Exercise

Build Your First Asset Inventory

Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.

Intended audience
Beginners with no inventory yet
Difficulty
Beginner
Estimated time
20 minutes
Access
Free
CIS Controls
NIST SP 800-171
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Enumerate every device, cloud service, and endpoint in a small business scenario, including easily overlooked personal devices.
  • Assign a named owner to each asset rather than a department or team.
  • Determine which assets belong in compliance scope by tracing where sensitive data actually flows.
  • Recognize the two most common inventory gaps: unmanaged personal devices and legacy on-premise servers.
  • Draft the opening rows of a real asset inventory using the same pattern practiced in the scenario.

Scenario

Northline Fabrication has ten employees: six laptops, two shop tablets, one office server, cloud email and file storage, an accounting service, and a CAD application. Two employees use personal phones for email.

Key takeaways

  • An asset inventory is only useful when every item has a specific, named owner who can act on it.
  • Scope should follow the data: any device or service that touches sensitive information belongs in the compliance boundary, regardless of who purchased it.
  • Personal devices used for company email or files are a common, high-risk inventory gap that organizations frequently omit.
  • Cloud services deserve the same inventory rigor as physical hardware because they typically hold the most sensitive data.
  • Building even five accurate rows of a real inventory is more valuable than a long list of guesses.

Practice workspace

  1. Hint: Ownership means a named person, not 'the shop'.

  2. Hint: Email and file storage almost always hold the most sensitive data.

  3. Hint: Follow the sensitive data, not the org chart.

  4. Hint: Personal phones and the on-premise server are usually the honest answers.

  5. Hint: Start with anything that receives company email.

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 1
Knowledge check

80% required to pass. Answers are graded on our servers.

1. In the Northline Fabrication scenario, why do the two employee personal phones matter for the inventory?

2. What is the correct way to record ownership in an asset inventory?

3. Which principle should determine whether an asset is in scope for a compliance program?

4. Why do cloud services like email and file storage usually need special inventory attention?

5. What is the most honest way to identify the riskiest inventory gaps?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Matched on shared frameworks, topics, and program packs.

Template

Asset Inventory Template

One list of the devices, accounts, and services you are actually responsible for protecting.

Beginner
30 min
Free
CIS Controls
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Guide

Building a Security Program from Scratch

A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.

Beginner
14 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Exercise

Classify Sample Data

Sort realistic records into classification levels and defend the handling rules that follow.

Intermediate
15 min
Free
NIST SP 800-171
ISO 27001

Published · v1.0.0 · 2026-08-01

Exercise

Complete a Readiness Scorecard

Score yourself honestly across six areas and turn the two lowest into a short plan.

Beginner
15 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Checklist

Cybersecurity Self-Assessment Checklist

A fast, honest look at your current security posture across identity, devices, data, people, and response.

Beginner
25 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.