Asset Inventory & Tracking
You cannot protect what you don't know exists. Asset management starts with a complete inventory:
- Hardware inventory: All physical devices — servers, workstations, laptops, network devices, printers, IoT
- Software inventory: All installed applications and licenses — identifies unauthorized software (shadow IT)
- Data inventory: Where sensitive data lives — critical for DLP and compliance
- Asset tagging: Physical labels (barcodes, QR, RFID) on hardware for tracking
- CMDB (Configuration Management Database): Central repository of all IT assets and their configurations and relationships
Mobile Device Management (MDM)
MDM solutions centrally manage and enforce policy on mobile devices:
- Remote wipe (full or selective/containerized)
- Enforce encryption, passcode complexity, screen timeout
- Push/install/remove apps remotely
- Geo-fencing — trigger actions based on device location
- Prevent camera use in sensitive areas
- VPN profile deployment
- Certificate deployment for enterprise Wi-Fi (802.1X)
Examples: Microsoft Intune, Jamf (Apple), VMware Workspace ONE, Google Endpoint Management.
MAM vs. MDM
| MDM (Mobile Device Management) | MAM (Mobile Application Management) | |
|---|---|---|
| Scope | Entire device | Only managed apps |
| Use Case | Corporate-owned devices | BYOD — employee personal devices |
| Remote Wipe | Full device wipe | Only corporate app data wiped |
| Privacy | Can see all device activity | Cannot see personal apps/data |
BYOD, COPE, CYOD Policies
| Policy | Description | Security Posture |
|---|---|---|
| BYOD (Bring Your Own Device) | Employee uses personal device for work | Weakest control — use MAM, containerization |
| COPE (Corporate-Owned, Personally Enabled) | Company buys device; employee can use personally | Full MDM policy applied |
| CYOD (Choose Your Own Device) | Employee picks from an approved list of corporate devices | Full MDM; limited device variety |
| Corporate-Owned Only | Strict corporate devices; no personal use | Strongest control |
Secure Data Disposal (Asset Lifecycle)
When an asset reaches end-of-life, its data must be properly destroyed before disposal or repurposing. (See also: Domain 3 — Secure Data Destruction)
- Maintain a chain of custody for disposal — document who destroyed what media, when, and how
- Certificate of destruction from a certified media destruction vendor
- Consider e-waste regulations — proper disposal of hardware components