Educause Security Discussion mailing list archives

Re: Asset/Resource Inventory


From: Todd Plesco <todd.plesco () INFOSECURITY PRO>
Date: Sat, 18 Jul 2015 08:19:32 -0700

 One of the challenges we deal with is validating our network vulnerability
scans with network assets so I have been reading up on ISO 17990 as it
relates to inventory identification and asset management needs for network
and infrastructure security.   We use a combination of different systems
but do not have a centralized ITAM.

There is an annual conference and expo (ACE) coming up in Dublin, Ireland
on September 1-2 for the International Association of IT Asset Managers
(IAITAM.)  If you register before July 31, IAITAM membership is included
free with the ACE registration.
Here's the link
https://www.iaitam.org/eweb/DynamicPage.aspx?Site=IAITAM&WebCode=EventDetail&evt_key=a8b85ae0-4de3-4eda-906b-d17e74e83c09
<https://exchange.chapman.edu/owa/redir.aspx?SURL=-GxT6_5fz3WRjJNTRlgxINbEuVQfASxGP6zLOks4vb5lp2nLg4_SCGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAGkAYQBpAHQAYQBtAC4AbwByAGcALwBlAHcAZQBiAC8ARAB5AG4AYQBtAGkAYwBQAGEAZwBlAC4AYQBzAHAAeAA_AFMAaQB0AGUAPQBJAEEASQBUAEEATQAmAFcAZQBiAEMAbwBkAGUAPQBFAHYAZQBuAHQARABlAHQAYQBpAGwAJgBlAHYAdABfAGsAZQB5AD0AYQA4AGIAOAA1AGEAZQAwAC0ANABkAGUAMwAtADQAZQBkAGEALQA5ADAANgBiAC0AZAAxADcAZQA3ADQAZQA4ADMAYwAwADkA&URL=https%3a%2f%2fwww.iaitam.org%2feweb%2fDynamicPage.aspx%3fSite%3dIAITAM%26WebCode%3dEventDetail%26evt_key%3da8b85ae0-4de3-4eda-906b-d17e74e83c09>

Regards,

Todd A. Plesco CISM, CBCP

Chapman University, Director of Information Security

Phone: (714) 997-6726/Fax: (714) 744-7041


On Thu, Jul 16, 2015 at 1:31 PM, Fowler, Becky Thurmond <
ThurmondR () missouri edu> wrote:

 Hello!  At the University of Missouri an effort is underway to explore
the creation of an authoritative IT asset/resource inventory.  We are
hoping to collect and share information from our peer institutions on your
successes and challenges in this area.  If your institution has (or is
working on) such an inventory, could you please take a few moments and
briefly answer the questions below?  We will be happy to summarize the
information and provide a report back to this list.



1.       Do you have a centralized IT asset/resource tracking system?

2.       Is the system authoritative and how well does it integrate with
satellite/distributed systems?

3.       What tools are you using?  (commercial, custom, etc)  If
commercial, what is the licensing model?

4.       What are the ballpark costs for your organization and how many
FTE does it take to run the system (both from a technology & a business
process standpoint)

5.       How well does it work for your organization?  Have you
encountered significant roadblocks?



Thanks in advance for your assistance!





*Becky Thurmond Fowler*

Manager, Security Assessments & Incident Response

Division of IT – Information Security & Access Management

University of Missouri-Columbia

becky () missouri edu

573.882.5182




Current thread: