Last updated: April 29, 2026
Asset inventory is the unsexy foundation of every other security control. Without it, vuln management, IR, audit response all fail.
What “asset” means in 2026
- Physical and virtual servers
- Endpoints (laptops, desktops)
- Mobile devices
- Cloud accounts, projects, subscriptions
- Cloud resources (instances, storage, databases, functions)
- Containers and Kubernetes workloads
- Internet-exposed services (per Module 6, API track)
- SaaS applications in use
- Domain names, certificates
- Data assets — what data, where, classification
Tools for discovery
- CMDB — ServiceNow, Jira Insight
- Cloud-native — AWS Config, Azure Resource Graph, GCP Asset Inventory
- CSPM — Wiz, Orca, Prisma Cloud — comprehensive cloud inventory
- EDR — endpoint inventory by extension
- Network discovery — Nmap, runZero, Tenable
- Attack-surface management — Censys ASM, Bit Discovery, Detectify
Tagging discipline
Without tags, inventory is a list. With tags, it’s actionable:
- Owner team
- Environment (prod/staging/dev)
- Data classification
- Compliance scope (PCI, HIPAA, etc.)
- Cost centre
Enforce tags via Org Policy / IaC validation. Untagged resource = automatic noncompliance.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.