifecycle clues
โ ๏ธ Risk clues
For any important asset ask:
Do we know it exists? Is it authorised? Who owns it? What does it support? Is it being managed throughout its lifecycle?
๐ Practice scenarios Apply asset-management thinking
Scenario 1
Network monitoring detects an unknown server connected to the production network.
What should happen?
Reconcile the server against the authorised asset inventory and investigate why it is present before assuming it is legitimate.
Scenario 2
A system administrator operates a database containing customer records.
Does this automatically make the administrator the information owner?
No. Technical custody and business ownership are separate concepts.
Scenario 3
A marketing team purchases an unapproved SaaS application and uploads customer data.
Which issue does this illustrate?
Shadow IT and an unmanaged cloud/service asset.
Scenario 4
An organisation discovers that its inventory says 950 endpoints exist while automated discovery detects 975.
What is the appropriate response?
Investigate and reconcile the difference.
Scenario 5
A critical vulnerability affects Software Version 8.4.
What asset-management capability helps most immediately?
An accurate software inventory capable of identifying where that version exists.
Scenario 6
An application is still running five years after the project that created it ended.
Nobody accepts responsibility for it.
What problem exists?
The application has effectively become an orphaned asset.
Scenario 7
A new server is connected to production with the manufacturer's default administrator password.
What failed?
Secure provisioning and configuration before deployment.
Scenario 8
The organisation records every physical server but does not inventory its SaaS applications.
What is missing?
Visibility of important service and intangible assets.
Scenario 9
A laptop inventory shows Employee A as the custodian, but Employee A left the organisation six months ago.
What does this demonstrate?
Asset inventory data has not been properly maintained or reconciled.
Scenario 10
An inexpensive server supports the authentication service used by every customer-facing application.
Should its value be judged only by purchase price?
No. Its business dependency and criticality may make it extremely important.
Scenario 11
A container exists for only 15 minutes during an automated software build.
Does its short lifetime mean asset visibility is irrelevant?
No. Dynamic environments may require automated asset-management approaches rather than traditional manual inventories.
Scenario 12
A stolen laptop is reported but the organisation cannot identify its serial number, assigned employee or whether disk encryption was enabled.
What organisational capability was weak?
Asset inventory and asset-management records.
Scenario 13
A business application has been shut down permanently but still appears as an active production asset in every inventory.
What should occur?
Complete the retirement process and update the authoritative asset records.
Scenario 14
Security identifies malware on HOST-8472 but has no information about what the server actually supports.
What additional asset information would be valuable?
Business service, owner, criticality, classification and dependency information.
Scenario 15
A business manager assumes the infrastructure team owns an application because infrastructure operates its servers.
What principle should be clarified?
Technical custody does not necessarily equal business asset ownership.
Secure Provisioning memory aid
Authorise. Register. Own. Secure. Manage.
The five Asset Management questions
What. Where. Who. Why. Status.
Inventory vs Discovery
Know. Discover. Compare. Correct.
Key takeaways
CISSP objective 2.3 covers secure provisioning, information and asset ownership, asset inventory and asset management.
Secure provisioning means introducing authorised assets into the environment through controlled processes rather than allowing technology to appear unmanaged.
An organisation cannot reliably protect assets it does not know exist.
Assets can be tangible or intangible.
Hardware, software, information, services, cloud resources, intellectual property and other resources may all require asset-management visibility.
Important assets should have appropriate ownership and accountability.
Asset ownership is not necessarily the same as technical administration or custody.
Asset inventories should contain enough information to support security and business decisions rather than merely listing technical identifiers.
Useful context can include owner, location, business service, classification, criticality, status and lifecycle state.
Hardware and software should both be inventoried appropriately.
Cloud services and other externally hosted services can also represent important organisational assets and dependencies.
Inventory represents what the organisation knows about; discovery helps identify what actually exists.
Differences between inventory and discovery should be investigated and reconciled.
Asset inventories should remain complete, accurate and current.
Shadow IT can create security risk because technology may operate outside normal inventory, assessment and governance processes.
Dynamic cloud and container environments may require automated asset discovery rather than relying only on manual records.
Asset-management information provides valuable context for vulnerability management and incident response.
Orphaned assets create risk because systems can continue operating after clear business ownership disappears.
Asset management continues through the lifecycle from acquisition and provisioning through operation, change and eventual retirement.
Most importantly: know what exists, know who owns it, know why it matters and keep that information accurate throughout the asset's life.
๐ Sources & Further Reading Authoritative references
- ISC2 โ CISSP Certification Exam Outline
View official CISSP exam outline - NIST Cybersecurity Framework 2.0 โ Asset Management
View NIST CSF 2.0 - NIST CSF 2.0 Reference Tool โ Asset Management
View NIST Asset Management outcomes - NIST โ Asset Glossary Definition
View NIST definition - NIST โ Information Owner Glossary Definition
View NIST definition - NIST โ Hardware Asset Management
View NIST definition - NIST โ Software Asset Management
View NIST definition - NIST SP 800-53 Rev. 5 โ Security and Privacy Controls
View NIST publication
