Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Asset inventory

Also known as: OT asset inventory, Asset register

German: Asset-Inventar

In OT cybersecurity, an asset inventory is a maintained record of the hardware, software, firmware and network components of an industrial automation and control system, with attributes such as location, owner, version, network address and criticality. It is the basis for risk assessment, patching and vulnerability management.

  • OT security

In one sentence

An asset inventory records all OT hardware, software and firmware with versions, owners and criticality, as the basis for security risk management.

Example

The inventory for a filling plant lists each PLC with its firmware version, each HMI panel with its operating system build and each managed switch with its configuration backup location.

How it applies

  • Engineering: An inventory is built from engineering projects, network scans (passive monitoring is preferred in running plants) and site walks. It should record firmware and software versions precisely, because Common Vulnerabilities and Exposures (CVE) entries refer to specific versions.
  • Operation: Without a current inventory, a new Security advisory cannot be matched to affected devices. NIS 2 lists asset management among the cybersecurity risk-management measures of covered entities.
  • Maintenance: Every replacement, firmware update or added device must update the inventory, ideally through Change control, so that it stays aligned with the Configuration baseline.
  • Documentation: Technical documentation can support the operator by stating component types, part numbers, installed software and firmware versions and, where available, an Software bill of materials (SBOM). Version tables in the manual should be kept in step with the delivered release.

Asset inventory vs. SBOM

The asset inventory is kept by the Asset owner and lists the devices and systems in a plant. An SBOM is supplied per product and lists the software components inside one product. Both are needed to decide whether a vulnerability affects a site.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on IEC 62443-2-1 and industrial cybersecurity practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!