Analysis

IT asset management: the method before the tool

The tool comes last. Asset management software installed on an incomplete inventory with no written rules only automates the disorder.

Close-up of a laptop keyboard lit in turquoise
A device estate is held together by its inventory, not by its breakdowns

IT asset management means knowing at all times what equipment, software, accounts and access rights the business has, who uses them, and what state they are in. In most small businesses that knowledge exists only in pieces: in the IT go-to person’s memory, in invoices, in a supplier’s console. The question usually arises at the worst moment — a departure, a theft, an attack, an audit — and that is when the business finds out what it did not know.

The temptation is to start with software. That is the reverse of the order that works. The tool comes last: first the inventory, then the rules, and only then the tool that will keep them.

Taking an inventory of IT assets: devices, licences, accounts, access rights

An IT asset inventory has four parts, and the first is the least important of the four.

  • Devices and equipment. Computers, phones, tablets, printers, network equipment: who uses them, since when, on what system, how up to date, and whether their disk is encrypted.
  • Licences and subscriptions. Every piece of software and online service paid for, with its number of seats, its renewal date and its owner.
  • Accounts. Every account open in each tool — including those of former staff, contractors and interns.
  • Privileged access. Who holds administrator rights, over what, and why.

The last two parts are the ones people neglect, and the ones that matter most. ANSSI’s IT hygiene guide devotes a whole chapter to knowing the information system, and asks in particular for an exhaustive, up-to-date inventory of privileged accounts: they are the first targets of an attacker looking to spread. A lost laptop can be replaced; a forgotten administrator account, still active three years after its holder left, opens the door to everything else.

To start with, the sources are well known: invoices and card statements for subscriptions, the admin consoles of the main tools for accounts, and a walk round the offices for hardware. The result first fits in a simple spreadsheet. It does not need to be perfect to be useful: it needs to exist.

That leaves personal devices used for work — a salesperson’s phone, a partner’s laptop. They do not belong to the business, but they reach its data. The inventory must at least list them, and the rules must say what they may access: ANSSI advises against mixing personal devices and work use, precisely because the business controls neither their security nor what becomes of them.

Management rules: arrivals, departures, renewals

An inventory starts deteriorating the next day unless rules keep it up. Three moments decide its quality, and ANSSI makes organising arrivals, departures and changes of role one of its basic measures.

Arrival

What equipment is handed over, which accounts are opened, with what rights, and who decides. A written list avoids the two usual pitfalls: the newcomer who waits a week for access, and the one who is given the predecessor’s rights for convenience.

Departure

This is the riskiest moment. On the day someone leaves, accounts are closed or suspended, access revoked — including to online tools signed up for outside the IT function —, equipment recovered, and work data transferred to whoever must take it over. Without a written procedure, every departure leaves open accounts and licences paid for nobody.

Renewal

Every device has a lifespan, every piece of software an end of support. Knowing them makes it possible to plan the budget rather than endure it, and to avoid keeping in service systems that no longer receive security updates — a precaution the ANSSI guide also ties to keeping an up-to-date inventory.

These rules belong in the IT usage policy, which tells everyone what is permitted and what the business monitors. The policy sets the rule; asset management makes it possible to keep it.

Choosing IT asset management software: the criteria

Once the inventory is in place and the rules are written, software becomes useful: it keeps the inventory up to date automatically, and enforces the rules without relying on anyone’s memory. The market mixes tools of different kinds, which are better told apart before comparing:

  • inventory and service management tools, often combined with request and incident tracking — GLPI, open-source software, is a widespread example in France;
  • remote monitoring and management platforms for devices, used in particular by managed-services providers — NinjaOne is one of them;
  • discovery tools, which scan the network to list what connects to it, such as Lansweeper;
  • mobile device and endpoint management tools, often tied to an office environment, such as Microsoft Intune.

These names illustrate categories; they are not a recommendation. The right choice depends on criteria that concern the business more than the software:

  • who will run it — an employee, a supplier, or nobody, in which case the simplest tool will be the best;
  • what it must cover — hardware only, or licences, accounts and online tools as well;
  • how it connects to what exists — account directory, office tools, request tracking;
  • where the data it collects about devices and users is stored, since it becomes a processor of that data;
  • reversibility — being able to export the inventory on the day the tool or the supplier changes.

The last criterion is often forgotten. When the tool belongs to the managed-services provider, the inventory effectively belongs to that provider: changing supplier then means losing knowledge of one’s own assets.

Licence tracking, the forgotten budget line

Licences are the part of the assets that costs without being seen. They renew automatically, multiply by department, and survive departures. Tracking them almost always reveals the same gaps: seats paid for people who have left, redundant tools signed up for by two teams, plan tiers above actual use, renewal dates passed without anyone having had a chance to renegotiate.

A growing share of these licences escapes the IT function: online tools signed up for by a team, paid by card, adopted before any decision. They do not only cost money. Each processes the business’s data, sometimes personal data, and therefore requires a contract compliant with GDPR Article 28 that nobody has read.

Tracking comes down to a few columns — tool, seats paid, seats active, plan tier, renewal date, owner — and one fixed moment: a review before each major renewal. It is often the first workstream that pays back the asset management effort, because its effects show on the following invoices.

When the business wants a full picture — assets, security, contracts, compliance — before investing, that is the purpose of an IT audit for a small business. And it is the work Maeliom Consulting most often undertakes first: knowing what you have, before deciding what to do with it.

Common questions

Where should an IT asset inventory start?

With accounts and subscriptions rather than hardware: invoices, card statements and the admin consoles of the main tools. That is where the risks and hidden costs lie.

Does a small business need asset management software?

Not at first. An up-to-date spreadsheet is enough while the assets are few and the rules written down. Software becomes useful when manual updating is no longer kept up.

Who should be responsible for asset management?

A named person, even part time, with a mandate from management. A supplier can run the tool, but the inventory must stay accessible to the business and exportable.

Source: ANSSI, IT hygiene guide (version 2.0, 2017), chapter “Knowing the information system”.


Next article

Website redesign cost: what really makes the budget vary

Read

A transformation to support?