IT-2 Inventory

Estimated reading: 2 minutes 1846 views

What is IT-2 Inventory control?

The IT-2 Inventory Control asks: ‘Are you aware of all the IT devices (such as laptops, organization mobile devices, phones, tablets, smartphones, printers, etc.) being used in your organization?

If so, are you tracking them?

Typically, for most organizations, these assets are workstations; however, some organizations enable smartwatches or systems for their employees. The goal here is to track such devices.

If the organization is using an asset management tool, tracking is easy. If not, this is to be done manually and reviewed at least once a year.

Available tools in the marketplace

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below, as we haven’t used them.

Asset Monitoring / Endpoint Security Tools
Jamf (Mac-specific)
Mosyle (Mac-specific)
OSQuery (free, open source)

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version:

  • N/A: no template for this control

Control implementation

NOTE: This control is 100% automated by TrustCloud. Connect your system to enjoy the benefits of automation.

To implement this control manually,

Take an inventory of all IT devices being used by your organization. This can include workstations, smart devices, printers, etc.

Review and update this list periodically (you can define how often this list will be updated).

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide a list of all devices from the asset management tool, tracking sheet, or document of internal devices.

Evidence example

For the suggested action, an example is provided below:

  1. Provide a list of all devices from the asset management tool, tracking sheet, or document of internal devices.
    The following screenshot shows a TrustCloud example demonstrating the list of internal devices.
    IT 2 Inventory 01

Join the conversation

You might also be interested in

Documentation Templates

Documentation Templates are documents that provide a content outline to meet certain documentation needs....

Data Backup Plan Template

The Data Backup Plan template helps you document in detail the data backup needs...

HR-13 Employee Handbook/Code of Conduct

HR-13 Employee Handbook or Code of Conduct communicates the organization’s values and ethics. It...

AUTH-1 Single Sign On (SSO)

Single Sign On (SSO) Control is a best practice recommendation for critical systems....

Security Incident Report Template

The Security Incident Report template helps you document the steps used to assess and...

BIZOPS-6 Disaster Recovery Testing

BIZOPS-6 Disaster Recovery Testing control refers to the exercise of identifying the critical systems...

PDP-10 SDLC – Separation of environments

PDP-10 SDLC Separation of Environments is important to maintain separate environments to develop, test,...

Privacy Committee Charter Template

Privacy Committee Charter serves as a foundational document, establishing the framework for the committee's...