CycloneDX and SPDX: choosing an SBOM format
Two formats, both standards, both accepted. The choice is less about features than about what your customers and your toolchain already consume.
Assets are bought carefully, tracked loosely, and disposed of badly. The end of the lifecycle is where both the money and the data risk actually sit.
IT asset management is the practice of tracking hardware and software from acquisition through deployment, maintenance and retirement. It exists to answer three questions that organisations are surprisingly bad at: what do we have, where is it, and are we paying for things nobody uses.
Most programmes concentrate on the first half of the lifecycle, because procurement generates records naturally. What is thinly managed is everything after deployment — the laptop with a departed employee, the licence renewed annually for a team that migrated two years ago, the server decommissioned physically but never removed from the inventory, the disposal that sent drives out of the building without documented destruction.
An accurate asset inventory is a prerequisite for almost every security control: patching, endpoint protection, access review, vulnerability scanning. A device nobody knows about receives none of them, and the gap is invisible by definition. That is why asset management appears near the top of every security control framework, and it is a better argument for funding the programme than licence savings are — though the savings are usually real too.
Reconcile the inventory against something independent at least annually — a discovery scan, the directory of active devices, the supplier’s licence position. An inventory reconciled only against itself always agrees with itself.
Unused licences renew silently, and over-deployment surfaces only during a vendor audit. Both are addressed the same way: comparing entitlements against actual installation and usage, on a schedule, before renewal dates rather than after. Build the renewal calendar first — it is a small piece of work that immediately produces decisions, and it makes the case for the rest of the programme.
Ettex Sheets holds the asset register with assignment, warranty and end-of-support dates so replacements and renewals are visible ahead of time, Ettex Records keeps the purchase documents, disposal certificates and licence entitlements per asset, and the dependency view of the same estate is the configuration record described alongside it. The finance-side view is covered in fixed asset register.
Plainly: this is a spreadsheet and records approach, not an asset management platform with discovery agents. Past a few hundred devices those tools earn their cost; what this covers is the lifecycle discipline that a tool will otherwise inherit incomplete.
Tracking hardware and software from acquisition through deployment, maintenance and disposal, to know what exists, where it is and what is being paid for.
After deployment — recovery from departing staff, unused licence renewals and undocumented disposal.
Unknown devices receive no patching, protection or scanning, so an accurate inventory is a prerequisite for most controls.
Asset management tracks ownership, cost and lifecycle; a CMDB models components and their dependencies for operational decisions.
Two formats, both standards, both accepted. The choice is less about features than about what your customers and your toolchain already consume.
Every function edits its own copy, and by the third revision nobody can say which is current. That is not a tooling problem until you decide it is.
A cap table is not a summary of ownership. It is the record of every instrument issued, and the errors in it are discovered by somebody else’s lawyer during diligence.