What is IT asset management?
IT asset management (ITAM) is the practice of recording every hardware and software asset an organisation owns — who uses it, what it depends on, what it cost and when it expires — across its whole lifecycle. In Ontech ICTM the asset register doubles as a configuration management database (CMDB), linking assets to users, licences, dependencies and the security and compliance modules.
Without a reliable register, simple questions become projects: how many laptops are unassigned, which servers are out of warranty, which software is unapproved, what breaks if this switch fails. Asset data kept in spreadsheets drifts out of date quickly because nothing else depends on it.
ICTM makes the register the foundation of the platform. Monitoring, vulnerability scans, business impact analysis, change requests and the data-protection ICT inventory all reference the same asset records, so keeping the register accurate pays off across every team rather than being an administrative chore.
The register records purchase date, cost and warranty expiry, tracks assignment to people with a full history, and holds the dependencies between assets that turn a list of equipment into a CMDB you can use for impact analysis.
What ICTM does for it asset management
Asset register and CMDB
Record hardware and software assets with purchase date, cost and warranty expiry, assign them to people with a full assignment history, update records in bulk and export the register to PDF or CSV.
Dependencies and impact analysis
Link assets to the assets and services they depend on. Impact analysis walks those dependencies to show which services are affected if a component fails or is taken down for change.
Software licence tracking
Track licence seats, utilisation, expiry risk and compliance status for each product. Seat usage is recorded by your team, giving one place to review renewals and over- or under-licensing.
Software catalogue and audit
Maintain a catalogue of software with approval status, link entries to licences, keep a register of known vulnerabilities in that software and see the change history of each entry.
Agentless device compliance checks
Check devices over SSH for firewall status, disk encryption, operating-system updates, password policy and antivirus. Results depend on the credentials supplied and on which checks the device's operating system supports.
Remote operations on assets
From an asset record, check a service's status, collect metrics or take a file or PostgreSQL/MySQL backup over SSH, without switching to another tool.
Subnet scans in IP address management
Run an nmap ping sweep of a subnet to record the hosts that respond, with MAC address and hostname — a practical way to spot devices that are on the network but missing from the register.
Joiner and leaver workflows
Onboarding and offboarding workflows built from task templates, with approvals, so equipment issue and return, account requests and access removal are tracked as checklist tasks for each person.
ICT inventory for data-protection work
Generate an ICT asset inventory from the register and export it as CSV for a Zambia Data Protection Act self-assessment, instead of rebuilding the list by hand each time.
ICTM modules: Assets & CMDB · CMDB Dependencies · Impact Analysis · Licenses · Software Audit · Software Catalog · Devices · Device Policies · Device Groups · Employee Lifecycle · IP Subnets
Use cases
Replacing spreadsheet registers
Move scattered asset lists into one register with owners, locations, costs and warranty dates that other teams actually use.
Evidence for an ISO 27001 audit
Show an inventory of information assets with owners and history — the kind of evidence auditors ask for under ISO/IEC 27001:2022.
Staff joining and leaving
Issue and recover laptops and phones through tracked onboarding and offboarding checklists, with approvals and a record of who holds what.
Licence renewal reviews
Review seats, utilisation and expiry risk before a renewal so you neither overpay nor fall short of your licence terms.
Planning a change safely
Before patching or replacing a server, use impact analysis to see which services depend on it and who should be told.
Benefits
One source of truth
Monitoring, security, compliance and continuity teams all work from the same asset records instead of maintaining their own lists.
Clear accountability
Assignment history shows who held each asset and when, which matters for security investigations and recovering equipment.
Better change decisions
Dependencies make the knock-on effects of a change or failure visible before they reach users.
Audit-ready records
Exportable registers and change history give auditors and data-protection reviewers what they ask for without a separate exercise.
Fewer licence surprises
Seats, utilisation and expiry in one view make renewals a planned decision rather than a last-minute scramble.
Frequently asked questions
What is a CMDB and how is it different from an asset register?
An asset register lists what you own. A configuration management database (CMDB) adds the relationships between those items — which application runs on which server, which server depends on which storage or network device. In ICTM the two are the same records: you capture assets once and add dependencies, which then power impact analysis and business continuity planning.
How do assets get into ICTM?
Assets are added individually or updated in bulk, and records can be exported to CSV or PDF. To find devices you may have missed, an nmap ping sweep in IP address management records the hosts on a subnet with their MAC address and hostname, and Docker containers on a server can be found over SSH and imported.
Can ICTM track software licences?
Yes. ICTM tracks seats, utilisation, expiry risk and compliance status for each licence, and links licences to entries in the software catalogue. Seat usage figures are recorded by your team rather than measured automatically, so the licence view is as accurate as the counts you maintain.
How does ICTM check whether devices meet policy?
ICTM connects to devices over SSH, without installing an agent, and checks firewall status, disk encryption, operating-system updates, password policy and antivirus. If credentials are missing a check is reported as unknown rather than passed, and some checks are not available on every operating system.
How does IT asset management support data protection?
You cannot protect personal data if you do not know which systems hold it. ICTM builds an ICT asset inventory from the register for a Zambia Data Protection Act self-assessment, and the same assets are referenced by records of processing, impact assessments and breach investigations in the data-protection registers.
What information should an IT asset register hold?
At minimum: a unique identifier, type, owner or assigned user, location, purchase date and cost, warranty or support expiry, and status. For a useful CMDB also record what each asset depends on and which business services rely on it, so the register can answer impact and continuity questions, not just count equipment.