Modern security platforms are no longer defined by a single inventory, but by their ability to unify software, infrastructure, identity, data, exposure, and behavior into a living, risk-aware security graph.
A basic understanding of our glossary, compliance frameworks, job roles and unified cloud security categories is required.
Inventory Landscape
1. Software & Application Inventories
Purpose: Understand what software exists and how it’s built.
Key inventories
- Application Inventory
Apps, services, microservices, APIs - Dependency / SBOM Inventory
Libraries, frameworks, open-source components - Version & Configuration Inventory
OS, runtime, frameworks, feature flags - License Inventory
Commercial software usage and entitlements - API Inventory
Internal, partner, and public APIs
Primary users: Engineering, DevOps, AppSec
Key question: What software are we running and how is it composed?
2. Infrastructure & Platform Inventories
Purpose: Track the environments software runs on.
Key inventories
- Compute Inventory
Servers, VMs, containers, serverless - Network Inventory
VPCs, subnets, firewalls, load balancers - Storage Inventory
Databases, object storage, volumes - Platform Inventory
Kubernetes clusters, PaaS services - On-prem / Hybrid Inventory
Primary users: IT, CloudOps, SRE
Key question: Where does everything run?
3. Cloud-Native & CNAPP Inventories
Purpose: Secure cloud workloads with context.
Key inventories
- Cloud Asset Inventory
All cloud resources across providers - Workload Inventory
Containers, images, functions - Identity & IAM Inventory
Roles, permissions, service accounts - Configuration & Posture Inventory
Misconfigurations, policy drift - Runtime Behavior Inventory
Process activity, network flows
Primary users: Cloud security, DevSecOps
Key question: How are cloud workloads configured, behaving, and exposed?
4. Cybersecurity Core Inventories
Purpose: Establish security visibility and control.
Key inventories
- Endpoint Inventory
Laptops, servers, mobile devices - Vulnerability Inventory
CVEs, weaknesses, exploitability - Patch & Update Inventory
- Control Inventory
Security tools, policies, detections - Security Event Inventory
Alerts, incidents, detections
Primary users: SecOps, IT security
Key question: What security risks and controls exist today?
5. Identity, Access & Trust Inventories
Purpose: Secure who or what can do what.
Key inventories
- User Inventory
Employees, contractors, partners - Machine & Non-Human Identity Inventory
Service accounts, workloads, bots - Credential Inventory
Keys, secrets, tokens, certificates - Privilege Inventory
Admin rights, excessive permissions - Trust Relationship Inventory
Primary users: IAM, Zero Trust teams
Key question: Who has access to what, and why?
6. Data & Information Inventories
Purpose: Protect sensitive and regulated data.
Key inventories
- Data Asset Inventory
Databases, data lakes, SaaS data - Data Classification Inventory
PII, PHI, PCI, IP - Data Flow Inventory
Ingress, egress, sharing paths - Data Access Inventory
- Data Residency & Compliance Inventory
Primary users: Security, privacy, compliance
Key question: Where is sensitive data and how does it move?
7. Attack Surface Management (ASM) Inventories
Purpose: See the organization like an attacker.
Key inventories
- External Asset Inventory
Domains, subdomains, IPs - Exposure Inventory
Open ports, services, APIs - Shadow IT Inventory
- Third-Party & Supply Chain Inventory
- Change & Drift Inventory
Primary users: Offensive security, SecOps
Key question: What is visible, reachable, or exploitable from the outside?
8. Threat, Risk & Adversary Inventories
Purpose: Understand risk in context.
Key inventories
- Threat Inventory
Threat actors, TTPs - Attack Technique Inventory
MITRE ATT&CK mappings - Exploit & Weaponization Inventory
- Risk Inventory
Business impact, likelihood - Attack Path Inventory
Primary users: Threat intel, SOC, leadership
Key question: How could this environment be attacked and what matters most?
9. Compliance, Governance & Policy Inventories
Purpose: Demonstrate control and accountability.
Key inventories
- Policy Inventory
- Control & Framework Inventory
ISO, NIST, SOC 2, CIS - Audit Evidence Inventory
- Exception & Risk Acceptance Inventory
- Regulatory Scope Inventory
Primary users: GRC, auditors, executives
Key question: Are we compliant and can we prove it?
10. AI-Native & Autonomous Security Inventories
Purpose: Enable reasoning, autonomy, and scale.
Key inventories
- Security Knowledge Graph
Assets, identities, data, relationships - Behavioral Inventory
Normal vs anomalous patterns - Decision & Action Inventory
Agent decisions, remediations - Model Inventory
AI models, versions, training data - Prompt & Agent Inventory
Primary users: AI security, platform teams
Key question: How does the system reason, learn, and act securely?
11. Business & Ownership Inventories (Often Missing)
Purpose: Tie security to outcomes.
Key inventories
- Service Ownership Inventory
- Application Criticality Inventory
- Business Process Inventory
- Cost & Usage Inventory
- Risk Acceptance Ownership Inventory
Primary users: Executives, product, finance
Key question: What actually matters to the business?
Unified View: Inventory by Maturity
Maturity Level | Inventory Type |
|---|---|
Basic | Asset lists |
Operational | Configuration & vulnerability |
Security | Exposure & attack surface |
Advanced | Attack paths & risk |
Next-Gen | Knowledge graphs & autonomy |
Modern security platforms are no longer defined by a single inventory, but by their ability to unify software, infrastructure, identity, data, exposure, and behavior into a living, risk-aware security graph.
