A single source of truth for assets reduces inventory ambiguity, but it does not decide whether access is still appropriate. Access risk remains when entitlement data, approval history, and offboarding controls sit outside the asset record. The result is better visibility with the same latent privilege creep.
Why a single asset inventory does not resolve access risk
A single source of truth for assets reduces inventory ambiguity, but it does not decide whether access is still appropriate. Access risk remains when entitlement data, approval history, and offboarding controls sit outside the asset record. The result is better visibility with the same latent privilege creep.
Asset truth answers “what exists” and “who owns it,” but access risk asks “who can still use it, under what authority, and for how long.” Those are different control questions. If the inventory is accurate but the entitlement layer is stale, you can still have dormant accounts, excessive roles, shared credentials, and access paths that were never removed after a project, vendor, or employee change.
The practical failure is a data-model mismatch. Asset management tends to describe devices, applications, services, and owners, while access governance tracks permissions, groups, roles, tokens, and exceptions. When those records are not linked, the inventory can look clean even though the authorization state is not.
What access risk still lives outside the asset record
Access risk usually sits in the lifecycle data around the asset, not in the asset label itself. An application can be catalogued correctly while its identity data remains incomplete, which means you still cannot tell whether each privilege is current, justified, or expired.
That gap matters because risk accumulates through entitlements, not just through asset existence. Approval history, periodic recertification, temporary exceptions, and offboarding events determine whether access is still valid. If those signals are held in separate systems or spreadsheets, the single inventory becomes a reference point, not a control decision.
For non-human and machine access, the same problem shows up as service accounts, API keys, tokens, and automation credentials that outlive the asset they support. A system can be retired, migrated, or renamed while the credential that used to reach it still works somewhere else. Inventory accuracy does not revoke that access by itself.
How to close the gap between asset truth and access truth
The fix is to treat asset inventory as one input to access governance, not the governance layer itself. The inventory should be linked to ownership, entitlement sources, approval evidence, last-used signals, and revocation status so that access can be reviewed against current business need rather than assumed from the asset record alone.
That is why a breach pattern like Change Healthcare breach 2024 is a useful reminder: a known asset or portal is not the same thing as controlled access. The exposed problem was not inventory uncertainty, it was that access remained available through a weak authentication path.
Practitioners should also distinguish visibility from enforcement. If the inventory says the asset exists but the approval model does not say who may use it today, you still need a separate control for authentication, authorization, revocation, and exception handling. Without that linkage, “single source of truth” can become a reporting improvement rather than a risk reduction control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Accounts and entitlement lifecycle drive residual access risk beyond the asset inventory. |
| AC-6 — Least Privilege | Privilege creep remains when permissions are not minimised and revalidated against current need. | |
| IA-5 — Authenticator Management | Stale secrets and tokens can outlive accurate asset records and preserve unauthorized access. | |
| Recommendation — Tie asset records to account lifecycle events and disable access promptly when it is no longer justified. Review and reduce permissions so access matches current business necessity and role scope. Track and rotate authenticators so expired or unused credentials cannot continue granting access. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access governance must sit alongside inventory to prevent lingering permissions and exceptions. |
| Recommendation — Centralize access reviews, revocation, and exception handling for all asset-backed access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control remains a separate obligation from asset inventory accuracy. |
| Recommendation — Define and enforce access rules independently of inventory correctness. | ||
Practitioner Guidance
What to verify: Confirm that every high-value asset record can be traced to current entitlement ownership, approval authority, and removal criteria. If you cannot answer who approved access, when it was last reviewed, and how it is revoked, the inventory is incomplete from a security perspective even if the asset list is accurate.
What good looks like: The asset record, entitlement source, and offboarding workflow are connected enough that a review can show active access, justification, expiry, and last change in one place. That is the threshold for treating inventory as a control input rather than a static catalogue.
Common mistake: Teams often stop after de-duplicating assets and assume they have reduced access risk. In practice, privilege creep usually persists because old approvals, inherited roles, and unused but valid credentials live in adjacent systems that the asset inventory does not govern.
Practitioner takeaway: A single source of truth can tell you what you own, but access risk is only reduced when it also tells you who can still act on it and whether that authority is still justified.