Glossary · OT cybersecurity
Asset inventory
Also known as: OT asset inventory, Asset register
German: Asset-Inventar
In OT cybersecurity, an asset inventory is a maintained record of the hardware, software, firmware and network components of an industrial automation and control system, with attributes such as location, owner, version, network address and criticality. It is the basis for risk assessment, patching and vulnerability management.
- OT security
In one sentence
An asset inventory records all OT hardware, software and firmware with versions, owners and criticality, as the basis for security risk management.
Example
The inventory for a filling plant lists each PLC with its firmware version, each HMI panel with its operating system build and each managed switch with its configuration backup location.
How it applies
- Engineering: An inventory is built from engineering projects, network scans (passive monitoring is preferred in running plants) and site walks. It should record firmware and software versions precisely, because Common Vulnerabilities and Exposures (CVE) entries refer to specific versions.
- Operation: Without a current inventory, a new Security advisory cannot be matched to affected devices. NIS 2 lists asset management among the cybersecurity risk-management measures of covered entities.
- Maintenance: Every replacement, firmware update or added device must update the inventory, ideally through Change control, so that it stays aligned with the Configuration baseline.
- Documentation: Technical documentation can support the operator by stating component types, part numbers, installed software and firmware versions and, where available, an Software bill of materials (SBOM). Version tables in the manual should be kept in step with the delivered release.
Asset inventory vs. SBOM
The asset inventory is kept by the Asset owner and lists the devices and systems in a plant. An SBOM is supplied per product and lists the software components inside one product. Both are needed to decide whether a vulnerability affects a site.