2.3 Secure Provisioning & Asset Management

CISSP Domain 2 ยท 2.3

Secure Provisioning & Asset Management at a glance

An organisation cannot reliably secure assets it does not know exist, cannot locate or cannot assign responsibility for.

Secure provisioning and asset management ensure that information, hardware, software and services are identified, authorised, recorded, assigned appropriate ownership and managed throughout their lifecycle.

๐Ÿ”Ž

Know the Asset

Identify what exists and maintain an appropriate inventory.

What do we have?
๐Ÿ‘ค

Know the Owner

Establish accountability for important information and assets.

Who is responsible?
๐Ÿ”„

Manage the Lifecycle

Track assets from acquisition through operation and eventual retirement.

What state is it in?

Secure asset provisioning flow

๐ŸŽฏ Need โ†’ Why is the asset required?
โœ… Authorise โ†’ Is the asset approved?
๐Ÿ“‹ Register โ†’ Add it to the appropriate inventory
๐Ÿ‘ค Own โ†’ Who is accountable for it?
๐Ÿท๏ธ Classify โ†’ How sensitive or important is it?
๐Ÿ›ก๏ธ Secure โ†’ Apply appropriate security requirements
๐Ÿš€ Deploy โ†’ Place the authorised asset into service
๐Ÿ‘๏ธ Manage โ†’ Track changes throughout its lifecycle
1 What does Secure Provisioning mean? Introduce assets into the environment in a controlled way

Provisioning is the process of preparing and making an information resource, device, system, service or other asset available for an authorised business purpose.

Secure provisioning means security is considered before or as the asset enters service rather than attempting to discover and secure it later.

A controlled provisioning process may include

Business Approval Procurement Inventory Registration Ownership Classification Security Configuration Access Control Asset Identification Deployment
Example

A new server is required for a customer application.

Instead of simply connecting it to the network, the organisation:

  • approves the business requirement;
  • records the server in the asset inventory;
  • assigns an owner;
  • identifies which business service it supports;
  • applies an approved secure configuration;
  • enables appropriate monitoring;
  • then places it into production.
Security should begin before deployment

An asset discovered only after it has been operating for six months has already spent six months outside normal asset-management processes.

2 What is Asset Management? Know what exists and manage it throughout its lifecycle

Asset management provides visibility and accountability for resources that have value to the organisation.

Security asset management helps answer questions such as:

What assets exist?
Where are they?
Who owns them?
What business service do they support?
What information do they process?
How important are they?
Are they authorised?
Are they still required?
Fundamental security principle

You cannot reliably protect what you do not know you have.

3 Tangible and Intangible Assets Asset inventory extends beyond physical equipment
๐Ÿ”ง Tangible Assets

Assets with physical form.

Laptops Servers Phones Routers Storage Devices Security Tokens Buildings
๐Ÿ’ก Intangible Assets

Assets that have value but may not exist as a physical object.

Information Software Licences Services Source Code Intellectual Property Reputation Cloud Resources
Example

A laptop is a tangible asset.

The customer database, software licence, source code and intellectual property accessible through that laptop are intangible assets.

Asset management must consider both categories.
CISSP exam clue

If a question says "asset inventory," do not think only about serial numbers attached to computers.

4 Information and Asset Ownership Every important asset needs accountability

Important information and assets should have appropriate ownership so somebody has authority and accountability for decisions concerning their use and protection.

Information Owner

Has authority over specified information and is responsible for determining or establishing appropriate protection requirements.

Asset Owner

Is accountable for an asset's business use, importance and appropriate management according to organisational processes.

Custodian

Performs operational activities and implements controls according to requirements established by owners and policy.

User

Uses the asset for an authorised business purpose and follows applicable handling and security requirements.

Example

Finance owns a financial-reporting application because it understands the business purpose and consequences of failure.

The infrastructure team operates the servers supporting it.

Operating the technology does not automatically make infrastructure the business owner of the application.
Ownership โ‰  technical administration

Operational responsibility can be delegated while accountability remains with an appropriate owner.

๐Ÿ‘ค What might an Asset Owner do? Ownership should lead to decisions

Exact responsibilities vary between organisations, but asset ownership commonly supports decisions such as:

Business Purpose Classification Criticality Access Requirements Protection Requirements Risk Decisions Review Retention Retirement
Example

A database administrator knows how a customer database operates.

The customer-services business owner understands how the database affects customers and business processes.

Different responsibilities require different types of knowledge.

Owner vs Custodian memory aid

Owner Decides WHAT is required
Custodian Implements HOW it is protected
User Uses it as AUTHORISED

Owner = ACCOUNTABILITY ยท Custodian = OPERATION

5 Asset Inventory Create reliable visibility of organisational assets

An asset inventory records assets that the organisation needs to manage.

The inventory should contain enough information to support security, operational and business decisions.

Possible inventory fields

Asset ID Asset Type Owner Location Business Service Classification Criticality Status Version Supplier Support Status Lifecycle State
Example inventory entry

Asset: PAYMENTS-DB-01

Type: Production database

Owner: Payments Service Owner

Business Service: Customer Payments

Classification: Confidential

Criticality: Critical

Environment: Production

An inventory should support decisions

A list containing only hostnames may be useful technically, but it is far more valuable when assets can also be connected to owners, services, criticality and business context.

๐Ÿ“‹ What should be inventoried? Modern asset inventories contain more than computers
Hardware

Servers, laptops, phones, network devices, IoT, OT and removable media.

Software

Operating systems, applications, packages and installed software.

Systems

Business applications and technology platforms.

Services

SaaS, PaaS, IaaS, APIs, managed services and other external services.

Information

Important information sets, repositories and designated data types.

Virtual Resources

Virtual machines, containers and cloud resources.

Modern assets may never appear in a physical storeroom

A cloud database or SaaS platform can be an important organisational asset even though the organisation owns no physical hardware associated with it.

๐Ÿ’ป Hardware Asset Management Know which physical devices are authorised

Hardware asset management provides visibility of physical devices operating within or on behalf of the organisation.

Examples include

Servers Laptops Desktops Phones Network Devices IoT OT Security Appliances

Useful information may include

  • manufacturer and model;
  • serial number;
  • unique asset identifier;
  • assigned user or owner;
  • physical or logical location;
  • business purpose;
  • operating status;
  • support status.
Example

Security monitoring identifies an unknown server communicating on the corporate network.

The device is not present in the authorised hardware inventory.

This discrepancy should be investigated rather than assuming the server is legitimate.
๐Ÿ’ฟ Software Asset Management Know what software is running

Software is also an organisational asset and should be appropriately inventoried and managed.

Software inventory may include

Product Version Publisher Installation Licence Owner Support Status Approval Status
Example

A critical vulnerability affects Version 4.2 of a widely used application.

An accurate software inventory can help determine which endpoints or systems have that version installed.

Inventory supports vulnerability management

Knowing that a vulnerability exists is much less useful if the organisation cannot determine where the affected software exists.

โ˜๏ธ Cloud and Service Assets Inventory services you use, not just infrastructure you own

Organisations increasingly depend on externally hosted services that should also be visible within asset-management processes.

SaaS IaaS PaaS APIs Managed Services Cloud Databases Identity Providers External Platforms
Example

The marketing department purchases a cloud campaign-management platform using a corporate credit card.

Customer information is uploaded to it, but the security and technology teams do not know the service exists.

The organisation now has an unmanaged external asset and data dependency.
Ownership is different from visibility

The organisation does not need to physically own the infrastructure for the service to be important to its security and business operations.

6 Asset Identification and Tagging Give assets identities that can be tracked

Assets may be assigned identifiers that allow them to be reliably distinguished and tracked.

Examples include

Asset Tag Serial Number Hostname Device ID Cloud Resource ID Software Identifier Inventory Number
Example

Two identical laptops are issued to different employees.

Manufacturer and model alone cannot distinguish them.

Unique identifiers allow each device to be separately recorded, assigned and tracked.

Identification supports accountability

An asset is easier to manage when the organisation can reliably distinguish it from every other similar asset.

7 Secure Provisioning Checklist Before an asset enters production
Business purpose confirmed

Why does the organisation need the asset?

Asset authorised

Has the appropriate acquisition or deployment been approved?

Inventory record created

Can the asset be identified and tracked?

Owner assigned

Who is accountable for its business use?

Classification established

What sensitivity and criticality apply?

Security requirements applied

Has the asset been prepared according to appropriate security standards?

Access established

Who is authorised to administer or use it?

Monitoring established

Is appropriate security and operational visibility available?

Lifecycle captured

Can the organisation track future changes to the asset?

๐Ÿ›ก๏ธ Secure Configuration During Provisioning Do not deploy assets with unnecessary exposure

Secure provisioning often includes applying an approved baseline or required configuration before an asset enters service.

Examples may include

Supported Software Security Updates Approved Configuration Required Logging Endpoint Protection Access Controls Encryption Unnecessary Services Disabled
Example

A manufacturer ships a network appliance with a default administrator password.

The device is connected directly to production without changing the credential.

The asset was acquired, but it was not securely provisioned.
Provisioning should create a known secure starting point

Detailed configuration-management concepts are covered elsewhere in the CISSP domains, but asset security begins by ensuring assets do not enter service unmanaged or insecurely configured.

โœ… Authorised vs Unauthorised Assets Presence does not equal permission
Authorised Asset

Known to the organisation and permitted for the relevant business purpose.

Unauthorised Asset

Present or being used without appropriate organisational approval.

Example

An employee connects a personal wireless access point to the corporate network because Wi-Fi coverage is poor.

The device functions perfectly.

Functionality does not make it an authorised organisational asset.
Inventory and discovery should be compared

Assets detected in the environment that do not match authorised inventory records may require investigation.

๐Ÿ‘ป Shadow IT Business technology operating outside normal governance

Shadow IT refers broadly to technology, applications or services used for business purposes outside expected organisational approval or management processes.

Examples

Unapproved SaaS Personal Cloud Storage Unmanaged Servers Personal Devices Unapproved AI Tools Unknown Databases
Example

A team needs a project-management tool immediately.

They sign up for a SaaS service without informing technology, procurement or security teams.

Project plans and customer information are uploaded.

The organisation may now lack visibility of the service, data, supplier risk and access arrangements.
Security visibility matters

If an asset is unknown, it may also be absent from vulnerability management, access reviews, monitoring, retention and incident response.

8 Inventory vs Discovery What should exist vs what actually exists
Inventory

Records assets the organisation knows about and manages.

Discovery

Detects assets that actually exist in an environment.

The difference between them is valuable

Inventory says what SHOULD exist.

Discovery helps show what DOES exist.

Example

Inventory contains 950 corporate endpoints.

Network discovery identifies 975 endpoints.

The additional 25 devices should be investigated.
๐Ÿ”„ Asset Reconciliation Keep records aligned with reality

Asset information can become inaccurate as environments change.

Reasons include

New Devices Removed Devices Cloud Changes Software Updates Employee Transfers Asset Reassignment Failed Processes
Example

An asset inventory says a laptop belongs to Employee A.

Employee A left six months ago and the laptop was reassigned to Employee B, but the inventory was never updated.

The inventory exists, but its information is unreliable.
Accuracy matters as much as existence

An outdated inventory can create false confidence.

9 Asset Assignment and Accountability Know who has custody of organisational assets

Physical and logical assets may be assigned to individuals, teams or services.

Who received it?
When was it issued?
Where should it be located?
What is its authorised purpose?
When must it be returned or reviewed?
Example

An employee receives:

  • a laptop;
  • a mobile phone;
  • a hardware security token;
  • a building access card.

Each asset can be associated with the employee so accountability and eventual recovery are easier.

๐Ÿ“ Asset Location Know where important assets reside

Location may be relevant to physical security, data protection, resilience, regulatory obligations and incident response.

Location may mean

Office Data Centre Employee Cloud Region Country Third Party Network Segment Repository
Example

An organisation knows it owns 5,000 laptops.

It cannot determine which employees hold 400 of them.

Quantity alone is not sufficient asset visibility.
๐Ÿ”— Asset Relationships and Dependencies Assets rarely operate alone

Understanding relationships between assets can make an inventory much more useful for security and resilience.

๐Ÿ“ฑ Customer Application โ†’ Depends on API
โš™๏ธ API โ†’ Depends on Database
๐Ÿ—„๏ธ Database โ†’ Runs on Infrastructure
โ˜๏ธ Infrastructure โ†’ Depends on Cloud Provider
Example

A vulnerable server appears to be a low-value infrastructure asset.

Asset relationships reveal that it supports the database behind a critical payment service.

Understanding relationships adds important business context.
๐Ÿ—ƒ๏ธ Asset Inventory and CMDB Related concepts, but not necessarily identical

Organisations may use several systems to manage asset information.

Asset Inventory

Focuses on identifying and tracking organisational assets.

CMDB

A Configuration Management Database may record configuration items and relationships between components supporting services.

Example

An asset-management system may record that the organisation owns Server 12345.

A CMDB may additionally record that Server 12345 supports Database A, which supports Application B, which provides Business Service C.

Tool names are less important than reliable visibility

CISSP questions are usually more concerned with understanding and managing assets than with selecting a particular commercial database product.

โ˜๏ธ Dynamic and Ephemeral Assets Modern assets may exist only briefly

Traditional asset management often focused on physical devices that remained in use for years.

Modern environments can create and remove assets automatically.

Virtual Machines Containers Serverless Functions Cloud Storage Temporary Test Environments
Example

A development pipeline automatically creates 100 containers in the morning and destroys them that afternoon.

A manual spreadsheet updated once per year cannot provide useful visibility of this environment.
Asset-management processes should match the environment

Highly dynamic infrastructure may require automated discovery and inventory updates.

10 Asset Changes Inventory should change when the asset changes

Asset records may need to be updated when important attributes change.

Ownership Change

A new business owner becomes accountable.

Location Change

The asset moves between sites or environments.

Classification Change

The sensitivity of information changes.

Purpose Change

The asset begins supporting a different business process.

Technology Change

Software or hardware is upgraded or replaced.

Status Change

Production, maintenance, storage or retirement status changes.

Asset information is not static

An inventory created once and never maintained gradually becomes a historical record rather than a reliable representation of the environment.

11 The Asset Lifecycle Manage assets from acquisition through retirement
๐Ÿ›’ Acquire โ†’ Obtain an authorised asset
๐Ÿ“‹ Register โ†’ Add it to inventory
๐Ÿ›ก๏ธ Provision โ†’ Prepare it securely
๐Ÿš€ Deploy โ†’ Place it into authorised use
๐Ÿ”ง Maintain โ†’ Manage changes and protection
๐Ÿ‘๏ธ Review โ†’ Confirm it is still required and supported
๐Ÿšช Retire โ†’ Remove it from service securely
Asset management is a lifecycle

Secure provisioning is only the beginning. Asset information and controls need to remain relevant throughout the period in which the asset is used.

End of Life and End of Support are covered specifically in CISSP objective 2.5, so retirement is introduced here without duplicating that lesson.

๐Ÿ“ถ Asset Lifecycle States Know whether an asset is active, stored or leaving service

Asset inventories can be more useful when they record an asset's current lifecycle state.

Ordered

Approved but not yet received.

Provisioning

Being prepared for authorised use.

Active

Currently operating.

Maintenance

Temporarily undergoing servicing or change.

Stored

Retained but not currently operational.

Retired

No longer authorised for normal operational use.

Actual lifecycle labels vary between organisations.

๐Ÿšจ Lost, Stolen and Missing Assets Inventory improves incident response

When an asset is lost or stolen, reliable inventory information can help the organisation understand what has happened.

Useful questions include

Which exact device is missing?
Who was assigned the device?
What information could be stored on it?
What security controls were enabled?
What systems could the device access?
Example

An employee reports a laptop stolen.

The asset inventory identifies the serial number, assigned employee, device-management record and business classification.

This information can support incident investigation and response.
๐Ÿฉน Asset Management and Vulnerability Management Find the vulnerable technology before you can fix it

Asset management provides important context for vulnerability management.

๐Ÿšจ Vulnerability โ†’ Which products are affected?
๐Ÿ“‹ Inventory โ†’ Where do those products exist?
๐Ÿ‘ค Owner โ†’ Who is responsible?
๐Ÿ’Ž Criticality โ†’ Which assets matter most?
๐Ÿ› ๏ธ Remediation โ†’ Prioritise and treat the exposure
Example

Security identifies a critical vulnerability affecting a specific database version.

Accurate inventory data shows:

  • 12 affected databases;
  • their owners;
  • which are production;
  • which support critical services;
  • which are already scheduled for retirement.
Asset context makes vulnerability information much more actionable.
๐Ÿš’ Asset Management and Incident Response Know what the compromised asset actually does

During a security incident, responders may need rapid information about an affected asset.

Owner Criticality Location Business Service Dependencies Classification Environment
Example

Malware is detected on server APP-327.

Without asset-management context, the SOC sees only a hostname.

The asset record reveals that APP-327 supports the organisation's online payment service.

Incident priority and response decisions can now reflect the business importance of the server.
โ“ Orphaned Assets What happens when nobody owns the asset?

An asset may remain operational even after its original owner, team or project disappears.

Example

A temporary application is created for a two-year project.

The project ends and the team is dissolved.

Three years later, the application is still running but nobody knows who is responsible for patching, access reviews or retirement.

The organisation has an orphaned asset.
Ownership must survive organisational change

If an owner leaves or a team changes, important assets should be reassigned rather than becoming unmanaged.

๐Ÿ” Periodic Asset Review Does this asset still need to exist?

Organisations should periodically or event-driven review important assets and inventory information.

Questions include

Does the asset still exist?
Is the owner still correct?
Is the business purpose still valid?
Is the classification still correct?
Is the asset still supported?
Should the asset be retired?
Example

Review finds a development server that has not been used for 18 months.

It remains connected to the network and continues to require vulnerability management and monitoring.

Removing unnecessary assets can reduce both cost and attack surface.
๐Ÿšช Retiring an Asset Removing an asset from service is part of asset management

Asset-management processes should continue when an asset leaves operational use.

Retirement may involve

Remove Access Remove Network Connectivity Transfer Data Sanitise Media Revoke Certificates Recover Licences Update Inventory Dispose
Example

A server is powered off permanently.

However, its administrator credentials remain active, DNS records remain configured and the inventory continues to list it as a production system.

Technical shutdown alone does not complete the asset-management lifecycle.

End of Life, End of Support and asset-retention decisions are covered in detail in CISSP objective 2.5.

๐Ÿ“Š What makes a good Asset Inventory? Complete, accurate, current and useful
Complete

Relevant assets are represented.

Accurate

Recorded information reflects reality.

Current

Changes are reflected within an appropriate timeframe.

Owned

Important assets have accountable owners.

Contextual

Records contain enough business information to support decisions.

Useful

Security and operational processes can consume the information.

Inventory quality memory aid

Complete Do we know EVERYTHING relevant?
Accurate Is the information CORRECT?
Current Is it still TRUE today?

Complete. Accurate. Current.

๐Ÿงฉ Asset Management vs Configuration Management Related but not identical
Asset Management

Focuses on assets, their ownership, value, lifecycle and accountability.

Think: What do we HAVE?

Configuration Management

Focuses more specifically on the configuration and controlled changes of systems and components.

Think: How is it CONFIGURED?

Example

Asset management records that Server A exists, belongs to Service X and is owned by Team Y.

Configuration management may record the approved operating system, installed components and configuration state of Server A.

The disciplines support each other

Reliable cybersecurity needs visibility of both the asset itself and, where necessary, how that asset is configured.

โš ๏ธ Common mistakes Asset-management concepts people frequently misunderstand
"Asset inventory means a spreadsheet of laptops."

Asset management can include hardware, software, services, systems, information and other tangible and intangible assets.

"If the asset works, it is successfully provisioned."

Functionality does not prove that the asset is authorised, inventoried, owned or appropriately secured.

"The administrator is automatically the asset owner."

Technical administration and business ownership are different responsibilities.

"Cloud services are not assets because we don't own the servers."

Services and cloud resources can still be important organisational assets and dependencies.

"An inventory created last year is enough."

Asset environments change continuously. Inventories need to remain accurate and current.

"Discovery and inventory are the same."

Discovery detects what exists. Inventory records what the organisation knows about and manages.

"If a device appears on the network, it must be authorised."

Unknown assets should be reconciled against approved inventory and investigated as appropriate.

"Every asset must be tracked manually."

Highly dynamic environments may require automated discovery and inventory processes.

"A hostname tells security everything it needs to know."

Business ownership, criticality, classification and service relationships provide additional context needed for risk decisions.

"The asset is powered off, so asset management is finished."

Access, credentials, data, inventory records, licences and disposal may still require action.

"Shadow IT is only an IT-governance problem."

Unknown technology can bypass security assessment, monitoring, vulnerability management, data controls and supplier-risk processes.

"Asset value is the purchase price."

Business dependency, information sensitivity, operational impact and other consequences may make an inexpensive asset extremely important.

CISSP Exam Perspective

Think visibility, ownership and lifecycle

CISSP questions may describe an unknown device, unowned application, inaccurate inventory or new asset entering an environment.

Look for the answer that creates authorisation, accountability and reliable asset visibility before jumping immediately to a technical security product.

๐Ÿ”Ž Visibility clues

Inventory Discovery Unknown Device Shadow IT Asset ID

๐Ÿ‘ค Ownership clues

Owner Accountability Custodian Business Responsibility

๐Ÿ“‹ Inventory clues

Hardware Software Services Information Cloud

๐Ÿ›ก๏ธ Provisioning clues

Authorise Register Baseline Deploy Secure

๐Ÿ”„ Lifecycle clues

Acquire Assign Maintain Review Retire

โš ๏ธ Risk clues

Unmanaged Orphaned Unsupported Unknown Unapproved
CISSP shortcut

For any important asset ask:

Do we know it exists? Is it authorised? Who owns it? What does it support? Is it being managed throughout its lifecycle?

๐Ÿ“ Practice scenarios Apply asset-management thinking

Scenario 1

Network monitoring detects an unknown server connected to the production network.

What should happen?

Reconcile the server against the authorised asset inventory and investigate why it is present before assuming it is legitimate.

Scenario 2

A system administrator operates a database containing customer records.

Does this automatically make the administrator the information owner?

No. Technical custody and business ownership are separate concepts.

Scenario 3

A marketing team purchases an unapproved SaaS application and uploads customer data.

Which issue does this illustrate?

Shadow IT and an unmanaged cloud/service asset.

Scenario 4

An organisation discovers that its inventory says 950 endpoints exist while automated discovery detects 975.

What is the appropriate response?

Investigate and reconcile the difference.

Scenario 5

A critical vulnerability affects Software Version 8.4.

What asset-management capability helps most immediately?

An accurate software inventory capable of identifying where that version exists.

Scenario 6

An application is still running five years after the project that created it ended.

Nobody accepts responsibility for it.

What problem exists?

The application has effectively become an orphaned asset.

Scenario 7

A new server is connected to production with the manufacturer's default administrator password.

What failed?

Secure provisioning and configuration before deployment.

Scenario 8

The organisation records every physical server but does not inventory its SaaS applications.

What is missing?

Visibility of important service and intangible assets.

Scenario 9

A laptop inventory shows Employee A as the custodian, but Employee A left the organisation six months ago.

What does this demonstrate?

Asset inventory data has not been properly maintained or reconciled.

Scenario 10

An inexpensive server supports the authentication service used by every customer-facing application.

Should its value be judged only by purchase price?

No. Its business dependency and criticality may make it extremely important.

Scenario 11

A container exists for only 15 minutes during an automated software build.

Does its short lifetime mean asset visibility is irrelevant?

No. Dynamic environments may require automated asset-management approaches rather than traditional manual inventories.

Scenario 12

A stolen laptop is reported but the organisation cannot identify its serial number, assigned employee or whether disk encryption was enabled.

What organisational capability was weak?

Asset inventory and asset-management records.

Scenario 13

A business application has been shut down permanently but still appears as an active production asset in every inventory.

What should occur?

Complete the retirement process and update the authoritative asset records.

Scenario 14

Security identifies malware on HOST-8472 but has no information about what the server actually supports.

What additional asset information would be valuable?

Business service, owner, criticality, classification and dependency information.

Scenario 15

A business manager assumes the infrastructure team owns an application because infrastructure operates its servers.

What principle should be clarified?

Technical custody does not necessarily equal business asset ownership.

Secure Provisioning memory aid

Authorise Should it EXIST?
Register Do we KNOW about it?
Own Who is ACCOUNTABLE?
Classify How IMPORTANT is it?
Secure How must it be PROTECTED?
Manage What has CHANGED?
Retire Should it still EXIST?

Authorise. Register. Own. Secure. Manage.

The five Asset Management questions

1 WHAT is it?
2 WHERE is it?
3 WHO owns it?
4 WHY do we need it?
5 WHAT state is it in?

What. Where. Who. Why. Status.

Inventory vs Discovery

Inventory What SHOULD be here?
Discovery What IS here?
Reconciliation Why are they DIFFERENT?

Know. Discover. Compare. Correct.

Key takeaways

CISSP objective 2.3 covers secure provisioning, information and asset ownership, asset inventory and asset management.

Secure provisioning means introducing authorised assets into the environment through controlled processes rather than allowing technology to appear unmanaged.

An organisation cannot reliably protect assets it does not know exist.

Assets can be tangible or intangible.

Hardware, software, information, services, cloud resources, intellectual property and other resources may all require asset-management visibility.

Important assets should have appropriate ownership and accountability.

Asset ownership is not necessarily the same as technical administration or custody.

Asset inventories should contain enough information to support security and business decisions rather than merely listing technical identifiers.

Useful context can include owner, location, business service, classification, criticality, status and lifecycle state.

Hardware and software should both be inventoried appropriately.

Cloud services and other externally hosted services can also represent important organisational assets and dependencies.

Inventory represents what the organisation knows about; discovery helps identify what actually exists.

Differences between inventory and discovery should be investigated and reconciled.

Asset inventories should remain complete, accurate and current.

Shadow IT can create security risk because technology may operate outside normal inventory, assessment and governance processes.

Dynamic cloud and container environments may require automated asset discovery rather than relying only on manual records.

Asset-management information provides valuable context for vulnerability management and incident response.

Orphaned assets create risk because systems can continue operating after clear business ownership disappears.

Asset management continues through the lifecycle from acquisition and provisioning through operation, change and eventual retirement.

Most importantly: know what exists, know who owns it, know why it matters and keep that information accurate throughout the asset's life.

๐Ÿ“š Sources & Further Reading Authoritative references