1. Homepage
  2. Trust Center
  3. Security
  4. Identify
  5. Asset management Asset management

1.4 Asset management

Attackers are continuously scanning organizations, waiting for new and unprotected systems to be attached to the network or to look for vulnerable versions of software that can be remotely exploited.

  • In terms of hardware, attackers look for devices (especially laptops) which come and go off of the enterprise’s network, and so get out of sync with patches or security updates. Additional systems that connect to the enterprise’s network (e.g., demonstration systems, temporary test systems, guest networks) are be managed carefully and/or isolated in order to prevent adversarial access from affecting the security of enterprise operations.

  • In terms of software, attackers scan target organizations and distribute hostile web pages, document files, media files, and other content via their own web pages or otherwise trustworthy third-party sites. When unsuspecting victims access this content with a vulnerable browser or other client-side program, attackers compromise their machines, often installing backdoor programs and bots that give the attacker long-term control of the system. Once a single machine has been exploited, attackers often use it as a staging point for collecting sensitive information from the compromised system and from other systems connected to it. In addition, compromised machines are used as a launching point for movement throughout the network and partnering networks. In this way, attackers may quickly turn one compromised machine into many.

“Know what we have” is therefore an important factor; if we don’t know what we have, we can’t protect is. It is therefore critical that Renewi devices and systems that enable the organization to achieve its business goals are identified and managed consistent with their relative importance to organizational objectives and the organization’s risk strategy.

Key principles

Hardware inventory

Renewi actively manages (inventory, track, and correct) all hardware devices on the network in an accurate and up-to-date inventory. The hardware asset inventory records the network address, hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network

Software Inventory

Renewi actively manages (inventory, track, and correct) all software on its systems. Software inventory tools are deployed throughout Renewi covering each of the operating system types in use, including servers, workstations, and laptops. The software inventory system should track the version of the underlying operating system as well as the applications installed on it.

Blacklisting

By default, Renewi employees are ‘semi’ local admin on their client machines. They are able to install software, but are unable to change certain settings in the operating system. To control the installing of software, and in addition to software inventory tools, Renewi applies blacklisting so that unauthorized and unmanaged software is found and prevented from installation or execution.