2.5: Integrate Software and Hardware Asset Inventories

The software inventory system should be tied into the hardware asset inventory so all devices and associated software are tracked from a single location.

Asset Type

Security Function

Implementation Groups

Applications

Identify

3

Dependencies

  • Sub-control 1.4: Maintain Detailed Asset Inventory

  • Sub-control 1.5: Maintain Asset Inventory Information

Inputs

  1. The list of endpoints

Operations

  1. Enumerate software inventory systems from the endpoint inventory

  2. Enumerate hardware inventory systems from the endpoint inventory

  3. For each software inventory system, examine its configuration to ensure that it is tied to at least one hardware inventory system, noting appropriately and inappropriately configured software inventory systems

Measures

  • M1 = List of software inventory systems

  • M2 = List of hardware inventory systems

  • M3 = List of appropriately configured software inventory systems

  • M4 = List of inappropriately configured software inventory systems

  • M5 = Count of software inventory systems (count of M1)

  • M6 = Count of hardware inventory systems (count of M2)

  • M7 = Count of appropriately configured software inventory systems (count of M3)

  • M8 = Count of inappropriately configured software inventory systems (count of M4)

Metrics

Coverage

Metric

The ratio of appropriately configured software inventory systems to the number of
software inventory systems

Calculation

M7 / M5