Asset Inventory Template
One list of the devices, accounts, and services you are actually responsible for protecting.
Published · v1.0.0 · 2026-08-01
Exercise
Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.
Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team
Northline Fabrication has ten employees: six laptops, two shop tablets, one office server, cloud email and file storage, an accounting service, and a CAD application. Two employees use personal phones for email.
Hint: Ownership means a named person, not 'the shop'.
Hint: Email and file storage almost always hold the most sensitive data.
Hint: Follow the sensitive data, not the org chart.
Hint: Personal phones and the on-premise server are usually the honest answers.
Hint: Start with anything that receives company email.
Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.
Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.
NIST · Revision 3
SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems(opens in a new tab)Link last confirmed 2026-02-01
CISA
Secure Our World — Small Business Resources(opens in a new tab)Link last confirmed 2026-02-01
U.S. Small Business Administration
Strengthen Your Cybersecurity(opens in a new tab)Link last confirmed 2026-02-01
Complete every section, acknowledge, and pass the knowledge check.
This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.
Version v1.0.0 · Document owner: ComplianceAnvil Content Team
Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.
Matched on shared frameworks, topics, and program packs.
One list of the devices, accounts, and services you are actually responsible for protecting.
Published · v1.0.0 · 2026-08-01
Draft one System Security Plan section end to end, using the narrative pattern assessors expect.
Published · v1.0.0 · 2026-08-01
A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.
Published · v1.0.0 · 2026-08-01
Sort realistic records into classification levels and defend the handling rules that follow.
Published · v1.0.0 · 2026-08-01
Score yourself honestly across six areas and turn the two lowest into a short plan.
Published · v1.0.0 · 2026-08-01
A fast, honest look at your current security posture across identity, devices, data, people, and response.
Published · v1.0.0 · 2026-08-01
Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.