Effective asset management requires both tracking physical locations and monitoring device security across a network. This coverage spans inventory methods, tracking technologies, ownership records, and network scanning techniques used to identify unauthorized devices.
Asset Monitoring & Tracking
Once we deploy an asset on our network, we are going to want to make sure that we are monitoring and tracking it, and there are several different ways that we can go about doing that.
Once we deploy an asset to our organization, we are going to want to keep an eye on it. Perhaps we are going to want to track it to make sure we understand where it is from a physical perspective, or maybe we just want to monitor it to make sure it is operating within our security boundaries.
An example might be anti-malware, that we install anti-malware on the devices to make sure that there are no viruses or no malware being installed on the machine, and then we are managing it from some sort of dashboard. Another example is the software updates that happen on the machine, that they are happening on a regular basis, when they need to be updated.
Usually with assets we have some sort of asset tracking, understanding where they are. From a very basic level we may just perform an inventory. An inventory is when you have a list of your assets and then you make sure that you understand exactly where that asset is. As an example, I would get a printout from our accounting department of our assets, and then one of my employees would go around and find each one of those assets and make sure that it was accounted for. So that is one way you could do it.
There are more complex ways, like GPS positioning, where we could understand where our product is, or where our asset is, no matter where in the world, using GPS positioning. So that might be another example of what we could use to really track things.
Another way to do it is with RFID tags, barcodes, QR codes or asset tags. A lot of times we will use asset tags that will have a number on there, and that would make things like inventory go much faster and quicker and easier. Same thing with barcodes and QR codes: then you just scan it, and when you scan it then it checks it off the list. So that is a quick way of doing that.
Sometimes these RFIDs and barcodes and QR codes are put at strategic checkpoints. We see this a lot in shipping, where a shipping container would have an RFID tag on it or a barcode on it, and when it passes checkpoints they would get scanned, whether with a laser scanner, or RFID tags with some sort of RFID scanner. It gets scanned and then logged. These are the positionings along the shipping route, so that way they can track packages.
Many times we will use some sort of database or software to track all of this. We would keep inventory on this database of all of the devices on our network. Then we could even do some sort of asset tag or asset sticker that we put onto the devices, so we could track them and do inventory a little bit easier. Not to mention we would also track ownership.
What this allows us to do is, let's say we have a laptop that was flagged with a virus in our antivirus and malware software. Now what we could do is look up in our database who owns that device, so that way we can go talk to them and fix the issue, whatever the issue is. Or maybe that employee leaves, and now what we can do is better track that device as that employee exits the company, and then reassign that device to another user. So we can track that type of stuff.
There are times when assets end up on our infrastructure, inside of our network, that we were not aware of. Maybe it did not go through the proper purchasing process, and so now it is not an official asset, yet somebody has bought a laptop and is now connecting it to the network. Or maybe it is not company-owned at all; maybe it is a cell phone, somebody's personal cell phone, and they are connecting it to a network that they should not be connecting it to. Or maybe somebody thought that their rogue access point was better than our access point. I have certainly encountered this before as well, creating a big security hole.
So there are times when we want to discover what assets are connected to our network, and make sure that we are tracking those, or that if they are not allowed on our network that we are getting rid of them. That is where something like network scanning can come into play, where it scans our network and looks for devices on our network to see what is on there, and identify if there are assets that we are not tracking.
Another name for this is enumeration. Enumeration is when we do a network scan and find extra devices that are on our network. Maybe we even do things like port scanning, to figure out what type of device this is and what kind of open ports there are, and more information.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →