· ASSET INVENTORY

Asset Inventory & Attack Surface

An asset nobody knows about is unpatched, unmonitored and unrecovered by definition. Inventory is where cyber programmes stall, because the interesting assets are the ones nobody owns: a serial converter behind a panel, a vendor-supplied instrument with an embedded PC, the engineering laptop that holds the only copy of the programming software. In a regulated plant those are also the assets closest to product.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 23 LINKS

Every other control is scoped by the inventory. An asset nobody listed is not lightly protected — it is outside patching, monitoring, access review and backup simultaneously.

06 · QUALITY MATURITY — ASSET INVENTORY & ATTACK SURFACE, REACTIVE TO ADAPTIVE

L1
Reactive

A spreadsheet exists, maintained by hand, last reconciled at an unknown date. Laboratory instruments with embedded computers are absent from it.

L2
Defined

The inventory covers servers and workstations and is updated at procurement, but instruments, embedded controllers and cloud services are outside it.

L3
Controlled

Every asset that stores, processes or influences a regulated record is inventoried with its owner, its GxP relevance and its exposure, including instruments and hosted services.

L4
Predictive

Discovery is continuous rather than declared, so an asset appearing on the network is detected instead of waiting to be registered.

L5
Adaptive

The inventory is the operational spine other controls read from, so scoping patching, monitoring or access review is a query rather than a project.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 4

Derived from the 4 standards SPEQ maps to this subject, across 3 regulatory bodies: EMA, ISO, IEC.

RECORDS & OBJECTIVE EVIDENCE

  • The asset inventory with owner, GxP relevance and network exposure per entry
  • Reconciliation records between the inventory and what is actually on the network
  • Coverage of laboratory instruments and embedded controllers, not only IT endpoints
  • Hosted and cloud services inventoried alongside on-premise assets
  • Decommissioning records showing assets removed from service and from the inventory

COMMON INSPECTION FINDINGS

  • Laboratory instruments with embedded operating systems absent from the inventory entirely
  • An inventory maintained by declaration, with no reconciliation against the live network
  • Cloud and hosted services outside the inventory, so their controls are unassessed
  • Assets with no named owner, which leaves every control on them unassigned
  • Decommissioned equipment still holding regulated data and still connected
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

What an inventory has to record beyond existence

A list of hostnames is not an inventory. The fields that make it usable are the ones that support decisions: what the asset does, who owns it, what it connects to and depends on, what data it holds or produces, whether it has a GxP impact, what software and firmware version it runs, and whether that version is still supported. Without dependency and criticality, the inventory cannot tell you what a compromise reaches or what a patch window costs.

IEC 62443-2-1 makes the asset inventory an explicit requirement of the asset owner’s security programme, and specifically calls out the systems and connections that are easy to forget. ISO/IEC 27001 reaches the same requirement through Annex A. Neither prescribes a tool, and the tool is rarely the problem — the problem is that discovery on an OT network is constrained, because active scanning can disrupt the process it is scanning.

Discovery without breaking the plant

The IT approach — authenticated active scanning on a schedule — is unsafe on many control networks. Scanners have reset PLCs, and an agent that quarantines a driver can stop a line. The workable techniques are passive: span-port traffic analysis that identifies devices by what they say rather than by interrogating them, configuration extraction from the engineering workstations that already hold the project files, and structured walk-downs against the P&IDs and panel schedules.

Walk-downs are unfashionable and remain the only way to find assets that speak no network protocol anyone is listening to. The practical pairing is a passive baseline maintained continuously, reconciled periodically against a physical survey — because the passive view sees what talks, and the survey sees what is installed.

One register, two attributes

A regulated site maintains a validated-systems inventory with a GxP impact assessment, because Annex 11 expects one. A security programme maintains an asset inventory with a criticality assessment. Where these are two lists, they diverge — and the divergence is discovered during an incident, when the question is whether the compromised asset touches product.

Maintaining one register carrying both attributes costs less than reconciling two, and it puts the GxP criticality of an asset in front of whoever is making a security decision about it. That is the difference between a patch deferral assessed as an IT risk and one assessed as a risk to batch release.

Attack surface is a property of connections, not of assets

Counting assets does not measure exposure. What matters is reachability: which assets can be reached from an untrusted network, which paths exist between the business network and the process network, which remote-access routes are live, and which cloud services hold or can reach regulated data. An estate of ten thousand well-inventoried assets behind one flat network has a larger attack surface than a smaller estate that is properly segmented.

The recurring finding is a convenience connection: a link opened during commissioning or to solve a support problem, never removed, and invisible to the architecture diagram everyone reviews. Periodic verification that actual segmentation matches the designed zones and conduits is the control, and it has to be a test against the running network rather than a review of the drawing.

SPEQ interpretation — the inventory is a data-integrity control

Asset inventory is treated as security hygiene and funded accordingly. In a regulated environment it is also the thing that determines whether an organisation can answer the question that follows any incident: which regulated records could have been touched. That answer requires knowing which systems were reachable from the compromised asset and which of them create or hold GxP data — which is an inventory question, asked under time pressure.

So the argument for investing in the register is not only that it enables patching and monitoring. It is that without it, the record-integrity assessment after an incident cannot be scoped, and the organisation ends up either over-quarantining product it could have released or releasing product it cannot defend.

FREQUENTLY ASKED

Why can’t OT assets be discovered with normal network scanning?

Because active scanning can disrupt the process. Scanners have reset PLCs and interrogation traffic can upset devices that were never designed for it. Passive discovery — span-port traffic analysis, configuration extraction from engineering workstations — plus structured physical walk-downs is the safe combination, with the passive baseline reconciled periodically against the survey.

Should the security asset inventory and the GxP system inventory be separate?

No. Keeping two lists guarantees they diverge, and the divergence surfaces during an incident when the question is whether a compromised asset touches product. One register carrying both the security criticality and the GxP impact assessment costs less to maintain and puts the regulatory consequence in front of whoever is making the security decision.

What makes attack surface different from asset count?

Reachability. Exposure is a property of the connections between assets and untrusted networks, not of how many assets exist. A large, well-segmented estate can have a smaller attack surface than a small flat one — which is why verifying that actual segmentation matches the designed zones matters more than completing the asset count.

What is usually missing from an asset inventory?

The assets nobody owns: serial converters behind panels, vendor-supplied instruments with embedded PCs, engineering laptops holding the only copy of programming software, and connections opened during commissioning and never removed. These are the ones closest to production and the least likely to appear on an architecture diagram.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…