Regardless of which cyber security framework your organization has chosen (or will choose), an accurate IT asset inventory is a requirement. It's important to note that maintaining an accurate IT asset inventory is an ongoing process rather than a one-time event. Let’s start by briefly examining what IT asset lifecycle management entails.
Event | ITAM Phase | What Happens |
New asset type is acquired | Acquire | In this phase, all vested parties are involved in the decision process to adopt a new asset type. Roles and responsibilities are identified between departments, the organization, and the vendor. |
New asset is acquired | Acquire | Purchasing information is captured including proof-of-purchase, warranty, etc. |
Asset is received | Receive | The asset is now the responsibility of the organization, and the methods to manage the asset type begin. |
Asset is in in-use | Deploy, In-Use | The asset is configured and deployed to a user at a location all of which is recorded. |
Asset is no longer needed by the user | Recover | The asset and its related assets are recovered and placed back into inventory. Data and software are secured. |
Asset is no longer needed by the organization | Dispose | The asset’s data is secured and properly disposed of following a pre-defined process. The data destruction and the disposal method are recorded. |
Although the above description may seem simple, much more is happening behind the scenes. For instance, the IT Asset Management (ITAM) program identifies and oversees the electronic waste disposal vendor. And a lot of data is being generated by different departments. This data must be curated to create meaningful information and linked to the asset. From one perspective, the ITAM Program operates in the same way, regardless of the security framework in place. However, the specific details of the framework may require the ITAM Program to make some adjustments.
Cyber Security Frameworks and The ITAM Program
Many organizations still struggle with IT security. The threat from malicious actors is constantly changing and seems to be never-ending. While it may not directly add value to the organization, security is crucial and cannot be ignored. We must accept this reality and focus on making the most of our IT security investment while safeguarding our data. What steps can we take moving forward?
Securing the Data
NIST: https://www.nist.gov/cyberframework
CIS: https://www.cisecurity.org
What's Next?
Our ITAM/NIST/CIS mapping and training blaze the trail to protect what's most important, the data. Click to learn more about the ITAM / Cyber Security Workshop