OT Asset Inventory: 5 Essential Steps From the CISA Guide

Share:
Cybersecurity
OT Asset Inventory: 5 Essential Steps From the CISA Guide

You cannot protect a PLC you do not know exists, and many plants find forgotten controllers, modems and laptops the first time they look properly. A complete, living list of every device is the foundation for patching, segmentation and incident response.

CISA Guidance Passive Discovery Asset Taxonomy Criticality

Control networks grow over decades through projects, vendors and quick fixes. A structured register of every device, its software and its role tells security and maintenance teams what they are really running.

Hello everyone, today we are going to learn how to build an OT asset inventory, follow the five steps in the 2025 CISA guidance, choose discovery methods and record the attributes that matter.
OT asset inventory

What Is an OT Asset Inventory?

An OT asset inventory is an organised, regularly maintained record of every hardware and software asset in an industrial control environment, with attributes such as vendor, model, firmware, network address, location, function and criticality. It is the starting point for almost every requirement in IEC 62443 and similar frameworks.

In August 2025, CISA published Foundations for OT Cybersecurity: Asset Inventory Guidance with partners across nine countries and agencies. Industrial Defender summarises its five steps as scope, identify, taxonomy, data management and lifecycle management.

Overview graphic of the CISA OT asset inventory guidance
Image credit: Industrial Defender

The record must include context and criticality, not just an IP address. Knowing that a PLC runs a boiler trip matters more than knowing its MAC address.

The inventory also supports maintenance, spares and obsolescence planning, as covered in DCS migration and obsolescence.

5 Essential Steps From the CISA Guide

1
Define Scope
Choose sites, zones and system boundaries.
2
Identify Assets
Discover devices by walkdown and network tools.
3
Build a Taxonomy
Group by function and criticality.
4
Manage the Data
Store, secure and reconcile records.
5
Maintain the Lifecycle
Update on every change and review regularly.

Taxonomy often follows the levels of the Purdue model, from field devices to site servers. That makes it easy to map assets to zones.

Lifecycle management means changes, replacements and disposals update the record through the management of change process.

Discovery Methods Compared

MethodHow It WorksRisk to ProcessDetail Level
Passive monitoringListens to traffic from a switch span portNoneGood
Active native queryReads device info using its own protocolLow if testedVery good
Configuration filesParse PLC and DCS project filesNoneExcellent for logic
Physical walkdownVisit cabinets and read nameplatesNoneFinds offline devices

Passive monitoring is the safe first step because it never sends packets to fragile devices. Active queries using native protocols add firmware and module details.

Span ports on SCADA and DCS network switches feed the passive tools. Walkdowns catch serial devices and spare laptops that never appear on Ethernet.

Attributes to Record

Identity
Tag, vendor, model and serial number.
Software
Firmware, OS, patches and applications.
Network
IP, MAC, VLAN, protocols and ports.
Location
Site, building, cabinet and zone.
Function
Process role and connected equipment.
Criticality
Safety, production and environmental impact.

Controller models and firmware versions come from project files or diagnostics, as described in PLC diagnostic status bits. Keep owner and support contact details as well.

Security teams then match firmware versions with vulnerability advisories, which drives patching and replacement.

How the Inventory Feeds Security

InventoryEvery asset and attribute
Vulnerability MatchingFirmware checked against advisories
Risk RankingCriticality and exposure combined
ControlsPatching, segmentation and monitoring
Incident ResponseResponders know what each device does

Without an OT asset inventory, patching, segmentation and response become guesswork. It is often the first item in a SCADA security checklist.

Coverage Formula

Coverage percent = Inventoried assets ÷ Estimated total assets × 100
Critical coverage = Critical assets with full attributes ÷ Critical assets × 100

Example:
Estimated 850 assets, 680 inventoried
120 critical assets, 102 with full data
Coverage 80 percent, critical coverage 85 percent

Aim for 100 percent critical coverage first, then broaden. Estimates improve as discovery tools and walkdowns reveal hidden devices.

Coverage Calculator

Inventory Completeness
Result
Coverage 80 percent, critical coverage 85 percent

Track both figures every quarter as key performance indicators for the security programme.

Benefits
  • Clear view of the attack surface.
  • Faster vulnerability matching.
  • Better spares and obsolescence planning.
  • Quicker incident response.
Challenges
  • Legacy and serial devices are hard to find.
  • Data goes stale without change control.
  • Active scans can upset fragile devices.
  • Many vendors and formats.

Build team skills using free OT cybersecurity training before starting large discovery projects.

CISA Asset Inventory Guidance PDF

PDF
Foundations for OT Cybersecurity: Asset Inventory Guidance
CISA, EPA, NSA, FBI and international partners, August 2025

CISA Asset Inventory Webinar

OT Asset Inventory FAQ

What is an OT asset inventory?
It is a maintained record of every control system device and its key attributes. It includes firmware, network details, location, function and criticality.
Why is it the first security step?
You cannot patch, segment or monitor devices you do not know about. The inventory drives every other control in the programme.
What does the CISA guidance recommend?
It sets out five steps of scope, identification, taxonomy, data management and lifecycle management. It was published in August 2025 with international partners.
Is active scanning safe?
Generic IT scanners can crash fragile devices. Start with passive monitoring and use tested native protocol queries only where approved.
How often should it be updated?
Update it through every change and review it at least yearly. Continuous passive monitoring helps spot new or changed devices.
What about serial devices?
Passive network tools cannot see them, so walkdowns and project files are needed. Record them just like Ethernet devices.
Which attributes matter most?
Identity, firmware, network, location, function and criticality are the core set. Criticality decides priorities for patching and response.

Related Articles

External References

What We Learn Today

  • An OT asset inventory lists every device with context and criticality.
  • Follow the five CISA steps and prefer passive discovery first.
  • Keep it current through change control and regular reviews.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *