Asset Inventory
A comprehensive, maintained register of all assets an organization relies on: information assets, IT systems, physical infrastructure, people, and third parties. You cannot protect what you do not know you have.
Why it matters
Asset inventory is the foundation of every security program. Risk assessment requires knowing what is at stake. Control mapping requires knowing what to protect. Incident response requires knowing what was affected. Without a current inventory, every downstream activity operates on incomplete information. ISO 27001 mandates asset identification, and auditors routinely verify that inventories are complete and current.
In practice
An asset inventory categorizes assets by type (information, IT, physical, personnel), assigns ownership, records business criticality, and tracks lifecycle status. IT assets need end-of-life and end-of-support dates. Information assets need classification levels. In vucavoid, assets are first-class entities linked to risks, controls, and processes. Business criticality ratings feed into your VUCA score, and assets without owners are automatically flagged.