Thirty years of enterprise IT, distilled into something you can use on Monday morning.
Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet.
No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on.
New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.
Hey everybody, and welcome back to the Operational ITAM podcast.
I'm Bill Van Nort, and I'm super excited about episode two for this series.
If you joined me for the first episode, welcome back. I'm glad you're here.
If you are new to the series, I suggest listening to the first episode,
and then come back to episode two.
Good morning, good afternoon, or good evening, wherever you happen to be listening from.
This is the Operational ITAM podcast, the show where we take the unglamorous
machinery of enterprise technology and make it make sense.
I'm your host, Bill, and today's episode is a deep dive of the hardware asset
management topic we briefly touched upon in the first episode.
Welcome in. Grab your coffee, grab your headphones, and let's get into it.
Last time, I told you the hardware lifecycle has seven stages,
and I promised we'd go deeper. Today, we keep that promise.
Quick recap because good teaching repeats itself on purpose Hardware Asset Management,
or HAM is the discipline of managing physical technology assets across their
entire life cycle Request, Procure,
Receive, Deploy,
Maintain, Recover, and Dispose 7 Stages Every device passes through all 7,
whether you're watching or not.
Today, we walk the life cycle gate by gate, and at each gate I'll tell you three things.
What the stage is, what data must be captured, and how it fails.
Because every stage fails the same way in every organization I've ever seen.
The failure modes are practically franchised. Gate 1.
The Request The request stage is where a business need becomes a demand for equipment.
Someone is hired. Someone's machine dies. A project spins up.
Simple, right? Here's what must be captured at this gate.
Who is asking? What are they asking for? What standards it maps to?
Who approved it? And what cost center is paying for it?
Five facts. That's the whole toll.
And here's how it fails. The request happens outside the process.
A manager emails a friend in IT. A department buys its own gear on a credit
card. An executive's assistant just handles it.
Every one of those transactions creates an asset that will haunt your inventory
for years. Because an asset born without a record is a ghost from day one.
We'll talk about ghosts properly in part two. They deserve their own segment.
The control at this gate is a service catalog with standard configurations.
Standards matter more than people think, and not just for cost.
Every deviation from standard is a snowflake. Unique to support,
unique to secure, unique to dispose of.
A fleet of snowflakes isn't a fleet. It's a blizzard.
Gate 2. Procure. Procurement converts the approved request into a purchase,
and this is where the asset record should be born.
Not at receiving. Not at deployment. At the purchase order.
The moment money is committed, a record should exist saying this asset is inbound,
here's what it is, here's what it cost, here's the vendor, here's the contract,
here's the warranty entitlement. What must be captured?
Purchase order number, line item detail, unit cost, vendor, warranty terms,
and, critically, the link between the PO and the eventual serial numbers.
That link is the thread that ties your financial world to your operational world.
Cut that thread, and finance and IT are describing two different companies.
How it fails. Bulk purchases recorded as a single line.
200 laptops, one line item, one lump sum.
Now, try answering three years later, which of those 200 serials is still under
warranty, or what any individual device actually cost for depreciation purposes.
You can't. The data was never atomic, and you cannot split an atom you never had.
Gate 3. Receive. Receiving is where the physical world and the record meet for the first time.
The handshake between the purchase order and the box on the dock.
This is the single highest leverage moment in the entire life cycle.
Capture at this gate. Serial number, asset tag applied, model verified against
the PO, condition confirmed, and location assigned.
Even if that location is just stock room, shelf 4.
Let me say that plainly. If you tag and record assets accurately at receiving,
every downstream stage gets easier.
If you don't, no amount of downstream heroics fully recovers.
Receiving is where data quality is cheapest. Every gate after this one,
the same correction costs more.
How it fails? Receiving is treated as a shipping function instead of a data function.
The box gets signed for, stacked, and the record gets created later.
And later, as we all know, is a mythical time zone where no work has ever actually been performed.
Gate 4. Deploy. Deployment assigns the asset to a person, a place,
or a purpose and puts it to work.
What must be captured, the assignment, who has it, the location,
the date, what configuration is applied, and the status change from in-stock to in-use.
In modern estates, deployment is also where the device enrolls in endpoint management,
joins identity, and inherits security policy, which means deployment is where
HAM shakes hands with security for the first time.
It will not be the last handshake. Keep that thought for the end of the episode.
How it fails. Assignment drift.
The device was deployed to Alice. Alice moved teams. The machine went to Srini.
Srini left. His manager kept it in a drawer as a spare.
The record still says Alice. Three moves. Zero updates.
Multiply by a thousand devices in five years, and your assignment data becomes historical fiction.
Well written, internally consistent, and dead wrong.
The control. No moves without a ticket, and no ticket without a corresponding record update.
In episode one, I called this control adherence, the percentage of lifecycle
events that pass through the sanction process instead of around it.
Deployment, and everything after it, is where that metric earns its keep.
Gate five, maintain. Maintenance is the long middle of the lifecycle.
Repairs, upgrades, warranty claims, and the quiet accumulation of wear and tear.
It's the least glamorous stage, and the longest one. A device spends a few days
in the first four gates, and several years in this one. What's important to capture here?
Incident and repair history tied to the asset record, warranty status,
and any changes to configuration or components.
Why does repair history belong in the asset record?
Because patterns hide in it. If one model generates triple the tickets of its
peers, that's not trivia. That's procurement intelligence.
The maintain stage is where your asset data starts paying you back, if you let it.
Feed repair patterns into your next purchase decision, and asset management
stops being a record-keeping function and starts being a forecasting function.
How it fails. The service desk and the asset register live in different systems that never speak.
Tickets reference Bob's laptop. Which laptop?
The record can't say, so the pattern is never seen. So the same lemon gets purchased three more times.
Gate 6. Recover. Recovery is the retrieval of an asset when its assignment ends.
The employee departs, the project closes, the refresh replaces it.
And I'll be blunt, recovery is the most commonly broken stage in the entire
life cycle, and remote work broke it harder.
When the workforce went home, the devices went with them, and a meaningful percentage never came back.
Offboarding without asset recovery is resignation by mail with company property as a parting gift.
What must be captured? The return itself?
Condition upon return? The status change to in-stock or pending disposal?
And, before anything else happens, confirmation that the device is still enrolled,
still locatable, and still encrypted?
Key item to capture here, the disposition decision. Redeploy it,
hold it as a spare, or retire it.
That decision should be deliberate, recorded, and fast, because a recovered
asset sitting in limbo is depreciating in the dark.
The control at this gate is elegant in its simplicity. Tie asset returned to
offboarding and put teeth in it.
No return, no ticket closure, and someone's name stays on the exception report
until the device is in hand or formally written off.
Remember the daily exception report from volume one? This is what it's for.
That's six gates. The seventh, disposal, is where security, legality,
and money all collide, and it deserves the room to breathe.
Gate seven, dispose. Disposal, or more formally, IT asset disposition,
or ITAD, is the controlled retirement of an asset.
Data sanitized, chain of custody maintained, value recovered where possible,
and the record closed with evidence.
In Volume 1, I called Disposal the shredder in the back room,
and I said the shredder keeps records too.
Here's why that line matters. Disposal is the only life cycle stage where a
mistake can put your company on the front page.
Nobody ever suffered a breaking news segment from a badly recorded deployment.
Improperly disposed devices with recoverable data?
That's a breach, a regulatory event, and a brand wound, all in one dumpster.
So let's get precise about data Sanitization, because precision here is the whole job.
The reference standard is NIST Special Publication 888, the federal media sanitization
guideline that the private sector adopted as the de facto benchmark.
It defines three levels.
The first level, clear, involves logical techniques, overriding,
protecting against simple recovery.
Purge, the second level, offers stronger techniques, cryptographic erase,
block erase, and sanitize commands, which offers protection against laboratory-grade recovery.
The third level? Destroy. Physical destruction.
This level includes shredding, degaussing where applicable. The data dies with the device.
Which level you choose depends on the sensitivity of the data and where the
asset is going next, not on the hardware alone.
A standard-issue laptop might hold the most sensitive data in the company,
depending on who carried it.
And note, for the technically inclined, solid-state drives are not hard drives.
Wear leveling and hidden blocks mean old-school multi-pass overwrites,
the ancient DoD 7-pass folklore, don't reliably sanitize flash media.
If a vendor quotes you passes, that's not a service offering,
that's a museum exhibit.
Purge-level techniques, cryptographic erase in particular, are the modern answer
for SSDs, and as a bonus, Purge preserved the hardware for resale,
which means compliance and residual value are not in conflict.
Also worth knowing, NIST refreshed the standard. Revision 2 shifts the emphasis
from device-by-device wipe recipes toward running a sanitization program,
and points to IEEE 2-883 for technique selection.
The direction of travel is clear. Regulators want to see a system, not a one-off.
Now, most organizations don't dispose of assets themselves. They use an ITAD vendor.
That's great, but hear me. You can outsource the work. You cannot outsource the accountability.
So audit the credential, not the vendor brochure.
The certifications that matter, R2v3, Responsible Recycling Version 3,
covering data security, environmental handling, and downstream accountability.
E-Stewards, similar territory with a strong environmental emphasis,
and NAIDA, which is specific to data destruction, with unannounced audits.
A vendor holding these has been
independently verified against the same standards you're on the hook for.
A vendor without them is asking you to take their word for it,
with your data, on their truck.
And demand the paper, certificates of sanitization or destruction,
serial by serial, matched back to your asset records.
Chain of custody from your dock to final disposition.
When an auditor or regulator asks what happened to a device,
we send it to a recycler is not an answer.
Serial number, certificate, date, method, final disposition. That's an answer.
The shredder keeps records. Make sure yours does.
Now let's talk about the two economic questions that hover over the whole life cycle.
When do you refresh, and what is all this neglect actually costing you?
Refresh first. The industry's center of gravity for laptops is a three to five
year cycle, with desktops running a bit longer, and power users cycling faster.
The total cost of ownership research behind the shorter end is real.
Past year three, out-of-warranty repairs, support burden, and security exposure climb.
One frequently cited study found four-year-old PCs suffered roughly 50% more
security incidents than new ones.
But, and this is the part the OEM's marketing departments won't tell you,
the calendar is a proxy, not a truth.
The mature version of refresh is condition-based. Actual device health.
Actual failure rates from your maintenance and warranty claim data.
Actual performance against the workload.
Some devices earn a sixth year. some demand replacement in their third.
A calendar refresh treats them identically, which means it's simultaneously
scrapping good machines and babying bad ones.
If you captured repair history at gate 5, you already own the data to do better.
This is also very much a current events topic. Operating system end-of-life
waves and component shortages have been pushing device prices up sharply,
which makes squeezing honest extra life from healthy assets a genuine financial
lever, not just a sustainability talking point. And then there are the ghosts.
A ghost asset is a record without a device. Inventory says it exists,
but the physical world disagrees.
Its evil twin, the zombie asset, is a device without a record.
It's on your network, drawing support and licenses and risk,
and your system of record has never heard of it.
Here's the composite picture. And it's typical, not extreme.
An enterprise buys 1,000 laptops.
Three years of departures, upgrades, failures, and office moves later,
the inventory still says 1,000 active.
A physical audit finds 820. The other 180 are ghosts. And here's the expensive
part. The company is still paying for them.
Maintenance contracts. Endpoint security licenses. Software provisioned per
device. Support capacity.
Ghosts don't just distort your data, they draw a salary.
Every ghost was created at a gate. A purchase never atomized.
A receipt never recorded.
A move never ticketed. A departure never recovered.
Which is the entire thesis of this episode. You don't fix ghosts with an annual seance.
You fix them by controlling the gates. So ghosts stop being born.
Let me extend the library one more time since it served us well in Volume 1.
If the estate is a library, then hardware asset management is circulation.
Request is the patron at the desk. Procurement is acquisitions placing the order.
Receiving is cataloging. And
a book shelled without a catalog card is lost the moment you let go of it.
Deployment is checkout. Maintenance is rebinding the ones that get read too many times.
Recovery is the return slot. And every library learns that returns need a due date and a consequence.
Or the shelves empty one borrower at a time.
And disposal is the shredder in the back, with a log, a certificate, and a clean conscience.
One closing principle, in the spirit of the one that closed volume one.
Hardware asset management is a custody discipline. At every moment of an asset's
life, one accountable party holds it, and the record says so.
Every failure we walk through today, the rogue purchase, the lump sum PO,
the unrecorded receipt, the drifted assignment, the unreturned laptop,
and the undocumented disposal, is the same failure, wearing six costumes.
Custody changed, and the record didn't.
Guard the gates, and the record follows the asset. That's the whole discipline in one sentence.
Next episode, we cross over to the intangible side of the house.
Software asset management.
Licenses, entitlements, audits, and the publishers who profit from your confusion.
Bring your skepticism. You'll need it.
Class dismissed. homework. And this one is intended to make this real for everyone.
Pick your last completed employee offboarding and trace the device.
Not the record, the device.
Where is it, physically, right now, and does the record agree?
If you can answer in under five minutes, congratulations, your gates are holding.
If you can't, well, now you know which episode to listen to again.
That's today's episode. Congratulations.
You now know the full spectrum of hardware asset management.
Not all the details, but enough to get you started in a very meaningful way.
And of course, I'll be here next week to provide more relevant ITAM content
for all of you practitioners out there.
I'm Bill Van Nort, and this is the Operational ITAM Podcast.
I look forward to talking more with you next week. Take care.