Skip to content
arrow_back
ISM-0336policyASD Information Security Manual (ISM)

Develop and Maintain Networked IT Equipment Register

Keep a regularly checked list of IT equipment connected to the network.

record_voice_over

Plain language

It's important to keep a list of all computers and devices that are plugged into your network. This is crucial because if you don't know what's connected, you can't protect it. Hackers could exploit unsecured devices to access private information or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

A networked IT equipment register is developed, implemented, maintained and regularly verified.
policyASD Information Security Manual (ISM)ISM-0336
priority_high

Why it matters

Without a current register, unidentified devices can provide entry points for cyberattacks, risking data breaches and operational disruptions.

settings

Operational notes

Regular updates and audits of the IT equipment register ensure new devices are swiftly secured and potential risks are minimised.

build

Implementation tips

  • The IT manager should start by listing all the devices, like computers, printers, and mobile phones, that are connected to the network. Use a simple spreadsheet or digital tool to create this inventory.
  • The office administrator should regularly update this list every month to reflect new or removed devices. Keep track of equipment purchases and disposals to ensure accuracy.
  • The IT team must label and document network details, such as IP addresses and device types, for each item in the register. This helps quickly identify and secure any potential vulnerabilities.
  • The IT manager should set up routine checks, such as quarterly audits, to verify that the equipment list is up to date and matches the actual devices connected to the network.
  • The business owner should review this list during regular team meetings to ensure everyone understands its importance for the security and smooth running of the business.
fact_check

Audit / evidence tips

  • Askthe current networked IT equipment register documentLook atcompleteness with information on device type, location, and details like IP addressesGoodregister will be current and contain no discrepancies
  • Request evidence of monthly updates to the equipment register. Check for documented changes, including new and removed equipment, to verify the register is actively maintained.
  • Askrecords of quarterly checks or audits of the equipment register. Look to ensure these audits are logged and any identified discrepancies were corrected promptly
  • Request the procedure document detailing how new devices are added to the register. It should show a clear, followed process for recording device details within a quick timeframe from when devices join the network.
  • Askmeeting minutes where the register is reviewed and discussedLook atmentions of discussing the register's accuracy and planned improvementsGoodincludes action points and review decisions
link

Cross-framework mappings

How ISM-0336 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 5.9Annex A 5.9 requires developing and maintaining an inventory of information and associated assets, including ownership

E8

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
E8-PA-ML1.1E8-PA-ML1.1 requires an automated method of asset discovery at least fortnightly to identify assets for subsequent vulnerability scanning
handshakeSupports(1)expand_less
E8-PO-ML1.1ISM-0336 requires organisations to keep an accurate, verified register of network-connected IT equipment
extensionDepends on(1)expand_less
E8-PO-ML1.8E8-PO-ML1.8 requires organisations to replace operating systems that are no longer supported by vendors

ISO 42001

ControlNotesDetails
handshakeSupports(1)expand_less
Annex A 4.5Annex A 4.5 requires the organisation to document the system and computing resources utilised for each AI system

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for information technology equipment controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls