Jason Edwards
Asset management is the operational backbone of effective blue team defense because every downstream control depends on knowing what exists, where it is, and who is responsible for it. This chapter explains why asset awareness determines the scope and reliability of patching, vulnerability management, monitoring, identity controls, and incident response. It expands the definition of “asset” beyond hardware to include cloud workloads, SaaS tenants, identities, certificates, code repositories, and data stores, emphasizing that incomplete visibility creates blind spots that attackers exploit and defenders struggle to measure. The chapter details how to build and sustain an inventory using continuous multi-signal discovery and reconciliation rather than a one-time list. It covers the practical mechanics of creating canonical asset records, establishing stable identifiers, and maintaining data quality through provenance, confidence, and ongoing drift management. Readers will learn how to define durable ownership and accountability that survives reorganizations, and how to classify assets by business criticality, exposure, and data sensitivity so defensive effort is focused where it reduces real risk. Finally, the chapter addresses modern realities that break traditional asset programs, including shadow IT, unknown assets, and the lifecycle pitfalls that leave residual access and trust behind. It explains how correlation and AI-assisted discovery can accelerate enrichment and prioritization when grounded in strong telemetry and bounded by verification and human approval. Throughout, the focus remains operational: building repeatable workflows that turn asset management into a control surface that drives security work, speeds response, and produces coverage leaders can trust.