Bringing Assets and Identity Under Control

Bringing Assets and Identity Under Control

During the implementation of modern SIEM platforms, we find that a large number of our clients do not have a trustworthy Configuration Management Database (CMDB). Of the ones that do, few trust it enough to act on it during an incident. Yet every meaningful security decision — how urgent is this alert, who owns this box, does this account belong to a real person, is this asset even supposed to be here — depends on knowing what you have and who is responsible for it.

Whilst the underlying issue for a CISO is that "you can not protect what you dont know" about will need to be addressed, organisations need a tactical approach to get their SIEM platforms working for them.

Practical Approach

The approach is to build and sustain "Assets and Identity" data good enough to implement a security operations service on an estate that has no CMDB, no agreed source of truth, multiple overlapping (or incomplete) directory services and an unknown volume of unmanaged and shadow infrastructure.

With it built, it can then expand with the maturity of the organisation to be service orientated along with the security operations service.

Secure by Design Principles

The Security Operations Centre (SOC) must never become the de facto owner or custodian of asset and identity truth. It is a consumer, not a system of record.

The SOC must never rely on non-machine-readable artefacts — spreadsheets, Word documents, wiki pages — as its working copy of this data. Everything the SOC consumes must be structured, versioned, and machine-readable.

The delivery must work in multiple phases: a first-time population exercise that gets the estate to a usable baseline, followed by a business-owned, continuously maintained state that the SOC simply draws from.

The other AI: Assets and Identity. Using Splunk to keep in check

We're proud to be attending Splunk .Conf 26 in Denver, where on Wednesday 16th September we are presenting 'SEC1053: The Other AI - Assets and Identity'.

This is a theatre presentation where we provide a common sense approach to bring Assets and Identity under control with your organisation. Compliance doesn’t have to be a checkbox chase. Splunk can transform governance into a living, automated process—mapping assets, identities, and risks in real time. Learn how to align with the UK Government’s Cyber Assessment Framework & the NIST Cyber Security Framework while leveraging AI‑driven, agentic workflows to detect anomalies, trigger automated responses, and sustain a continuously monitored, audit‑ready environment powered by Splunk Enterprise and Splunk Enterprise Security.

  • Learn how to use Splunk for continuous asset discovery and risk tracking across secure infrastructures.
  • How Splunks automated governance workflows simplify meeting regulatory mandates such as the Cyber Assessment Framework / NIST Cyber Security Framework
  • Understand how to turn compliance reports into proactive, automated security actions inside Splunk.