Asset management is one of the sections most Pakistani ISPs underestimate when preparing for a CTDISR-2025 audit. The requirement sounds straightforward: maintain an inventory of your IT and network assets. The reality of implementing it against a network that has grown organically over years, with devices added, moved, and sometimes decommissioned informally, is more demanding than it first appears.
Section 3 requires a complete and current IT and network asset inventory, asset classification by criticality, documented lifecycle management procedures, and consideration of third-party asset risks. Each component is audited, and the common finding is not that the ISP has no inventory, it's that the inventory is incomplete, out of date, or not classified in a way that drives the security controls applied to each asset.
What Counts as an Asset
The scope of Section 3 is broader than most ISPs initially assume. Physical hardware is the obvious category: routers, switches, OLTs, ONTs, servers, workstations, laptops, and mobile devices used for business purposes. Network infrastructure including wireless access points, backhaul links, and passive equipment like fiber patch panels are included where they have IP-addressable management interfaces or play a critical role in service delivery.
Software assets are equally in scope: operating systems, NMS platforms, billing systems, RADIUS servers, network management tooling, cloud services, and any licensed software used in operations. An ISP running Zabbix, Splynx, FreeRADIUS, and a ticket management system has a software asset inventory to maintain alongside the hardware inventory.
Data assets, meaning the data sets your organisation holds and processes, also fall under asset management for CTDISR purposes, particularly subscriber data, network configuration data, and credentials. Their treatment intersects with Section 7's data privacy requirements, but asset classification that includes critical data sets is expected in the Section 3 evidence.
Building the Inventory
The starting point for a realistic inventory build is discovery, not documentation. Running an active network scan (using Nmap, your NMS's auto-discovery, or both) against all your IP ranges produces a list of what's actually on the network, which you then reconcile against what you thought was there. The gap between discovered devices and documented devices is the inventory debt that needs to be cleared before an audit.
For each discovered asset, the minimum record includes: asset name or identifier, type and category, make and model, IP address and management interface details, location (site or facility), responsible owner, criticality classification, and current lifecycle status (active, decommissioned, spare). This doesn't require specialised software: a maintained spreadsheet is audit-acceptable if it's current and structured. At larger scale, a CMDB or asset management platform makes maintenance more practical, but it's not mandated.
The harder problem is assets that are physically present but not IP-discoverable: passive infrastructure, ONTs at subscriber premises that don't report to a central management system, offline spares, and decommissioned equipment not yet physically removed. These need a separate physical audit process rather than just a network scan.
Criticality Classification
Every asset in the inventory must be classified by criticality. CTDISR-2025 doesn't prescribe a specific classification scheme, so you define your own tiers, but the classification needs to be defensible: an auditor asking why a core router is classified the same as a spare laptop should get a coherent answer.
A practical three-tier scheme for ISP assets: Critical covers assets whose failure or compromise would directly and immediately affect subscriber service delivery or the security of the network, including core routers, OLTs, authentication servers, and the NMS. Important covers assets that support operations but whose loss doesn't immediately affect subscribers, including NOC workstations, billing servers, and management infrastructure. Standard covers all other assets including endpoint devices, spare hardware, and administrative systems.
The criticality classification drives the security controls applied to each asset: critical assets get the most rigorous access controls, monitoring, patching priority, and backup frequency. This is what makes classification useful rather than just a compliance exercise: it produces a defensible rationale for why your security investments are distributed the way they are.
Lifecycle Management
Lifecycle management procedures cover how assets are handled from procurement through decommission. For CTDISR compliance, the minimum required procedure covers: how new assets are added to the inventory (procurement process, acceptance testing, initial configuration hardening before deployment), how changes to assets are tracked (location changes, configuration changes, ownership changes), and how assets are decommissioned (secure data wiping for storage devices, removal from network access control, inventory status update, physical disposal or storage).
The decommission process is where most ISPs have the largest gap. Equipment that has been replaced but sits connected to the network with old credentials is a security exposure. Equipment that has been disconnected physically but not removed from access control lists and RADIUS authentication is a ghost account waiting to be exploited. Decommission procedures that close these gaps need to exist in writing and be followed consistently.
End-of-life tracking is also part of Section 3: assets that are running software or firmware past vendor end-of-life dates represent known security risk and should be flagged in the inventory with a remediation timeline. Auditors will ask about EOL assets and expect to see either an upgrade plan or a risk acceptance decision with compensating controls documented.
Third-Party Asset Considerations
Assets owned or managed by third parties but used in delivering your services fall under the scope of your Section 3 obligations. This includes co-location facility infrastructure you depend on, cloud provider infrastructure hosting critical systems, and managed service provider tooling with access to your network. For each significant third-party asset relationship, you need to understand what the third party's asset management and security practices are, which flows into the Section 13 third-party risk requirements.
For ongoing tracking of asset status, criticality, and lifecycle across your full CTDISR compliance programme, ComplianceIQ provides the evidence management framework that keeps Section 3 records organised and audit-ready. For a scored assessment of your current asset management maturity, ISP Audit covers this section alongside all others. If your NMS is not yet giving you the network visibility that makes asset discovery practical, NOC Enablement & Monitoring covers the monitoring stack design that makes inventory maintenance much less manual.