
Asset and service inventory: knowing what you actually run
An inventory is a record with checkable properties, not a database: what CM-8 requires.
Hardening, monitoring, tooling and good practice.

An inventory is a record with checkable properties, not a database: what CM-8 requires.

The inventory is a snapshot; the lifecycle is the process that ends an asset.

The impact level is the decision; the label only carries it to the object it governs.

How NIST sorts controls by who executes them, and where physical controls sit.

Three hats on one asset: who sets the rules, who runs it, and what the register names.

One register keeps the risk decision; the other keeps the deviation and its expiry.

A RACI chart maps activities to roles; done badly it hides who answers for what.

Drawing a system boundary: the decision it encodes and the assumptions it rests on.

Criticality is a property of the service, not the box: name what it depends on.

The parts a security policy must contain, and what their presence does not prove.

Supplier risk that arrives with the contract: what stays yours and how it is managed.

Asset, process and risk are owned differently; NIST names who is accountable for each.

An asset matters for its process and data; scope is a chain, not a perimeter.

Security protects three separate properties, not one attribute: each has its own impact.

Designed, implemented and effective: three different claims, each with its own evidence.

An audit trail records what happened; evidence is the proof a control works.

Least privilege bounds one identity; defense in depth bounds one failure.

Policy states intent, standards bind, procedures give the steps, guidelines advise.

Risk appetite is a leadership call; acceptance is real once written, owned and dated.

Risk is not one number: threat source, vulnerability, likelihood and impact are separate.

Five ways to respond to a risk: what each one changes, what is left, and who answers.