Asset Tracking
Summary
PDF p.180Asset tracking involves managing and monitoring an organization's critical systems, components, devices, and other valuable objects. This process includes collecting and analyzing information about these assets to support informed decision-making and achieve business goals.
In plain words
Supplementary — not from your PDFYou can't protect what you don't know you have. Asset tracking keeps an inventory of systems, devices and software, recording type, model, serial number, location, owner and value, and gives each asset an owner and a classification. Inventories are built manually, by network discovery tools, with asset management software, in a CMDB, through MDM, or with cloud discovery tools. Buying securely means considering security features, vendor reputation, integration and total cost of ownership.
Detailed explanation
PDF p.180-
Asset Management Process
- Definition: Tracks all critical systems, components, devices, and other valuable objects in an inventory.
- Functions: Collects and analyzes information to support informed changes and achieve business goals.
- Tools: Various software suites and hardware solutions are available for tracking and managing assets.
- Data Stored: Type, model, serial number, asset ID, location, user(s), value, and service information.
-
Technical Assets
- Focus: Requires some degree of configuration.
- Non-Technical Assets: Includes items like furniture and buildings that do not require configuration.
-
Asset Assignment/Accounting and Monitoring
- Ownership Assignment: Designates specific individuals or teams responsible for particular assets.
- Classification: Organizes assets based on value, sensitivity, or criticality.
- Monitoring Activities: Includes inventory and enumeration tasks to maintain a comprehensive list of assets.
- Importance: Vital for license management, patch deployment, and security incident response.
-
Asset Enumeration Methods
- Manual Inventory: Suitable for smaller organizations or specific asset types.
- Network Scanning: Tools like Nmap, Nessus, or OpenVAS discover and enumerate networked devices.
- Asset Management Software: Solutions like Lansweeper, ManageEngine, or SolarWinds track and catalog assets.
- Configuration Management Database (CMDB): Centralized repository of IT infrastructure information.
- Mobile Device Management (MDM) Solutions: Manage and secure mobile devices.
- Cloud Asset Discovery: Tools like AWS Config or Azure Resource Graph discover and catalog cloud assets.
-
Asset Acquisition/Procurement
- Security Features: Select hardware and software with strong security features.
- Vendor Selection: Work with reputable vendors that prioritize security.
- Integration: Ensure solutions integrate with existing security infrastructure.
- Total Cost of Ownership (TCO): Consider initial purchase price and ongoing costs.
Important terms
taken from the text above- Asset Management Process
- Tracks all critical systems, components, devices, and other valuable objects in an inventory.
- Data Stored
- Type, model, serial number, asset ID, location, user(s), value, and service information.
- Non-Technical Assets
- Includes items like furniture and buildings that do not require configuration.
- Ownership Assignment
- Designates specific individuals or teams responsible for particular assets.
- Classification
- Organizes assets based on value, sensitivity, or criticality.
- Monitoring Activities
- Includes inventory and enumeration tasks to maintain a comprehensive list of assets.
- Manual Inventory
- Suitable for smaller organizations or specific asset types.
- Network Scanning
- Tools like Nmap, Nessus, or OpenVAS discover and enumerate networked devices.
- Asset Management Software
- Solutions like Lansweeper, ManageEngine, or SolarWinds track and catalog assets.
- Configuration Management Database (CMDB)
- Centralized repository of IT infrastructure information.
- Mobile Device Management (MDM) Solutions
- Manage and secure mobile devices.
- Cloud Asset Discovery
- Tools like AWS Config or Azure Resource Graph discover and catalog cloud assets.
- Security Features
- Select hardware and software with strong security features.
- Vendor Selection
- Work with reputable vendors that prioritize security.
- Total Cost of Ownership (TCO)
- Consider initial purchase price and ongoing costs.
Examples & real-world scenarios
Supplementary — not from your PDF- A CMDB entry for each server with its owner and criticality.
- AWS Config listing every cloud resource in an account.
- Reviewing a vendor's security track record before purchase.
Scenario
During an incident, the team finds an unpatched server nobody knew existed. A complete, current inventory would have included it in patching and monitoring.
Common mistakes
Supplementary — not from your PDF- Treating inventory as a one-time project instead of a continuous process.
- Judging purchases on price alone and ignoring total cost of ownership and security features.
Practical skills
Supplementary — not from your PDF- Build an asset inventory for your own home lab with owner and classification fields.
What I should remember
Key Points PDF p.180-
Asset Management Process
- Inventory: Tracks critical systems and devices.
- Data Collection: Supports informed decision-making.
- Tools: Software and hardware solutions.
-
Technical Assets
- Configuration Required: Focus on assets needing configuration.
- Non-Technical Assets: Includes furniture and buildings.
-
Asset Assignment/Accounting and Monitoring
- Ownership Assignment: Clear accountability for assets.
- Classification: Based on value, sensitivity, or criticality.
- Monitoring: Inventory and enumeration tasks.
-
Asset Enumeration Methods
- Manual Inventory: For smaller organizations.
- Network Scanning: Tools like Nmap, Nessus, OpenVAS.
- Asset Management Software: Lansweeper, ManageEngine, SolarWinds.
- CMDB: Centralized IT infrastructure repository.
- MDM Solutions: Manage mobile devices.
- Cloud Asset Discovery: AWS Config, Azure Resource Graph.
-
Asset Acquisition/Procurement
- Security Features: Built-in encryption, secure boot mechanisms.
- Vendor Selection: Reputable vendors with ongoing support.
- Integration: Seamless with existing security infrastructure.
- TCO: Initial purchase and ongoing costs.