We have a minimalist asset management program today and are beginning to re-conceptualize. At present we have an asset mgr supported by a junior level reporting resources focused on hardware inventory. As we move forward with a more evolved CMDB, new discovery processes, and a desire to incorporate software assets we'd like to define our ideal staffing configuration. What does your team complement w/roles and responsibilities consist of?

2.2k viewscircle icon3 Comments
Sort by:
CISOa year ago

The issue of information assets is something that I have found is not completely resolved in organizations. We have used several approaches and we always arrive at a complex result. My suggestion is to use an approach that is as simple as possible: define taxonomy at the domain level and information subdomains, and at that general level define classification of information assets and depending on the classification (confidential, public, etc.) define the controls to be applied on those assets and on the technological components in which those assets live. For this you must have the relationship between information assets and the technological component in which they live, to define controls over both. On how to organize the work team to do this work, you would already define the ideal organization chart for this depending on which areas are responsible for IT components and information assets (hey may be different areas or the same depending on your organizational structure) and depending on this you must define relationships or subordination. between these areas

Director of ITa year ago

The streamlined asset management team includes:
Asset Management Lead: Sets strategy, policies, defines asset management scope and ensures ongoing governance and compliance.
Asset Analyst(s): Handle day-to-day tasks like inventory maintenance, reconciliation, and reporting.
Discovery and Automation Specialist(s): Implements and manages automated tools for asset discovery and integration with the CMDB. 
As your organization grows, consider expanding the team with specialized roles for Software, Hardware, Cloud, and Data Asset Managers to enhance asset management capabilities further.

VP of ITa year ago

Asset management is also an intense discussed topic in our organisation. Since we introduced Qualys as a software scanner, we enriched our CMDBs also with a lot of data about the software artefacts on our servers. Both together is joined with information about vulnerabilities. 
In the process to enrich our CMDBs and join them in one central terradata environment, we have the following roles: data management (in our org part of the enterprise architecture), IT-Security, process owner for the vulnerability management, Data Science Expert (for the data agregation and reporting), infrastructure expert and application owner of the CMDBs.  

Content you might like

An EA certification18%

Several years of general EA experience73%

Experience with a business similar to yours8%

View Results

Yes72%

No21%

Unsure5%

Other (explain in the comments)1%

View Results