TechKnowSurge
ISC2 CISSP 2.3 NIST CSF ID.AM-08 CompTIA Security+ 4.2 NIST 800-53 SA-3
VideoSecurityFree

Asset Acquisition and Management

Asset management in cybersecurity extends far beyond physical hardware to include data, software, intellectual property, and even workforce—each requiring security controls at every stage of its life cycle. Understanding how assets are acquired, assigned, maintained, transferred, and securely disposed of is essential to reducing organizational risk.

Complete this video to capture a CTF flag worth 1 point.

About this video

Most organizations have established financial processes for purchasing new assets, but those processes frequently leave security considerations unaddressed. From a risk management standpoint, the definition of an asset must extend well beyond cash, buildings, and physical equipment. Data in storage, internally developed software, third-party applications, customer records, intellectual property, and even the workforce itself all represent assets that carry measurable value and require protection. Every asset follows a life cycle that moves through acquisition, assignment, ongoing maintenance, transfer between users or departments, and eventual disposal. Security controls need to be applied consistently across each of these phases rather than treated as a one-time concern at the point of purchase. A laptop, for example, must be properly tracked when assigned, managed when it changes hands, and sanitized or destroyed before it leaves the organization's control. Neglecting any stage of the asset life cycle creates gaps that can be exploited. Disposing of a device without wiping sensitive data, failing to update records when assets are transferred, or overlooking the security implications of decommissioning software are all examples of how incomplete processes lead to real vulnerabilities. A structured approach to asset management—one that accounts for both financial and security requirements throughout the entire life cycle—is a foundational element of sound organizational risk management.

What you'll learn

What's covered

Asset Management & Security

Aligned to

ISC2 CISSP
2.3 Provision information and assets securely
NIST CSF
ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles.
CompTIA Security+
4.2 Explain the security implications of proper hardware, software, and data asset management.
NIST 800-53
SA-3 System Development Life Cycle

Key terms

Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Asset Lifecycle
The stages an organizational asset passes through from initial procurement and assignment through maintenance, change management, and final deprovisioning.
Data Sanitization
The process of permanently and securely removing or destroying data from a storage device before disposal or reuse.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.

Topics

Asset Management Asset Lifecycle Change Management Secure Disposal Data Classification Cybersecurity

Transcript

What Counts as an Asset

Most companies that I'm aware of already have an acquisition process. That is, when you purchase new assets for the company, there's some sort of financial process that you have to go through to ensure that there's financial protection of that asset. However, there are some elements from a security standpoint that go missing from those processes.

From a financial standpoint, it's pretty easy to define what an asset is. It's the cash we have on hand or in the bank, it's the buildings and the equipment that we buy, it's the laptops that we purchase. So that's pretty straightforward.

But from a risk standpoint, we need to think a little more globally. It could be the data that we're storing, it could be the code that we create or the software that we purchase, it could be the company's reputation with our customers, it could be our customers' data that we are storing that has value. All of this has value. We could even consider our workforce as being an asset as well.

The Asset Life Cycle

Assets have a life cycle. That is, we acquire an asset, we work with that asset, and then at some point in time we do away with that asset.

Let's use an example of a laptop. We go through some sort of acquisition process to purchase that laptop, and then we assign that laptop out, so there's an assignment that happens, and there's an accounting piece that happens to that. We need to maintain that laptop. Sometimes that laptop exchanges hands or goes from one person to another, so there's this change management that happens with that. Then finally we need to dispose of that laptop correctly.

So we need to think about these different processes that happen throughout the life cycle of that asset. What we need to think about is the different processes that happen through the life cycle with each one of those types of assets, and if we don't, then there are going to be steps that get missed.

As an example, if we were to just throw away that laptop and it had sensitive information on it, then that's going to cause a problem and open up the company for vulnerabilities. What we want to do is go through some sort of sanitization or destruction process with the data on that laptop before we release it. That's just one example, but we want to think about each step along the life cycle.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →