DIBStack
All resources

Building an Asset Inventory for Small DIB Companies: What to Include

You can't protect what you don't know you have. Here's a plain, practical asset inventory for a small DIB team — what to capture and how to keep it current.

You can’t protect what you can’t see

An asset inventory is a list of the hardware and software in your environment. It sounds basic, and it is — which is exactly why it gets skipped or left half-done. Almost every other security activity (access reviews, patching, knowing what’s in scope) leans on having a current inventory.

This article is generic and educational. An inventory helps you organize a picture of your own environment; it does not determine your scope or whether your organization is compliant.

What to capture

For a small DIB team, one row per asset with a handful of fields is plenty:

  • Asset ID and type (laptop, desktop, server, network device, mobile).
  • Make / model and operating system / version.
  • Owner and location.
  • Whether it handles FCI or CUI — this is what makes your in-scope assets obvious.
  • Whether it is encrypted.
  • Status (active, spare, retired) and notes.

The “handles FCI/CUI?” column does a lot of work: it turns a flat device list into a view of what is actually in scope for your covered information.

Software, not just hardware

It is easy to inventory laptops and forget the software. A short software inventory — applications installed, where they run — pairs with the hardware list and supports patching and configuration work. Keep both; they answer different questions.

Keeping it current

An inventory is only useful if it reflects reality:

  • Update it when assets are added, retired, or change owners.
  • Give it an owner so updates have a home.
  • Review it periodically — pair it with your access reviews, since people and devices change together.

Where it fits

The inventory underpins much of the rest of your evidence: you can’t review access to systems you haven’t listed, or confirm patching on devices you don’t track. It belongs in an 05_Asset_Inventory folder in your evidence structure.

A ready template

You can build this in a blank spreadsheet. If you would rather start from a standardized template — with the in-scope and encryption fields already laid out and dropdowns to keep entries consistent — the DIBStack Evidence Binder includes asset and user inventory templates. They help you organize the picture; they do not determine your scope or compliance.

Related product

DIBStack Evidence Binder

Folder structures, evidence checklists, workbooks, logs, and templates for organizing cybersecurity evidence.

View DIBStack Evidence Binder