What Gets Captured
Each asset record captures name, type, location, operating system, IP address or identifier, whether the asset stores or processes CUI, and its in-scope or out-of-scope status for the assessment boundary. Serial numbers and purchase dates are available as optional fields. Assets are categorized by type (workstations, servers, network devices, storage systems, printers, and portable media) so the inventory gives a complete picture of the hardware environment.
The in-scope or out-of-scope designation is the most consequential field in the record. Assessors verify that in-scope assets are covered by your security controls and that out-of-scope assets are genuinely isolated from the CUI environment. An asset marked out of scope that shares a network segment with in-scope systems is a boundary finding, and it surfaces during the assessment regardless of what the inventory says.