Asset management in cybersecurity extends far beyond physical hardware to include data, software, intellectual property, and even workforce—each requiring security controls at every stage of its life cycle. Understanding how assets are acquired, assigned, maintained, transferred, and securely disposed of is essential to reducing organizational risk.
Asset Management & Security
Most companies that I'm aware of already have an acquisition process. That is, when you purchase new assets for the company, there's some sort of financial process that you have to go through to ensure that there's financial protection of that asset. However, there are some elements from a security standpoint that go missing from those processes.
From a financial standpoint, it's pretty easy to define what an asset is. It's the cash we have on hand or in the bank, it's the buildings and the equipment that we buy, it's the laptops that we purchase. So that's pretty straightforward.
But from a risk standpoint, we need to think a little more globally. It could be the data that we're storing, it could be the code that we create or the software that we purchase, it could be the company's reputation with our customers, it could be our customers' data that we are storing that has value. All of this has value. We could even consider our workforce as being an asset as well.
Assets have a life cycle. That is, we acquire an asset, we work with that asset, and then at some point in time we do away with that asset.
Let's use an example of a laptop. We go through some sort of acquisition process to purchase that laptop, and then we assign that laptop out, so there's an assignment that happens, and there's an accounting piece that happens to that. We need to maintain that laptop. Sometimes that laptop exchanges hands or goes from one person to another, so there's this change management that happens with that. Then finally we need to dispose of that laptop correctly.
So we need to think about these different processes that happen throughout the life cycle of that asset. What we need to think about is the different processes that happen through the life cycle with each one of those types of assets, and if we don't, then there are going to be steps that get missed.
As an example, if we were to just throw away that laptop and it had sensitive information on it, then that's going to cause a problem and open up the company for vulnerabilities. What we want to do is go through some sort of sanitization or destruction process with the data on that laptop before we release it. That's just one example, but we want to think about each step along the life cycle.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →