Every quarter the security team signs off on an inventory that stopped matching the network on day one. The spreadsheet says ten devices in the boardroom. The wire shows fourteen. This piece covers why that gap opens, why it stays open, and what the audit finds when nobody else goes looking.
The register starts wrong.
Asset registers are built from purchase orders, deployment tickets and the procurement system. Every device on the spreadsheet was bought, received and assigned. That describes what was ordered well enough. What is connected is a different list.
Devices arrive without tickets. Contractors plug in equipment they brought with them. A vendor ships a replacement part under warranty and nobody logs it. Picture a codec swapped under an RMA, a temporary hotspot during construction, or the cheap unmanaged switch the AV crew tucked behind the rack for more ports. Procurement never sees any of those. The network sees every one.
It drifts further every quarter.
Most enterprise asset registers are reviewed quarterly. The network changes every day. Even in a frozen environment devices fail, get replaced, get moved and get repurposed, and each of those is a small drift. They add up.
By the time the next audit cycle starts, the spreadsheet that was right on day one is fiction. The team running it knows. The auditor figures it out fast.
Unmanaged switches multiply the problem.
This is where the register goes from incomplete to misleading. A registered network drop hosts one registered device, and the team marks that drop as done. Then someone plugs a 5-port unmanaged switch into the drop, and four more devices appear on the port behind it.
The register lists none of the four. NAC sees one endpoint where there are five. The wire knows. In one CybrIQ deployment a single Catalyst 2960 port resolved to 65 distinct devices behind it, and the asset spreadsheet listed one.
Vendor-managed devices fall between owners.
Modern conference rooms ship with codecs, signage players, smart cameras and wireless presenters that the vendor manages by design. The integrator owns the install. The vendor owns the firmware and its lifecycle, and the customer owns the network the device sits on.
Nobody owns the question of whether the device connected today is the one installed last quarter. The integrator's records cover the install and the vendor's cover the device. The customer has a floor plan. The switch fabric is in nobody's records.
What an auditor wants to see.
The auditor wants evidence that the network you describe is the network you have. A list of devices is a start. A list you can show is current is what satisfies the control.
HIPAA Security Rule §164.310, PCI 4.0 Requirement 12.5.1, SOC 2 Trust Services Criterion CC6.1, NIST CSF function ID.AM and CMMC Level 2 control AC.L2-3.4.1 all ask the same underlying question. Each phrases it differently and accepts evidence in its own shape. All five reject "the spreadsheet says so."
Change the data structure.
The spreadsheet keeps drifting even when the security team and the asset team both do their jobs well, because a spreadsheet is the wrong data structure for this question. People update it on a schedule. The network changes on its own, between updates, faster than anybody can type.
So treat the wire as the source of truth and let the register follow it. CybrIQ runs Device DNA™ continuously. It derives each device's signature from its observable Layer 1 behavior and keeps the inventory current as the network changes. Nobody reconstructs the register before the audit, because it is rebuilt every time a port is validated.
The register was always going to drift. What you get to choose is who closes the gap: your own tooling, every day, or the auditor, in a finding.
Further reading
- "Looks good" is not Layer 1 evidence. What an environmental dashboard tells you, what it leaves out, and why audits ask for the wire.
- Five reports, one truth. Mapping a single Layer 1 record to HIPAA, PCI, SOC 2, NIST CSF and CMMC without rebuilding it five times.
Get the inventory from the wire.
A 30-minute working session against one of your rooms or one floor of one building. You leave the meeting with a Device DNA™ inventory drawn from the wire and dated to the second, ready for the next audit.
