IT asset management best practices, as published, are mostly written for organisations with an ITAM team, a configuration database and a procurement function. A company of five to two hundred people has one person and a spreadsheet, and the practices that matter are the ones that keep that register true without a team. This page sets out eight of them, each one a habit rather than a project: one register, a serial number and a holder on every line, discovery reconciled against the register, seats counted against people, a warranty date on every device, the leaver's laptop handled the same day, a disposal record with a wipe, and one physical count a year that records what was not found. The free worksheets on this site work the arithmetic behind three of them.
One register, not three, and a serial number and holder on every line
The laptop list, the phone list and the accountant's fixed asset schedule are usually three files kept by three people that disagree about the same devices. The first practice is one register with a serial number, a holder, a location, a cost, a purchase date and a warranty end date on every line, and the fixed asset schedule generated from it rather than kept beside it. CIS Control 1 asks for exactly this inventory of enterprise assets, reviewed and updated at least every six months; a small organisation that keeps it current on every issue and return does better than that without trying.
Reconcile the register against the network, on a cadence
A register typed from purchase orders drifts from the day it is finished. The second practice is a discovery pass, an agent report or a scan of the address ranges, reconciled against the register on a cadence. Federal agencies are directed to discover every 7 days; a small organisation that reconciles before each monthly or quarterly close is doing well. The discovery coverage worksheet on this site works the reconciliation: what answered, what the register expected, and the unknown devices in between.
Count the seats against people, and release them the day someone leaves
Software asset management in a small organisation is one habit: every paid seat is counted against the person using it, and the leaver's seats are released on the day the laptop comes back. The IT asset inventory worksheet here costs the seats a year, and the figure is usually larger than anyone expected, because seats are bought per person and cancelled per nobody. A licence audit from a vendor is survived by the same record.
Warranty dates, the leaver's laptop, the disposal wipe and the annual count
The remaining practices are the ones that fail silently. A warranty end date on every line, so the out-of-warranty count and its replacement value are a report rather than a surprise. The leaver's laptop returned, wiped and reissued or retired the same day, with the rows to show it. A disposal that records the sanitisation of the storage, in the way NIST SP 800-88 describes. And one physical count a year that records what was found and, more importantly, what was not, because a register that only records presence never learns anything.
Questions people ask about it asset management best practices
Which IT asset management best practice matters most for a small organisation?
One register with a holder on every line. Every other practice depends on it, and most of the failures in small organisations come from three lists that disagree rather than from the absence of a tool.
How often should a small organisation reconcile its IT register against the network?
Before each monthly or quarterly close is a good habit. CISA directs federal agencies to discover every 7 days, which is a useful reference for what a reconciliation cadence looks like when it is taken seriously.
Do I need an ITAM tool to follow these practices?
You need a register that keeps history and can be reconciled. A spreadsheet can start it; the practices that break spreadsheets are history, multiple editors and the release of seats on a leaver, which is where a product earns its place.
Are software asset management best practices different?
They are the licence half of the same practices: seats counted against people, releases on leavers, and a record that survives a vendor's audit. This site has a separate page on them.
Sources
- CIS Critical Security Controls v8, Control 1, Inventory and Control of Enterprise Assets
- CISA Binding Operational Directive 23-01: automated asset discovery every 7 days across the whole address space
- NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization: what disposal of a device with storage has to record