User and mobile endpoints
Desktops, laptops, thin clients, shared workstations, kiosks, tablets, phones, rugged devices, remote endpoints, personally owned devices permitted to access business data, and devices awaiting deployment or return.
A dashboard can report 98% endpoint protection while excluding devices it has never seen. This guide helps internal auditors, CISOs, IT managers, and asset owners build an evidence-based population across on-premises, cloud, virtual, mobile, and connected technology.

A tool can measure its own enrollment accurately and still misstate enterprise coverage.
Security tools usually describe the assets reporting to that tool. They may omit devices that were never enrolled, disconnected before the reporting window, use an unsupported operating system, exist in another tenant, live in an isolated network, or were created outside the standard procurement process. Conversely, one physical or virtual asset can appear under several names, addresses, agents, or stale records. An IT asset inventory audit therefore tests the population before relying on percentages built from that population.
The audit scope should reflect the organization’s real environment, not only familiar workstation and server categories. Scope decisions belong in the workpaper so excluded technology cannot silently disappear from the conclusion.
Desktops, laptops, thin clients, shared workstations, kiosks, tablets, phones, rugged devices, remote endpoints, personally owned devices permitted to access business data, and devices awaiting deployment or return.
Physical servers, virtual machines, hypervisor hosts, clusters, appliances, containers where separately accountable, development systems, lab systems, recovery systems, and dormant templates that can be instantiated.
Firewalls, routers, switches, access points, VPN appliances, load balancers, cameras, printers, building systems, medical or industrial equipment, conference systems, storage, and other IoT or operational technology.
Cloud subscriptions, accounts, projects, virtual machines, managed services, public IP addresses, domains, subdomains, certificates, administrative interfaces, SaaS applications, and resources created outside central IT.
No source is universally authoritative for every attribute. The useful question is which source can establish existence, identity, ownership, location, connectivity, management status, security coverage, lifecycle state, or financial custody for each asset class.
Provides assigned owner, support group, service relationship, criticality, location, business purpose, lifecycle status, and change history. Test whether discovery feeds, manual updates, and retirement workflows keep it current.
Reveals enrolled devices, agent health, policy assignment, last contact, operating system, hardware identifiers, and security state. It cannot prove completeness without an independent denominator.
Shows computer objects, device registrations, join type, ownership signals, timestamps, and directory state. Stale objects, duplicate registrations, renamed devices, non-domain systems, and cross-tenant assets require separate treatment.
Can identify addresses, hostnames, hardware addresses, lease activity, switch ports, wireless associations, and unrecognized systems. Dynamic addressing, network address translation, intermittent devices, segmented networks, and incomplete sensor reach affect interpretation.
Establishes resources that may never appear in traditional procurement or endpoint tools. Include every relevant tenant, subscription, account, region, project, cluster, resource group, and delegated administration boundary.
These sources help expose assets absent from another control plane and assets with missing agents or jobs. Scanner results, backup catalogs, monitoring targets, SIEM sources, and certificate observations are valuable candidate populations, not automatic truth.
Purchase orders, invoices, leases, depreciation schedules, disposal records, warranty records, and vendor renewals can identify technology outside operational tools. They may aggregate components or lag real deployment and retirement dates.
Identity-provider apps, browser-discovered services, licensing portals, accounts-payable records, corporate-card expenses, and vendor lists can reveal shadow IT and ownerless services that do not present as conventional hardware.
Authorized attack-surface records, public DNS, certificate transparency, registrar records, cloud addresses, firewall publications, and third-party exposure data can identify externally reachable assets missing from internal inventories.
Preserve each original export and its extraction parameters. Perform normalization and matching in a controlled derivative so the auditor can reproduce every merge, exclusion, and disposition.
Record scope boundaries, asset classes, dates, active-state rules, lifecycle statuses, required attributes, materiality, and known exclusions. Name the business and technical owners who can resolve exceptions.
Collect direct exports or controlled queries with report name, source, tenant, filters, timezone, extraction time, row count, permissions, and hash or other integrity record where appropriate.
Standardize case, whitespace, hostname suffixes, address notation, serial formats, cloud resource identifiers, dates, and status labels. Retain raw values and source lineage beside normalized fields.
Use stable identifiers first: cloud resource ID, device ID, serial number, hardware UUID, management ID, directory ID, agent ID, or hardware address. Use hostname or IP only with time context and corroboration.
Create presence flags and attribute comparisons across the candidate population. Identify one-sided records, contradictory owners, stale timestamps, unsupported versions, missing control agents, and unexplained duplicate clusters.
Trace each material exception to evidence. Classify it as valid, duplicate, retired, rebuilt, transient, unauthorized, unmanaged, unsupported, out of scope with rationale, or unresolved. Assign corrective action and due date.
Percentages should disclose which authoritative population they use, when it was validated, how duplicates were handled, and whether unresolved items remain. A precise number calculated from a partial population is not strong assurance.
Healthy tool records ÷ all current tool records
Useful for operating the tool, but it says nothing about assets absent from the tool. Label it as console or enrolled-population coverage.
Matched active assets with the control ÷ validated active in-scope assets
Stronger when the validated population integrates independent sources and every exclusion is supported and approved.
Unresolved candidate records ÷ all candidate records before final disposition
Keep uncertainty visible. If unresolved records could materially change the conclusion, qualify the metric or defer the effectiveness claim.
Example: an EDR console may show 980 healthy sensors out of 1,000 enrolled devices, or 98%. If reconciliation identifies 80 additional active endpoints with no sensor, validated coverage becomes 980 out of 1,080, or about 90.7%, before evaluating stale or duplicate records. The tool was not necessarily wrong; the denominator answered a narrower question.
Do not put every mismatch in one generic bucket. Classification determines the risk, owner, evidence, urgency, and corrective action.
An active asset exists in an authoritative or independently observed source but not in the management, security, backup, monitoring, or vulnerability system expected to cover it. Determine whether the issue is enrollment, network reach, policy assignment, agent failure, or scope design.
A record remains active after disposal, replacement, decommissioning, tenant migration, rebuild, or long-term inactivity. Validate retirement evidence before removal so attackers cannot hide real systems behind a “stale” label.
One asset appears several times because of rebuilds, cloning, renaming, multiple interfaces, reused addresses, conflicting agent IDs, or synchronized systems. Preserve the history needed to understand coverage and incidents.
A connected device, cloud service, SaaS application, domain, public address, or administrative interface lacks approval or an accountable owner. Contain or remove it under an authorized process; do not let the audit itself make production changes.
The asset or its operating system, firmware, application, or management agent is outside vendor support or cannot receive required security updates. Record business dependency, exposure, compensating controls, risk acceptance, and retirement plan.
The asset exists, but responsibility, business purpose, criticality, data classification, location, environment, or service dependency is absent or contradictory. Ownership gaps commonly delay patching, incident response, renewal, and retirement decisions.
This example structure keeps source lineage and audit reasoning visible. Add or remove fields according to scope and evidence-minimization requirements. Do not place credentials, secrets, unnecessary personal data, or regulated content in the workpaper.
| Audit record | Asset class | Stable identifier | Source presence | Last-seen comparison | Owner and purpose | Control coverage | Exception | Disposition evidence | Risk and action |
|---|---|---|---|---|---|---|---|---|---|
| AA-001 | Windows endpoint | Serial, device ID, hardware UUID | CMDB, Entra, endpoint management, EDR | All sources current within policy | Assigned user and department agree | EDR, encryption, patch, backup not required by policy | None | Direct exports and match record | No action |
| AA-002 | Remote laptop | Serial and directory device ID | Directory and procurement only | Recent sign-in; absent from management tools | Named employee; business purpose confirmed | No EDR, patch, or encryption evidence | Unmanaged active asset | Sign-in, purchase, and custody records | High: contain and enroll under approved incident/IT process |
| AA-003 | Virtual server | Cloud resource ID | Cloud inventory, scanner, monitoring | Current in cloud; CMDB absent | Subscription owner identified; app owner unclear | Scanner and monitoring present; backup unresolved | Missing inventory and ownership | Cloud configuration and billing evidence | High: assign owner, classify, validate backup |
| AA-004 | Network switch | Serial and management address | CMDB, monitoring, finance | Monitoring current; CMDB status retired | Network operations | Monitoring present; firmware support expired | Contradictory state and end of life | Running config metadata and support record | High: correct status and approve replacement plan |
| AA-005 | Rebuilt endpoint | Same serial; new agent and directory IDs | Two EDR records, two directory records, one CMDB record | Old records stale after rebuild date | Owner consistent | Current record healthy | Duplicate history | Rebuild ticket and record timestamps | Low: retire obsolete records without erasing history |
| AA-006 | SaaS application | Tenant and vendor account ID | Identity provider and expense record | Recent sign-ins and monthly charge | Requester left organization | No central logging or vendor review | Shadow IT and ownerless service | SSO activity, invoice, and contract search | High: assign sponsor, assess, govern, or terminate |
| AA-007 | IoT camera | Hardware address and serial | DHCP, switch, and network discovery only | Current network activity | Facilities confirms business use | No central management; isolated VLAN observed | Missing formal inventory | Port, lease, physical, and VLAN evidence | Medium: record owner, model, firmware, lifecycle, and control plan |
| AA-008 | Public cloud address | Resource and subscription ID | Cloud inventory and external observation | Current and internet reachable | Project team identified | Logging present; vulnerability coverage absent | Incomplete security coverage | Cloud allocation, firewall, and external observation | High: validate purpose, exposure, scanning, and owner approval |
| AA-009 | Retired server | Serial and CMDB ID | CMDB, finance, backup catalog | No network or monitoring activity; backup retained | Former application owner | Not operational; retention still applies | Valid retired record | Decommission approval and retention requirement | Document exclusion; verify data disposal when retention ends |
| AA-010 | Mobile device | Management device ID and serial | MDM and directory | MDM current; directory object stale under old name | Assigned employee | Compliant in MDM | Directory duplicate | Enrollment and rename history | Low: resolve identity mapping and retire obsolete directory object |
| AA-011 | Hypervisor host | Hardware UUID and management ID | Hypervisor manager and monitoring | Current; no procurement match due to acquisition | Infrastructure team | Monitoring present; EDR excluded by design | Acquired asset outside procurement history | Acquisition inventory and platform evidence | Medium: add to CMDB and document compensating controls |
| AA-012 | Certificate endpoint | Certificate fingerprint and DNS name | Certificate observation and DNS | Certificate current; host not resolved internally | Unknown | Unknown | Unresolved external asset | DNS, registrar, certificate, and hosting investigation | Critical pending validation: establish ownership and exposure promptly |
A sophisticated join cannot repair incomplete or misleading source data. Record how each population was obtained and test whether filters, permissions, time windows, synchronization, pagination, licensing, and retention could omit material assets.
Confirm all intended tenants, subscriptions, locations, domains, organizational units, networks, sites, platforms, and lifecycle states were included. Compare reported counts to console totals and inspect whether APIs or exports truncate, page, or suppress records.
Trace selected fields to direct system configuration or physical/virtual evidence. Evaluate reused identifiers, cloned images, address changes, synchronized directories, agent reinstallations, and timestamps expressed in different timezones.
Restrict workpaper access, preserve originals separately from transformations, record query and matching logic, retain hashes when appropriate, minimize sensitive fields, and keep enough lineage for a reviewer to reproduce the result.
Use read-only collection methods whenever practical. Network discovery, cloud queries, endpoint actions, and external exposure validation must stay within written authorization, approved scope, safe rates, and change-control boundaries. This page does not authorize scanning or active testing.
These examples illustrate reasoning patterns. The applicable source, evidence threshold, risk, and action depend on the environment and authorized engagement.
Reconcile active directory devices, endpoint-management enrollment, EDR sensors, recent authentication, and ownership. Exclude obsolete directory objects only with lifecycle evidence. For remaining active devices, determine whether the sensor is absent, unhealthy, assigned to another console, unsupported, or blocked by network or policy. Recalculate coverage against the validated population and report both coverage and unresolved uncertainty.
Enumerate every approved cloud tenant, subscription, account, region, project, and delegated management boundary. Match resources to CMDB services, owners, cost centers, identity assignments, logs, vulnerability coverage, backup, and exposure. Treat tags as evidence to validate, not proof of accountability. Investigate resources with public access, missing owners, stale activity, or unsupported images first.
Correlate hardware address, lease history, switch port, wireless association, network-access control, DNS, discovery results, physical location, and traffic purpose. A device may be a legitimate printer, building system, guest device, lab unit, or unauthorized technology. Use an approved operational or incident process for containment; preserve the audit trail without independently disrupting service.
Compare disposal certificates, lease returns, asset tags, depreciation status, decommission tickets, backup retention, directory state, management telemetry, and network observation. Financial and operational retirement can occur on different dates. The audit should distinguish an accounting timing difference from an active unprotected asset or unverified disposal.
Assign each action to a named owner with a target date and validation method. Retesting should confirm both the immediate correction and the process change intended to prevent recurrence.
Validate internet-exposed, privileged, regulated-data, unsupported, and apparently unauthorized assets. Use approved incident, network, cloud, or endpoint processes to restrict risk while preserving evidence and business continuity.
Enroll missing assets, repair agents, correct ownership, validate backups, add monitoring, reconcile tenants, remove confirmed obsolete records, and document approved exceptions with expiration and residual risk.
Define authoritative attributes, stable identifiers, ingestion rules, lifecycle states, synchronization ownership, exception queues, acquisition and disposal triggers, and recurring reconciliation reports.
Track unmatched active assets, stale records, duplicate clusters, ownerless assets, unsupported technology, discovery-to-inventory delay, enrollment delay, exception age, and closure validation—not only tool-console coverage.
An audit establishes what the evidence supports and where assurance fails. Sustainable improvement requires ownership, monitoring, enrollment, documentation, lifecycle discipline, and timely exception handling across endpoint, network, server, identity, cloud, backup, and security operations.
When approved findings require practical remediation, proactive monitoring and maintenance support can help integrate supported assets into recurring operations, while network infrastructure management can strengthen device visibility, DHCP/DNS documentation, monitoring, and network accountability.
Use the cybersecurity control testing guide to distinguish an inventory design from implementation and sustained operation.
Request complete, reproducible population exports with the technical audit evidence request guide.
Preserve matching logic, source lineage, exceptions, and conclusions with the cybersecurity audit workpapers guide.
Place inventory reconciliation inside the broader internal cybersecurity audit process.
Drawing on more than 25 years across IT operations, cybersecurity leadership, compliance, Microsoft infrastructure, cloud, networks, firewalls, endpoint security, vulnerability management, and managed services, Ali Hassani evaluates inventories in the context of how systems are procured, deployed, connected, rebuilt, monitored, protected, and retired. That operational depth helps identify false coverage created by incomplete tool populations and weak lifecycle handoffs.
Review Ali Hassani’s professional background or contact OC Security Audit to discuss an independent IT asset inventory audit, coverage validation, attack-surface reconciliation, or remediation verification.
Applicable requirements depend on the organization, sector, contracts, and engagement. These resources support inventory and assessment methods but do not create universal obligations for every organization.
Control CM-8 addresses an accurate system-component inventory, complete scope, duplicate prevention, needed accountability attributes, and periodic review and update.
NIST assessment procedures support examining, interviewing, and testing evidence for security and privacy controls, including configuration-management controls.
CIS Control 1 addresses detailed enterprise asset inventory, unauthorized assets, and active, DHCP-based, and passive discovery safeguards.
CISA describes internet exposure sources that can improve visibility into public IP addresses, domains, certificates, and internet-connected assets.
It is the reconciled population supported by the best available evidence for the defined scope and date. One system may be authoritative for a stable identifier, another for ownership, and another for connectivity or management state. Authority should be assigned by attribute and tested, not assumed.
They often use enrolled or reporting devices as the denominator. Devices never enrolled, assigned to another tenant, unsupported, disconnected, or excluded may be absent. Reconcile the console population to independent active-asset sources before extending the percentage to the enterprise.
No. Validate disposal, decommissioning, rebuild, migration, retention, and inactivity evidence first. Preserve enough history to support incident investigations and the audit trail, then retire or archive records through the approved lifecycle process.
Use stable platform identifiers such as cloud resource ID, device ID, serial number, hardware UUID, management ID, directory ID, or agent ID, with corroboration. Hostnames and IP addresses can change or be reused and should be evaluated with timestamps and additional evidence.
Frequency should reflect risk, change velocity, environment size, contractual or regulatory requirements, and detection needs. High-change cloud or endpoint environments may require continuous or frequent automated comparison plus periodic independent review.
No. It documents declared assets and relationships, but its completeness depends on discovery integration, manual processes, procurement, cloud governance, acquisition, and retirement workflows. Compare it to independent technical and business sources.
Only within written authorization and defined safe methods. Prefer approved existing discovery evidence first. Any new active or passive discovery must respect scope, operational sensitivity, rates, monitoring, privacy, and stop conditions.
Evaluate their possible number, criticality, exposure, data access, and effect on coverage. If they could materially change the result, qualify or defer the conclusion rather than treating uncertainty as a clean exclusion.
OC Security Audit can help define the asset universe, collect and validate independent populations, reconcile identities, investigate exceptions, recalculate control coverage, and build a remediation roadmap that management and IT teams can act on.
Created by Ali Hassani, CISO — 25+ years of IT, cybersecurity, compliance, and infrastructure experience. This guide is for initial guidance only and does not replace a professional cybersecurity audit, compliance assessment, penetration test, legal/compliance review, privacy review, or engagement-specific authorization and methodology.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.