Building an Asset Inventory for Small DIB Companies: What to Include
You can't protect what you don't know you have. Here's a plain, practical asset inventory for a small DIB team — what to capture and how to keep it current.
You can’t protect what you can’t see
An asset inventory is a list of the hardware and software in your environment. It sounds basic, and it is — which is exactly why it gets skipped or left half-done. Almost every other security activity (access reviews, patching, knowing what’s in scope) leans on having a current inventory.
This article is generic and educational. An inventory helps you organize a picture of your own environment; it does not determine your scope or whether your organization is compliant.
What to capture
For a small DIB team, one row per asset with a handful of fields is plenty:
- Asset ID and type (laptop, desktop, server, network device, mobile).
- Make / model and operating system / version.
- Owner and location.
- Whether it handles FCI or CUI — this is what makes your in-scope assets obvious.
- Whether it is encrypted.
- Status (active, spare, retired) and notes.
The “handles FCI/CUI?” column does a lot of work: it turns a flat device list into a view of what is actually in scope for your covered information.
Software, not just hardware
It is easy to inventory laptops and forget the software. A short software inventory — applications installed, where they run — pairs with the hardware list and supports patching and configuration work. Keep both; they answer different questions.
Keeping it current
An inventory is only useful if it reflects reality:
- Update it when assets are added, retired, or change owners.
- Give it an owner so updates have a home.
- Review it periodically — pair it with your access reviews, since people and devices change together.
Where it fits
The inventory underpins much of the rest of your evidence: you can’t review access to systems you haven’t listed, or confirm patching on devices you don’t track. It belongs in an 05_Asset_Inventory folder in your evidence structure.
A ready template
You can build this in a blank spreadsheet. If you would rather start from a standardized template — with the in-scope and encryption fields already laid out and dropdowns to keep entries consistent — the DIBStack Evidence Binder includes asset and user inventory templates. They help you organize the picture; they do not determine your scope or compliance.
Related product
DIBStack Evidence Binder
Folder structures, evidence checklists, workbooks, logs, and templates for organizing cybersecurity evidence.
View DIBStack Evidence Binder