Modern security platforms are no longer defined by a single inventory, but by their ability to unify software, infrastructure, identity, data, exposure, and behavior into a living, risk-aware security graph.

A basic understanding of our glossarycompliance frameworksjob roles and unified cloud security categories is required.

Inventory Landscape

1. Software & Application Inventories

Purpose: Understand what software exists and how it’s built.

Key inventories
  • Application Inventory
    Apps, services, microservices, APIs
  • Dependency / SBOM Inventory
    Libraries, frameworks, open-source components
  • Version & Configuration Inventory
    OS, runtime, frameworks, feature flags
  • License Inventory
    Commercial software usage and entitlements
  • API Inventory
    Internal, partner, and public APIs

Primary users: Engineering, DevOps, AppSec
Key question: What software are we running and how is it composed?

2. Infrastructure & Platform Inventories

Purpose: Track the environments software runs on.

Key inventories
  • Compute Inventory
    Servers, VMs, containers, serverless
  • Network Inventory
    VPCs, subnets, firewalls, load balancers
  • Storage Inventory
    Databases, object storage, volumes
  • Platform Inventory
    Kubernetes clusters, PaaS services
  • On-prem / Hybrid Inventory

Primary users: IT, CloudOps, SRE
Key question: Where does everything run?

3. Cloud-Native & CNAPP Inventories

Purpose: Secure cloud workloads with context.

Key inventories
  • Cloud Asset Inventory
    All cloud resources across providers
  • Workload Inventory
    Containers, images, functions
  • Identity & IAM Inventory
    Roles, permissions, service accounts
  • Configuration & Posture Inventory
    Misconfigurations, policy drift
  • Runtime Behavior Inventory
    Process activity, network flows

Primary users: Cloud security, DevSecOps
Key question: How are cloud workloads configured, behaving, and exposed?

4. Cybersecurity Core Inventories

Purpose: Establish security visibility and control.

Key inventories
  • Endpoint Inventory
    Laptops, servers, mobile devices
  • Vulnerability Inventory
    CVEs, weaknesses, exploitability
  • Patch & Update Inventory
  • Control Inventory
    Security tools, policies, detections
  • Security Event Inventory
    Alerts, incidents, detections

Primary users: SecOps, IT security
Key question: What security risks and controls exist today?

5. Identity, Access & Trust Inventories

Purpose: Secure who or what can do what.

Key inventories
  • User Inventory
    Employees, contractors, partners
  • Machine & Non-Human Identity Inventory
    Service accounts, workloads, bots
  • Credential Inventory
    Keys, secrets, tokens, certificates
  • Privilege Inventory
    Admin rights, excessive permissions
  • Trust Relationship Inventory

Primary users: IAM, Zero Trust teams
Key question: Who has access to what, and why?

6. Data & Information Inventories

Purpose: Protect sensitive and regulated data.

Key inventories
  • Data Asset Inventory
    Databases, data lakes, SaaS data
  • Data Classification Inventory
    PII, PHI, PCI, IP
  • Data Flow Inventory
    Ingress, egress, sharing paths
  • Data Access Inventory
  • Data Residency & Compliance Inventory

Primary users: Security, privacy, compliance
Key question: Where is sensitive data and how does it move?

7. Attack Surface Management (ASM) Inventories

Purpose: See the organization like an attacker.

Key inventories
  • External Asset Inventory
    Domains, subdomains, IPs
  • Exposure Inventory
    Open ports, services, APIs
  • Shadow IT Inventory
  • Third-Party & Supply Chain Inventory
  • Change & Drift Inventory

Primary users: Offensive security, SecOps
Key question: What is visible, reachable, or exploitable from the outside?

8. Threat, Risk & Adversary Inventories

Purpose: Understand risk in context.

Key inventories
  • Threat Inventory
    Threat actors, TTPs
  • Attack Technique Inventory
    MITRE ATT&CK mappings
  • Exploit & Weaponization Inventory
  • Risk Inventory
    Business impact, likelihood
  • Attack Path Inventory

Primary users: Threat intel, SOC, leadership
Key question: How could this environment be attacked and what matters most?

9. Compliance, Governance & Policy Inventories

Purpose: Demonstrate control and accountability.

Key inventories
  • Policy Inventory
  • Control & Framework Inventory
    ISO, NIST, SOC 2, CIS
  • Audit Evidence Inventory
  • Exception & Risk Acceptance Inventory
  • Regulatory Scope Inventory

Primary users: GRC, auditors, executives
Key question: Are we compliant and can we prove it?

10. AI-Native & Autonomous Security Inventories

Purpose: Enable reasoning, autonomy, and scale.

Key inventories
  • Security Knowledge Graph
    Assets, identities, data, relationships
  • Behavioral Inventory
    Normal vs anomalous patterns
  • Decision & Action Inventory
    Agent decisions, remediations
  • Model Inventory
    AI models, versions, training data
  • Prompt & Agent Inventory

Primary users: AI security, platform teams
Key question: How does the system reason, learn, and act securely?

11. Business & Ownership Inventories (Often Missing)

Purpose: Tie security to outcomes.

Key inventories
  • Service Ownership Inventory
  • Application Criticality Inventory
  • Business Process Inventory
  • Cost & Usage Inventory
  • Risk Acceptance Ownership Inventory

Primary users: Executives, product, finance
Key question: What actually matters to the business?

Unified View: Inventory by Maturity
Maturity Level
Inventory Type
Basic
Asset lists
Operational
Configuration & vulnerability
Security
Exposure & attack surface
Advanced
Attack paths & risk
Next-Gen
Knowledge graphs & autonomy


Modern security platforms are no longer defined by a single inventory, but by their ability to unify software, infrastructure, identity, data, exposure, and behavior into a living, risk-aware security graph.