Join our Newsletter — 33% off our NHI Course

Should asset management support only laptops and desktops?

No. Asset governance should cover the full technology footprint, including phones, tablets, printers, peripherals, and accessories. Narrow scope creates blind spots that undermine accountability and can leave unmanaged equipment outside normal lifecycle and reporting processes.

Why asset governance has to cover more than laptops and desktops

asset management is about knowing what exists, who owns it, where it is used, and how it is controlled. If the scope stops at traditional endpoints, the organisation loses visibility over devices that still store data, connect to systems, or create operational and security obligations. Phones, tablets, printers, peripherals, and accessories can all introduce accountability gaps if they are omitted from inventory, assignment, and retirement processes.

That broader scope matters because the control objective is not “track every object equally,” but “avoid unmanaged exposure.” A printer can hold queued documents, a tablet can access corporate email, and a peripheral can be a trusted attachment point. Once those assets sit outside the normal lifecycle, they are harder to assign, monitor, patch, recover, or retire cleanly.

Scope decisions should therefore be based on whether the item can affect confidentiality, integrity, availability, or accountability, not on whether it looks like a standard workstation. The practical test is simple: if the item has an owner, can be lost or stolen, can connect to the environment, or can create support, data, or decommissioning obligations, it belongs in asset governance.

Where narrow scope creates the most damage

When only laptops and desktops are tracked, the first failure is usually inventory drift. Unrecorded devices can keep working, keep consuming licenses, or keep accessing services after the organisation has lost sight of them. That creates blind spots in ownership, refresh cycles, repair tracking, and secure disposal.

The second failure is control inconsistency. If mobile devices or printers are treated as “exceptions,” teams often apply weaker enrollment, weaker update expectations, or no decommissioning workflow at all. Over time, that produces a shadow fleet of unmanaged equipment that is still part of the business environment but outside normal reporting and review.

This is also where supporting guidance from CIS Controls v8 is useful, because asset inventory and secure configuration become much harder when the inventory itself is incomplete. The same logic aligns with NIST Cybersecurity Framework 2.0, which depends on knowing what assets are in scope before you can govern, protect, detect, respond, or recover effectively.

Printers and peripherals deserve particular attention because they are often treated as facility items instead of managed technology. That is a mistake when they can store jobs, accept credentials, hold firmware, or bridge into the same network segment as higher-value systems. Inclusion in asset management does not mean identical treatment, it means explicit ownership and lifecycle handling.

What good scope looks like in practice

Good asset governance starts with a simple classification rule: include any technology item that can store information, authenticate to something, connect to the corporate environment, or require secure disposal. That usually covers endpoints, mobiles, printers, scanners, docks, headsets, removable media, and other accessories that can affect support or security outcomes.

From there, assign controls proportionate to the risk of the asset class. A phone may need enrollment and remote wipe, a printer may need inventory and firmware review, and an accessory may need traceability if it is tied to a regulated or high-risk workflow. The point is to make the control model explicit instead of letting “not a laptop” become “not managed.”

Asset governance also works best when it is tied to onboarding, transfer, repair, and retirement events. If procurement, service desk, facilities, and security each hold part of the picture, the inventory will only be reliable when those handoffs are defined and enforced. Coverage is therefore an operating model issue as much as a tooling issue.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-1 — Inventory and Control of Enterprise Assets Asset scope and inventory completeness are central to this question.
Recommendation — Include all managed technology assets in a maintained inventory and assign ownership for each class.
NIST CSF 2.0 ID.AM-01 — Physical devices and systems inventoried The question is about broad asset coverage beyond laptops and desktops.
GV.OC-03 — Mission, objectives, stakeholders, and activities are understood and prioritized Asset scope should reflect what the organisation actually operates and relies on.
Recommendation — Inventory every asset class that affects security, operations, or accountability. Define asset scope from business use and risk, not from convenience or device labels.

Practitioner Guidance

What to prioritise: Start by defining the asset classes that can create real accountability or exposure, then make sure each class has an owner, a lifecycle state, and a retirement path. The goal is not a perfect catalogue of every object; it is a complete enough inventory to prevent unmanaged technology from slipping through gaps.

What to verify: Confirm that the inventory process captures non-traditional assets at procurement, assignment, repair, and disposal, and that the records are actually used for support and recovery decisions. If a device can affect access, data handling, or decommissioning, it should not live only in an informal spreadsheet or local team record.

Common mistake: Treating “endpoint management” as a synonym for “asset management.” That shortcut usually leaves out shared equipment, peripheral devices, and accessories that still carry operational and security obligations, even if they are not the primary user device.

Practitioner takeaway: Asset scope should follow business and security impact, not device category labels. If something can be lost, connected, trusted, or retired badly, it needs governance somewhere in the lifecycle.