ID.AM-01.121
Does your organization implement automated network monitoring to detect new hardware and update inventory records in real-time?
Explanation
Continuous network monitoring for new hardware is essential for maintaining an accurate asset inventory and identifying unauthorized devices that could pose security risks. Without automated detection, organizations may have blind spots in their network where unmanaged or rogue devices could operate undetected, potentially creating entry points for attackers or data exfiltration paths. Evidence of fulfillment could include screenshots of a network access control (NAC) system dashboard showing newly detected devices, documentation of the automated inventory update process, or reports from tools like network scanners or endpoint management systems that show timestamps of when new devices were detected and added to inventory.
Implementation Example
Constantly monitor networks to detect new hardware and automatically update inventories
ID: ID.AM-01.121
Context
- Function
- ID: IDENTIFY
- Category
- ID.AM: Asset Management
- Sub-Category
- Inventories of hardware managed by the organization are maintained

