Define the Inventory System of Record
Treat Nmap and site visits as collection methods, not as the inventory database. The required system of record must store assets, support visualization and retrieval, associate assets with IEC 62443 Zones and Conduits, and export a client-shareable report. Importing Nmap output and existing inventory documents is an additional selection criterion.
| Requirement | Acceptance test |
|---|---|
| Asset management | Import or enter an asset, update it, filter it, and retrieve its record without custom processing. |
| Zones and Conduits | Assign assets to Zones and document Conduits between them without maintaining a separate spreadsheet. |
| Reporting | Export an inventory and its Zone/Conduit structure in a format suitable for client delivery. |
| Data ingestion | Map existing Nmap results or inventory documents into stable asset fields without manual re-entry. |
| Operating model | Support periodic manual updates without requiring continuous active discovery. |
Separate Discovery from Lifecycle Management
An Nmap scan provides a point-in-time snapshot; it does not keep the inventory current. Preserve the scan date and source for every imported observation, then reconcile scan results with information collected during site visits. This prevents a newly imported observation from silently replacing validated asset data.
Active scanning risk is environment-dependent and disputed in the available evidence. Do not treat prior successful scans as proof that every OT device will tolerate the same probes. Define scan scope and obtain plant approval according to the site's change and risk controls. If active probing is unacceptable, passive monitoring through SPAN ports was identified as an alternative, but assets that generate no observed traffic can be missed.
Evaluate the Candidate Tools Against the Workflow
The available evidence identifies OTBase, RunZero, Industrial Defender, Asset Guardian, Network Perception, and Claroty as candidates. Reported characteristics include free and paid RunZero options, manual tracking with Asset Guardian, data import with Network Perception, reduced custom coding with Industrial Defender, and passive traffic collection with Claroty. These are field reports rather than verified specifications; validate each capability in a controlled evaluation before selection.
Reject any candidate that cannot preserve manual corrections, represent Zones and Conduits, or generate the required client export. Also distinguish an inventory platform from a discovery platform: continuous scanning or network analysis does not satisfy the stated workflow unless its resulting records can be governed as the authoritative inventory.
Run a Controlled Migration
- Define the minimum asset fields, including a stable identifier, observed addresses, asset description, location, collection source, observation date, validation status, Zone, and connected Conduit.
- Import a representative Nmap result and a sample existing inventory document. Record unmapped, duplicated, or overwritten fields.
- Build a small Zone and Conduit model, then verify that asset membership and inter-zone relationships remain visible after editing and re-importing data.
- Export the inventory and architecture view, and confirm that the client can read the deliverable without access to the inventory application.
- Test the update cycle by importing a later snapshot. Confirm that the tool distinguishes new, changed, unchanged, and missing observations without erasing validated records.
At a reported plant size of approximately 200 to 300 devices, this pilot should expose whether the product removes spreadsheet and script overhead or merely relocates it. Select the tool only after the complete collect, reconcile, model, export, and update cycle succeeds.
FAQ
Can Nmap maintain an OT asset inventory?
No. In this workflow, Nmap supplies a point-in-time snapshot. Maintain the authoritative inventory in a system that preserves validation status, observation dates, manual corrections, and later updates.
How should an OT inventory tool handle IEC 62443 Zones and Conduits?
It should assign assets to Zones, document Conduits between Zones, and retain those relationships through edits, imports, and report exports. Verify this behavior with a small model before migrating the full plant.
What should I test before replacing Excel for 200 to 300 OT assets?
Test Nmap and document imports, duplicate reconciliation, manual edits, Zone and Conduit modeling, client exports, and a second snapshot update. The tool must complete that lifecycle without custom processing becoming the new bottleneck.