Cybersecurity GRC 14 items
IT Asset Inventory & Management Audit
Audits the accuracy and completeness of hardware and software asset inventories and the processes that keep them current.
CIS v8NIST 800-53ISO 27001
Free PDF · enter your email to download.
Hardware Inventory
- Is a complete inventory of enterprise hardware assets maintained? *
- Does the inventory record owner, location, and network address? *
- Is active discovery used to identify assets on the network? *
- Are unauthorized assets detected and addressed? *
Software Inventory
- Is an inventory of all authorized software maintained? *
- Is unauthorized or unsupported software identified and removed? *
- Is software supported and within its vendor lifecycle? *
- Is application allowlisting used where feasible?
Cloud & Non-Traditional Assets
- Are cloud, SaaS, and virtual assets included in the inventory? *
- Are mobile, IoT, and OT devices tracked?
- Is the inventory integrated with a CMDB or authoritative data source?
Lifecycle & Governance
- Is the asset inventory reviewed and reconciled at a defined interval? *
- Are assets securely decommissioned and data sanitized at end of life? *
- Are asset owners assigned accountability for their assets? *
Download the full IT Asset Inventory & Management Audit checklist
Get it as a clean, printable PDF — free.
