IT Asset Management
IT asset management is the practice of tracking and governing the hardware, software, subscriptions, and services an organization uses. It connects each asset to its owner, cost, condition, risk, and place in the asset life cycle.
itIT service management and support | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — IT Asset Management
You already have an inventory. Spreadsheets, discovery tools, procurement records, CMDBs — somewhere in your organization there is a list of things you own. The problem is not the list. The problem is that you have several of them, and they disagree.
IT asset management is the discipline that turns those scattered records into decisions. Not a better spreadsheet. Not a fancier discovery tool. A management system that tells you what exists, who is responsible, what it costs, and whether anyone should still be paying for it.
The two ideas everything else hangs off are evidence and reconciliation. Procurement knows what was bought. Discovery knows what is running. The service desk knows what is broken. Identity knows who has access. No single source proves the current state. Reconciliation matches records that describe the same asset, exposes the ones that do not match, and routes each disagreement to a person with a deadline. That is the whole engine. Everything else is detail.
The thing that will surprise you is how much risk hides in the retirement gap. Organizations invest heavily in onboarding and deployment, then treat disposal as an afterthought. A device marked as retired but still present in the environment is an unpatched machine holding company data, invisible to the security team and visible to anyone who picks it up. The gap between what the record says and what actually happened is where the expensive findings live.
The lifecycle model is straightforward: request, approve, acquire, receive, deploy, operate, change, retire, dispose. Controls belong at the transitions — each one changes who is responsible and what the asset costs. Hardware and software need different details at each stage, but they follow the same governance model. A server is both a financial asset and a service component; ITAM governs the first, configuration management governs the second, and a shared identifier keeps them connected.
Start with a defined scope, a small required record, and the decisions the data must support. Expand only when a new field has an owner and a use. Trustworthy data comes before optimization. If the inventory is incomplete or stale, precise cost and risk reports will still be wrong.
The Glossary explains every term this file uses. The Slides show how evidence sources connect. The Cheatsheet gives you the minimum asset record and the reconciliation exceptions to watch for. The Field Notes tell you what it actually costs when teams get this wrong.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://committee.iso.org/sites/jtc1sc7/home/news/content-left-area/news-and-updates/it-asset-management-standards-is.html
Supports
- ITAM scope across hardware, software, subscriptions, and services
- Detection, tracking, management, and optimization across the asset life cycle
- ISO 19770 management-system and data-exchange context
- https://www.iso.org/standard/68531.html
Supports
- Requirements for an IT asset management system
- Applicability across organization sizes and IT asset types
- Boundary from financial, accounting, and asset-specific technical requirements
- https://committee.iso.org/sites/jtc1sc7/home/projects/flagship-standards/isoiec-19770-12017.html
Supports
- ITAM management, control, and protection across life-cycle stages
- Management-system establishment, implementation, maintenance, and improvement
- Progression from trustworthy data through life-cycle integration to optimization
- https://csrc.nist.gov/pubs/sp/1800/5/final
Supports
- ITAM visibility across physical and virtual assets
- Relationship between asset visibility, utilization, and security
- Publication identity and final status
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-5.pdf
Supports
- Asset discovery, identification, normalization, and reconciliation concepts
- Integration of evidence from multiple asset data sources
- Example ITAM architecture, workflows, and security outcomes
- https://www.cisecurity.org/controls/inventory-and-control-of-enterprise-assets
Supports
- Inventory and control of enterprise assets
- Identification and action for unauthorized and unmanaged assets
- Asset visibility as support for monitoring, response, backup, and recovery
- https://www.cisecurity.org/controls/inventory-and-control-of-software-assets
Supports
- Inventory and control of operating systems and applications
- Authorized, unauthorized, managed, and unmanaged software states
- Action to prevent unauthorized software installation or execution
- https://www.cisecurity.org/insights/white-papers/guide-to-enterprise-assets-and-software
Supports
- Scope guidance for enterprise asset and software inventories
- Use of the guide during implementation and audit
- Accounting for in-scope assets before applying security controls
- https://github.com/sindresorhus/awesome
Supports
- Discovery starting point for curated awesome lists
- https://github.com/awesome-foss/awesome-sysadmin
Supports
- Curated IT Asset Management software category
- Discovery of GLPI, OCS Inventory NG, openDCIM, and Snipe-IT
- https://www.glpi-project.org/en/
Supports
- Inventory and asset management
- Service desk, financial, contract, and configuration management functions
- GLPI learner destination and Awesome Links rationale
- https://ocsinventory-ng.org/?lang=en
Supports
- Hardware and software inventory through agents and network discovery
- Package deployment capability
- OCS Inventory NG learner destination and Awesome Links rationale
- https://documentation.ocsinventory-ng.org/
Supports
- Official documentation destination for OCS Inventory NG
- https://opendcim.org/
Supports
- Data center inventory management focus
- Physical infrastructure, rack, power, and capacity documentation
- openDCIM learner destination and Awesome Links rationale
- https://snipeitapp.com/
Supports
- Open-source asset and license management
- Inventory tracking, assignments, and API support
- Snipe-IT learner destination and Awesome Links rationale
- https://snipe-it.readme.io/docs
Supports
- Official user manual destination for Snipe-IT
- https://www.bsa.org/policy/policy-topics/piracy-overview
Supports
- Software audit and enforcement history creating ITAM pressure
- Timeline event: first large-scale software audit lawsuits
- https://www.axelos.com/what-we-offer/itsm
Supports
- ITIL introduction and process-oriented IT service management
- Timeline event: ITIL v1 published
- https://www.iso.org/standard/27001
Supports
- Information security standard with mandatory asset inventory control
- Timeline event: ISO/IEC 27001 published
- https://www.iso.org/standard/27663.html
Supports
- British information security standard linking asset inventory to security
- Timeline event: BS 7799-2 published
- https://en.wikipedia.org/wiki/ISO/IEC_19770
Supports
- ISO 19770-1 tiered model and second edition structure
- ISO 19770-2 SWID tags and ISO 19770-3 entitlement tags
- ISO 19770-5 overview and vocabulary publication
- https://www.csoonline.com/article/573783/the-astronomical-costs-of-an-asset-disposal-program-gone-wrong.html
Supports
- Morgan Stanley $155M cumulative penalties for disposal failures
- Timeline event: 2022 SEC penalty
- Field notes signal card on retirement gap risk
- https://www.digital-operational-resilience-act.com/
Supports
- EU Digital Operational Resilience Act asset inventory requirements
- Timeline event: DORA takes effect January 2025
