Asset Management Overview
You cannot secure what you cannot see. Cert-IX Asset Management gives your organization a single, continuously updated inventory of the systems it operates — the devices on your network, the resources running in your cloud accounts, the software installed across your estate, and the network infrastructure that connects it all. Each asset carries the security context you need to act: what it is, who owns it, and which vulnerabilities affect it.
This page explains what Cert-IX tracks, how assets are discovered, and what information the platform records for each one. For hands-on setup, follow the links to the individual asset pages and the Scanner Agents guide.
Why asset inventory matters
An accurate inventory is the foundation for almost every other security activity:
- Visibility — Know which systems actually exist before you try to protect them.
- Vulnerability context — Tie scan findings to specific, owned assets so remediation lands with the right team.
- Compliance — Maintain the system-of-record that most frameworks expect you to keep.
- Incident response — Identify affected hosts quickly when something goes wrong.
Cert-IX keeps that inventory current for you by combining automated discovery with manual and programmatic entry, rather than relying on a spreadsheet that drifts out of date.
What Cert-IX tracks
Asset Management is organized into focused categories, each with its own inventory view. The categories below are the surfaces available in the platform today.
| Category | What it covers | Learn more |
|---|---|---|
| Devices | Endpoints, servers, and other hosts, primarily discovered by agents on your network. | Devices |
| Cloud resources | Infrastructure and services running in your connected cloud accounts. | Cloud Resources |
| Software inventory | Applications and packages installed across your estate. | Software Inventory |
| Network assets | Routers, switches, firewalls, and other network infrastructure. | Network Assets |
Each view supports the same core actions: browse and filter the inventory, inspect an individual asset, and see the security findings associated with it. The categories share a common data model, so an asset discovered by an agent and an asset you add by hand are treated consistently.
How assets are discovered
Cert-IX populates your inventory through three complementary paths. Most organizations use all three.
Agent-based discovery
For internal networks, you deploy lightweight scanner agents that report telemetry back to the platform. This is the primary way devices and software populate automatically — you do not have to enter them by hand.
Four agents cover different aspects of discovery and assessment:
| Agent | Role |
|---|---|
| Bitcollector | Asset telemetry — inventories hosts, running processes, open ports, installed software, and system metrics. |
| Bitscanner | Vulnerability scanning — checks hosts and services against a CVE database and reports findings. |
| Bitmapper | Network topology and service discovery — maps how systems connect and which services they expose. |
| Bitenforcer | Compliance hardening — evaluates systems against CIS, STIG, and PCI-DSS baselines. |
Agents are downloaded from downloads.cert-ix.com and registered to your organization using your Tenant ID, which you can find under Settings → Organization.
The agents run inside your environment and connect outbound to Cert-IX. You choose which hosts and network ranges they cover, so discovery scope stays under your control.
See the Scanner Agents overview, the Agent Deployment Guide, and Agent Configuration for details.
Manual entry
You can add assets directly in the dashboard — useful for systems an agent cannot reach, or for records you want to maintain deliberately. Cert-IX validates structured inputs where it matters: network-addressable assets expect a well-formed IP address, a MAC address, and a defined device type, so records stay consistent and queryable rather than filling up with free-text.
Programmatic and on-demand scanning
For external targets and automated workflows, the Scan API lets you launch scans and retrieve findings programmatically, and integrate results into your own pipelines. This complements agent-based discovery for assets that live outside your internal network.
What Cert-IX records for each asset
Every asset carries a consistent set of attributes so you can search, group, and prioritize across the inventory. Rather than a generic template, the platform focuses on fields that are actually useful for security work:
- Identity — A human-readable name or hostname and a unique identifier.
- Classification — The asset category and type.
- Network addressing — IP and MAC addresses for network-addressable assets, stored as validated, structured values.
- Ownership and criticality — The responsible owner and a business-criticality rating you assign.
- Security state — Open vulnerability findings by severity, the time of the most recent scan, and hardening results from Bitenforcer where applicable.
- Custom tags — Your own labels (for example, business unit or environment) for filtering and grouping.
Security findings are ranked by severity — Critical, High, Medium, and Low — with remediation guidance, so the highest-risk issues on your most important assets rise to the top. To work through findings across the whole estate, use Vulnerability Management.
Asset lifecycle
Assets move through a simple, honest lifecycle:
- Discovered or added — An agent reports the asset, you enter it manually, or it appears from a scan.
- Active — The asset is part of your inventory and is continuously assessed for vulnerabilities and configuration issues.
- Archived — When an asset is decommissioned, it is archived rather than permanently erased, so historical context is preserved.
Cert-IX runs on EU-hosted infrastructure, with some US sub-processors under Standard Contractual Clauses, and is GDPR-aligned. Archiving and retention of asset records are covered by our privacy notice.
Access and tenancy
Every asset belongs to a single organization (tenant), and inventories are isolated between tenants. Within your organization, role-based access control (RBAC) governs who can view assets and who can add, edit, or archive them, so read-only team members and administrators see appropriately scoped views. Available capacity depends on your plan — Free, Starter, or Pro.
Getting started
- Deploy a scanner agent. Download Bitcollector from downloads.cert-ix.com and register it with your Tenant ID (Settings → Organization). Devices and software begin to populate as it reports in.
- Review discovered assets. Open the relevant category view, confirm the assets Cert-IX found, and assign owners and criticality.
- Add anything agents can't reach. Enter remaining systems manually, using the validated fields for IP, MAC, and device type.
- Act on findings. Move to Vulnerability Management to prioritize and track remediation across your inventory.
Not sure where something lives in the platform? Bobby, the built-in AI assistant, answers questions about Cert-IX and links you to the relevant documentation.
Learn more
- Devices — endpoint and server inventory.
- Network Assets — routers, switches, and firewalls.
- Scanner Agents — how internal discovery works.
- Vulnerability Management — prioritize and remediate findings across your assets.
Questa pagina ti è stata utile?