Table of Contents
ToggleYou cannot protect a PLC you do not know exists, and many plants find forgotten controllers, modems and laptops the first time they look properly. A complete, living list of every device is the foundation for patching, segmentation and incident response.
Control networks grow over decades through projects, vendors and quick fixes. A structured register of every device, its software and its role tells security and maintenance teams what they are really running.

What Is an OT Asset Inventory?
An OT asset inventory is an organised, regularly maintained record of every hardware and software asset in an industrial control environment, with attributes such as vendor, model, firmware, network address, location, function and criticality. It is the starting point for almost every requirement in IEC 62443 and similar frameworks.
In August 2025, CISA published Foundations for OT Cybersecurity: Asset Inventory Guidance with partners across nine countries and agencies. Industrial Defender summarises its five steps as scope, identify, taxonomy, data management and lifecycle management.

The record must include context and criticality, not just an IP address. Knowing that a PLC runs a boiler trip matters more than knowing its MAC address.
The inventory also supports maintenance, spares and obsolescence planning, as covered in DCS migration and obsolescence.
5 Essential Steps From the CISA Guide
Taxonomy often follows the levels of the Purdue model, from field devices to site servers. That makes it easy to map assets to zones.
Lifecycle management means changes, replacements and disposals update the record through the management of change process.
Discovery Methods Compared
| Method | How It Works | Risk to Process | Detail Level |
|---|---|---|---|
| Passive monitoring | Listens to traffic from a switch span port | None | Good |
| Active native query | Reads device info using its own protocol | Low if tested | Very good |
| Configuration files | Parse PLC and DCS project files | None | Excellent for logic |
| Physical walkdown | Visit cabinets and read nameplates | None | Finds offline devices |
Passive monitoring is the safe first step because it never sends packets to fragile devices. Active queries using native protocols add firmware and module details.
Span ports on SCADA and DCS network switches feed the passive tools. Walkdowns catch serial devices and spare laptops that never appear on Ethernet.
Attributes to Record
Controller models and firmware versions come from project files or diagnostics, as described in PLC diagnostic status bits. Keep owner and support contact details as well.
Security teams then match firmware versions with vulnerability advisories, which drives patching and replacement.
How the Inventory Feeds Security
Without an OT asset inventory, patching, segmentation and response become guesswork. It is often the first item in a SCADA security checklist.
Coverage Formula
Critical coverage = Critical assets with full attributes ÷ Critical assets × 100
Example:
Estimated 850 assets, 680 inventoried
120 critical assets, 102 with full data
Coverage 80 percent, critical coverage 85 percent
Aim for 100 percent critical coverage first, then broaden. Estimates improve as discovery tools and walkdowns reveal hidden devices.
Coverage Calculator
Track both figures every quarter as key performance indicators for the security programme.
- Clear view of the attack surface.
- Faster vulnerability matching.
- Better spares and obsolescence planning.
- Quicker incident response.
- Legacy and serial devices are hard to find.
- Data goes stale without change control.
- Active scans can upset fragile devices.
- Many vendors and formats.
Build team skills using free OT cybersecurity training before starting large discovery projects.
CISA Asset Inventory Guidance PDF
CISA Asset Inventory Webinar
OT Asset Inventory FAQ
Related Articles
- IEC 62443 Zones and Conduits
- Purdue Model ICS Cybersecurity
- Cybersecurity Standards for PLCs
- SCADA Security Checklist
- Network Switches for SCADA and DCS
External References
- Asset Inventory Guidance, CISA and Partners
- CISA Guide Summary, Industrial Defender
- Asset Management, Wikipedia
What We Learn Today
- An OT asset inventory lists every device with context and criticality.
- Follow the five CISA steps and prefer passive discovery first.
- Keep it current through change control and regular reviews.
