IT asset management (ITAM) is the discipline of managing, controlling and protecting the information technology assets of an organization throughout their life cycle. The ISO/IEC JTC 1/SC 7 committee, which maintains the international standards for the field, defines ITAM as all of the infrastructure and processes necessary for the effective management, control and protection of IT assets within an organization throughout all stages of the life cycle.[1] The assets concerned include physical hardware, installed and subscribed software, virtual and cloud resources, and the contracts and entitlements attached to them.
ITAM is usually presented as an umbrella over narrower practices, of which software asset management (SAM) is the most developed. The current requirements standard, ISO/IEC 19770-1:2017, specifies an “IT asset management system” that can be applied to all types of IT assets by all types and sizes of organization.[2] The SC 7 committee gives three reasons for the discipline: it is an enabling competency for other IT functions such as security and configuration management, it mitigates software compliance risk, and it saves cost by avoiding unused software and allowing licenses to be reharvested.[3]
History
The international standardization of the field began with software. The first two editions of ISO/IEC 19770-1 (2006 and 2012) were titled “Software asset management”; the 2012 edition defined an integrated, tiered set of SAM processes that applied to software and “related assets”, meaning other assets whose characteristics are needed to use or manage software.[8] With the third edition in December 2017 the family was retitled “IT asset management” and Part 1 became a management system standard for all IT assets, written as a discipline-specific extension of ISO 55001:2014, the general standard for asset management systems.[2] Later parts extended the data standards beyond software, notably a hardware identification tag published in 2024.[9] The development of the standard family is described in ISO/IEC 19770.
Public-sector policy followed a similar path. United States federal guidance in 2016 required agencies to automate both hardware and software asset discovery and inventory tracking as part of software license management, linking the two sides of the discipline.[12] A NIST practice guide published in 2018 approached ITAM from the security side, as a means of knowing the location and function of every device and application in a large enterprise.[4]
Scope and definitions
What counts as an IT asset
NIST glossaries define an asset in general terms as an item of value to stakeholders, which may be tangible (hardware, firmware, network devices) or intangible (software, data, services, intellectual property).[5] The NIST ITAM practice guide describes ITAM as the policies and procedures an organization uses to track, audit and monitor the state of its IT assets and maintain system configurations, and lists computing devices, IT systems and networks, software (both installed and physical instances), virtual computing platforms and related hardware among those assets.[4]
ISO/IEC 19770-1:2017 notes that it is intended mainly for IT assets but can be applied to other asset types. It is not intended for managing information as an asset in its own right, although data about the IT assets in scope is covered and, depending on the scope chosen, digital information content can be. It does not specify financial, accounting or technical requirements for particular asset types.[2]
Sub-disciplines
| Sub-discipline | Main concern | Typical records |
|---|---|---|
| Software asset management (SAM) | Software deployment and use reconciled against license and subscription entitlements | Software inventory, entitlements, effective license position |
| Hardware asset management (HAM) | Physical and virtual devices from acquisition to disposal | Hardware inventory, location, ownership, warranty, disposal |
| Cloud and SaaS asset management | Subscribed services and consumption-based resources | Subscriptions, user assignments, consumption reports |
The boundary between these areas is not fixed. Software license positions often depend on hardware facts, such as the number of processor cores in a server or the device a license is tied to, so SAM draws on HAM data (see software licensing models).
Practice
Life cycle
ISO/IEC TS 19770-10:2025, a technical specification giving implementation guidance, groups ITAM work into three layers. Management system processes cover context and stakeholder needs, leadership and policy, planning and risk, support, and performance evaluation. Functional management processes are cross-cutting: change management, data management, license management, security management, relationship and contract management, financial management, service level management and other risk management. Life cycle processes, as specified in ISO/IEC 19770-1, cover specification, development, acquisition, release, deployment, operation and retirement of IT assets.[7]
The NIST Cybersecurity Framework 2.0 expresses comparable outcomes in its Asset Management category: maintained inventories of hardware, of software, services and systems, of supplier services and of data; prioritization of assets by criticality; and management of systems, hardware, software, services and data throughout their life cycles.[11]
Implementation tiers
The SC 7 committee describes the 2017 edition of ISO/IEC 19770-1 as specifying 15 ITAM process areas and suggesting implementation in three tiers: Trustworthy Data, Life Cycle Integration and Optimization. As a management system standard it follows the Plan-Do-Check-Act cycle.[1] The first tier corresponds to the basic inventory and entitlement records on which everything else depends; the later tiers integrate asset management into procurement, deployment and retirement, and then use the data for cost and risk optimization.
Identification and data exchange
Much of ITAM depends on reliably identifying what is installed or connected. The standard family defines tag formats for this purpose: software identification (SWID) tags in ISO/IEC 19770-2, produced by platform and software providers and consumed by discovery tools, and hardware identification (HWID) tags in ISO/IEC 19770-6, which apply the same approach to devices and components.[10][9] The committee groups these, with the entitlement and resource utilization schemas, as “ITAM information structure” standards intended to let stakeholders exchange asset data.[3]
Certification
An organization’s ITAM system can be audited and certified against ISO/IEC 19770-1. ISO/IEC 19770-11:2021 sets requirements for the certification bodies that perform this work, in addition to the general requirements of ISO/IEC 17021-1.[19]
Standards and frameworks
The ISO/IEC 19770 family, developed by Working Group 21 of ISO/IEC JTC 1/SC 7, is the main body of international standards.[3] Part 5 provides the overview and vocabulary for the family and an introduction to ITAM and SAM; the committee described it in 2019 as the only freely available ITAM standard.[6][3] Part 8 defines how to map industry practice frameworks to and from ISO/IEC 19770-1.[22]
Part 1 is designed so that an organization can align and integrate its ITAM system with other management system standards, for example ISO/IEC 27001 for information security and ISO/IEC 20000-1 for service management.[1]
Relationship to other disciplines
Software asset management
SAM is the software-focused part of ITAM. Since 2017 the international standard has treated SAM as one application of a general ITAM system rather than as a separate management system.[2] What distinguishes the software side is that the right to use each asset is defined by license terms, which publishers’ agreements commonly allow them to verify; see software asset management and software license.
Configuration management and the CMDB
Configuration management is defined in NIST glossaries as a collection of activities for establishing and maintaining the integrity of products and systems by controlling how their configurations are initialized, changed and monitored.[14] Its unit is the configuration item, an item or aggregation of hardware, software or both that is treated as a single entity in the configuration management process.[13] Service management organizations commonly hold configuration items and their relationships in a configuration management database (CMDB). ITAM and configuration management overlap in the objects they record but differ in purpose: configuration management tracks how items are built and related in order to support services and changes, while ITAM tracks ownership, cost, contracts and entitlements across the life cycle, including assets that are in stock, retired or not yet deployed. The SC 7 committee describes ITAM as an enabler of configuration management.[3]
IT service management
IT service management (ITSM) is concerned with delivering IT services to agreed requirements. ISO/IEC 20000-1:2018 specifies requirements for a service management system covering the planning, design, transition, delivery and improvement of services.[15] UK government guidance for the Public Services Network advises that service delivery organizations use an ITSM framework such as ITIL.[16] ITAM supplies ITSM with asset data, and ITSM request and change processes are the points at which many assets are acquired, moved or retired.
FinOps
FinOps is defined by the FinOps Foundation as an operational framework and cultural practice that maximizes the business value of technology and creates financial accountability through collaboration between engineering, finance and business teams. Its scope, originally public cloud spending, now extends to SaaS, licensing, data centers and other technology categories.[17] The Foundation treats ITAM teams as an “allied persona” that collaborates with FinOps, finance and procurement on efficiency, transparency and value in managing IT assets and on compliance with asset contracts.[18] The two disciplines overlap most on cloud resources and SaaS subscriptions; ITAM brings entitlement and compliance knowledge, FinOps brings consumption and cost allocation data.
Information security
Security frameworks treat asset inventory as a precondition for protecting systems. The NIST practice guide on ITAM was written for financial services firms that could not otherwise answer questions such as which operating systems their laptops were running or which devices were exposed to a newly announced threat.[4]
Criticism and challenges
Public audit reports show that inventories remain the weak point. A 2014 GAO review of 24 United States federal agencies found that none fully implemented the practice of tracking and maintaining a license inventory, and that GAO could not accurately describe the most widely used software applications for that reason.[20] Cloud adoption adds contractual constraints: GAO reported in 2024 that restrictive licensing practices, such as higher charges for running software on a competitor’s cloud, had affected five of six agencies it examined.[21]
The scope of the discipline is also a practical difficulty. ISO/IEC 19770-1:2017 can be applied to any IT asset type but deliberately leaves financial, accounting and technical requirements for specific asset types to other standards, so organizations must decide for themselves where ITAM ends and adjacent functions begin.[2]
Out of scope
This article covers ITAM as a discipline. The LICENSEWARE Wiki is limited to software licensing, so hardware asset management, hardware catalogs, vulnerability feeds and sustainability data are described here only for context; see House rules. License rules for specific products are in the vendor articles, and the counting of license metrics is summarized in software licensing models.