LICENSEWARE

IT asset management

This article is about IT asset management as an umbrella discipline. For the software-specific practice, see Software asset management. For the standard family, see ISO/IEC 19770.

On This Page

IT asset management (ITAM) is the discipline of managing, controlling and protecting the information technology assets of an organization throughout their life cycle. The ISO/IEC JTC 1/SC 7 committee, which maintains the international standards for the field, defines ITAM as all of the infrastructure and processes necessary for the effective management, control and protection of IT assets within an organization throughout all stages of the life cycle.[1] The assets concerned include physical hardware, installed and subscribed software, virtual and cloud resources, and the contracts and entitlements attached to them.

ITAM is usually presented as an umbrella over narrower practices, of which software asset management (SAM) is the most developed. The current requirements standard, ISO/IEC 19770-1:2017, specifies an “IT asset management system” that can be applied to all types of IT assets by all types and sizes of organization.[2] The SC 7 committee gives three reasons for the discipline: it is an enabling competency for other IT functions such as security and configuration management, it mitigates software compliance risk, and it saves cost by avoiding unused software and allowing licenses to be reharvested.[3]

History

The international standardization of the field began with software. The first two editions of ISO/IEC 19770-1 (2006 and 2012) were titled “Software asset management”; the 2012 edition defined an integrated, tiered set of SAM processes that applied to software and “related assets”, meaning other assets whose characteristics are needed to use or manage software.[8] With the third edition in December 2017 the family was retitled “IT asset management” and Part 1 became a management system standard for all IT assets, written as a discipline-specific extension of ISO 55001:2014, the general standard for asset management systems.[2] Later parts extended the data standards beyond software, notably a hardware identification tag published in 2024.[9] The development of the standard family is described in ISO/IEC 19770.

Public-sector policy followed a similar path. United States federal guidance in 2016 required agencies to automate both hardware and software asset discovery and inventory tracking as part of software license management, linking the two sides of the discipline.[12] A NIST practice guide published in 2018 approached ITAM from the security side, as a means of knowing the location and function of every device and application in a large enterprise.[4]

Scope and definitions

What counts as an IT asset

NIST glossaries define an asset in general terms as an item of value to stakeholders, which may be tangible (hardware, firmware, network devices) or intangible (software, data, services, intellectual property).[5] The NIST ITAM practice guide describes ITAM as the policies and procedures an organization uses to track, audit and monitor the state of its IT assets and maintain system configurations, and lists computing devices, IT systems and networks, software (both installed and physical instances), virtual computing platforms and related hardware among those assets.[4]

ISO/IEC 19770-1:2017 notes that it is intended mainly for IT assets but can be applied to other asset types. It is not intended for managing information as an asset in its own right, although data about the IT assets in scope is covered and, depending on the scope chosen, digital information content can be. It does not specify financial, accounting or technical requirements for particular asset types.[2]

Sub-disciplines

Sub-discipline Main concern Typical records 
Software asset management (SAM) Software deployment and use reconciled against license and subscription entitlements Software inventory, entitlements, effective license position 
Hardware asset management (HAM) Physical and virtual devices from acquisition to disposal Hardware inventory, location, ownership, warranty, disposal 
Cloud and SaaS asset management Subscribed services and consumption-based resources Subscriptions, user assignments, consumption reports 

The boundary between these areas is not fixed. Software license positions often depend on hardware facts, such as the number of processor cores in a server or the device a license is tied to, so SAM draws on HAM data (see software licensing models).

Practice

Life cycle

ISO/IEC TS 19770-10:2025, a technical specification giving implementation guidance, groups ITAM work into three layers. Management system processes cover context and stakeholder needs, leadership and policy, planning and risk, support, and performance evaluation. Functional management processes are cross-cutting: change management, data management, license management, security management, relationship and contract management, financial management, service level management and other risk management. Life cycle processes, as specified in ISO/IEC 19770-1, cover specification, development, acquisition, release, deployment, operation and retirement of IT assets.[7]

The NIST Cybersecurity Framework 2.0 expresses comparable outcomes in its Asset Management category: maintained inventories of hardware, of software, services and systems, of supplier services and of data; prioritization of assets by criticality; and management of systems, hardware, software, services and data throughout their life cycles.[11]

Implementation tiers

The SC 7 committee describes the 2017 edition of ISO/IEC 19770-1 as specifying 15 ITAM process areas and suggesting implementation in three tiers: Trustworthy Data, Life Cycle Integration and Optimization. As a management system standard it follows the Plan-Do-Check-Act cycle.[1] The first tier corresponds to the basic inventory and entitlement records on which everything else depends; the later tiers integrate asset management into procurement, deployment and retirement, and then use the data for cost and risk optimization.

Identification and data exchange

Much of ITAM depends on reliably identifying what is installed or connected. The standard family defines tag formats for this purpose: software identification (SWID) tags in ISO/IEC 19770-2, produced by platform and software providers and consumed by discovery tools, and hardware identification (HWID) tags in ISO/IEC 19770-6, which apply the same approach to devices and components.[10][9] The committee groups these, with the entitlement and resource utilization schemas, as “ITAM information structure” standards intended to let stakeholders exchange asset data.[3]

Certification

An organization’s ITAM system can be audited and certified against ISO/IEC 19770-1. ISO/IEC 19770-11:2021 sets requirements for the certification bodies that perform this work, in addition to the general requirements of ISO/IEC 17021-1.[19]

Standards and frameworks

The ISO/IEC 19770 family, developed by Working Group 21 of ISO/IEC JTC 1/SC 7, is the main body of international standards.[3] Part 5 provides the overview and vocabulary for the family and an introduction to ITAM and SAM; the committee described it in 2019 as the only freely available ITAM standard.[6][3] Part 8 defines how to map industry practice frameworks to and from ISO/IEC 19770-1.[22]

Part 1 is designed so that an organization can align and integrate its ITAM system with other management system standards, for example ISO/IEC 27001 for information security and ISO/IEC 20000-1 for service management.[1]

Relationship to other disciplines

Software asset management

SAM is the software-focused part of ITAM. Since 2017 the international standard has treated SAM as one application of a general ITAM system rather than as a separate management system.[2] What distinguishes the software side is that the right to use each asset is defined by license terms, which publishers’ agreements commonly allow them to verify; see software asset management and software license.

Configuration management and the CMDB

Configuration management is defined in NIST glossaries as a collection of activities for establishing and maintaining the integrity of products and systems by controlling how their configurations are initialized, changed and monitored.[14] Its unit is the configuration item, an item or aggregation of hardware, software or both that is treated as a single entity in the configuration management process.[13] Service management organizations commonly hold configuration items and their relationships in a configuration management database (CMDB). ITAM and configuration management overlap in the objects they record but differ in purpose: configuration management tracks how items are built and related in order to support services and changes, while ITAM tracks ownership, cost, contracts and entitlements across the life cycle, including assets that are in stock, retired or not yet deployed. The SC 7 committee describes ITAM as an enabler of configuration management.[3]

IT service management

IT service management (ITSM) is concerned with delivering IT services to agreed requirements. ISO/IEC 20000-1:2018 specifies requirements for a service management system covering the planning, design, transition, delivery and improvement of services.[15] UK government guidance for the Public Services Network advises that service delivery organizations use an ITSM framework such as ITIL.[16] ITAM supplies ITSM with asset data, and ITSM request and change processes are the points at which many assets are acquired, moved or retired.

FinOps

FinOps is defined by the FinOps Foundation as an operational framework and cultural practice that maximizes the business value of technology and creates financial accountability through collaboration between engineering, finance and business teams. Its scope, originally public cloud spending, now extends to SaaS, licensing, data centers and other technology categories.[17] The Foundation treats ITAM teams as an “allied persona” that collaborates with FinOps, finance and procurement on efficiency, transparency and value in managing IT assets and on compliance with asset contracts.[18] The two disciplines overlap most on cloud resources and SaaS subscriptions; ITAM brings entitlement and compliance knowledge, FinOps brings consumption and cost allocation data.

Information security

Security frameworks treat asset inventory as a precondition for protecting systems. The NIST practice guide on ITAM was written for financial services firms that could not otherwise answer questions such as which operating systems their laptops were running or which devices were exposed to a newly announced threat.[4]

Criticism and challenges

Public audit reports show that inventories remain the weak point. A 2014 GAO review of 24 United States federal agencies found that none fully implemented the practice of tracking and maintaining a license inventory, and that GAO could not accurately describe the most widely used software applications for that reason.[20] Cloud adoption adds contractual constraints: GAO reported in 2024 that restrictive licensing practices, such as higher charges for running software on a competitor’s cloud, had affected five of six agencies it examined.[21]

The scope of the discipline is also a practical difficulty. ISO/IEC 19770-1:2017 can be applied to any IT asset type but deliberately leaves financial, accounting and technical requirements for specific asset types to other standards, so organizations must decide for themselves where ITAM ends and adjacent functions begin.[2]

Out of scope

This article covers ITAM as a discipline. The LICENSEWARE Wiki is limited to software licensing, so hardware asset management, hardware catalogs, vulnerability feeds and sustainability data are described here only for context; see House rules. License rules for specific products are in the vendor articles, and the counting of license metrics is summarized in software licensing models.

References

  1. ISO/IEC 19770-1:2017 (JTC 1/SC 7 flagship standards page)ISO/IEC JTC 1/SC 7 committee site.Retrieved 2026-09-26.
  2. ISO/IEC 19770-1:2017 Information technology: IT asset management, Part 1: IT asset management systems, RequirementsISO catalogue page. Edition 3, 2017-12; confirmed 2024; Amd 1:2024.Effective 2017-12-01. Retrieved 2026-09-26.
  3. IT Asset Management Standards (ISO/IEC 19770) Business Case & OverviewISO/IEC JTC 1/SC 7 news item, 2019-04-24.Effective 2019-04-24. Retrieved 2026-09-26.
  4. NIST SP 1800-5: IT Asset ManagementNIST National Cybersecurity Center of Excellence practice guide, September 2018.Effective 2018-09-01. Retrieved 2026-09-26.
  5. Asset (NIST CSRC Glossary)Definitions from NIST SP 800-160 and CNSSI 4009-2022.Retrieved 2026-09-26.
  6. ISO/IEC 19770-5:2015 Information technology: IT asset management, Part 5: Overview and vocabularyISO catalogue page. Edition 2, 2015-08.Effective 2015-08-01. Retrieved 2026-09-26.
  7. ISO/IEC TS 19770-10:2025 Information technology: IT asset management, Part 10: Guidance for implementing ITAMISO catalogue page. Technical Specification, Edition 1, 2025-06.Effective 2025-06-01. Retrieved 2026-09-26.
  8. ISO/IEC 19770-1:2012 Information technology: Software asset management, Part 1: Processes and tiered assessment of conformanceISO catalogue page. Edition 2, 2012-06; withdrawn.Effective 2012-06-01. Retrieved 2026-09-26.
  9. ISO/IEC 19770-6:2024 Information technology: IT asset management, Part 6: Hardware identification tagISO catalogue page. Edition 1, 2024-01.Effective 2024-01-01. Retrieved 2026-09-26.
  10. ISO/IEC 19770-2:2015 Information technology: IT asset management, Part 2: Software identification tagISO catalogue page. Edition 2, 2015-10.Effective 2015-10-01. Retrieved 2026-09-26.
  11. The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29)Published 2024-02-26. Asset Management category ID.AM.Effective 2024-02-26. Retrieved 2026-09-26.
  12. OMB M-16-12, Category Management Policy 16-1: Improving the Acquisition and Management of Common Information Technology: Software LicensingUS Office of Management and Budget memorandum, 2016-06-02.Effective 2016-06-02. Retrieved 2026-09-26.
  13. Configuration item (NIST CSRC Glossary)Definitions from CNSSI 4009-2022 and NIST SP 800-160.Retrieved 2026-09-26.
  14. Configuration management (NIST CSRC Glossary)Definitions from CNSSI 4009-2022 and NIST SP 800-128.Retrieved 2026-09-26.
  15. ISO/IEC 20000-1:2018 Information technology: Service management, Part 1: Service management system requirementsISO catalogue page. Edition 3, 2018-09.Effective 2018-09-01. Retrieved 2026-09-26.
  16. Service management good practice (Public Services Network)UK Cabinet Office guidance, published 2015-01-07.Effective 2015-01-07. Retrieved 2026-09-26.
  17. What is FinOps?FinOps Foundation definition, updated March 2026.Retrieved 2026-09-26.
  18. FinOps PersonasFinOps Foundation framework page; ITAM allied persona.Retrieved 2026-09-26.
  19. ISO/IEC 19770-11:2021 Information technology: IT asset management, Part 11: Requirements for bodies providing audit and certification of IT asset management systemsISO catalogue page. Edition 1, 2021-06.Effective 2021-06-01. Retrieved 2026-09-26.
  20. Federal Software Licenses: Better Management Needed to Achieve Significant Savings Government-Wide (GAO-14-413)US Government Accountability Office; published 2014-05-22.Effective 2014-05-22. Retrieved 2026-09-26.
  21. Cloud Computing: Selected Agencies Need to Implement Updated Guidance for Managing Restrictive Licenses (GAO-25-107114)US GAO; published 2024-11-13.Effective 2024-11-13. Retrieved 2026-09-26.
  22. ISO/IEC 19770-8:2020 Information technology: IT asset management, Part 8: Guidelines for mapping of industry practices to/from the ISO/IEC 19770 family of standardsISO catalogue page. Edition 1, 2020-01.Effective 2020-01-01. Retrieved 2026-09-26.

See also

Esc