OT Asset Inventory
An OT asset inventory is a continuously maintained record of every device on an operational network: its type, vendor, model, firmware, protocols and communication relationships. In rail OT it is the foundation for vulnerability management, segmentation design and compliance evidence.
How it works
In OT, the inventory is typically built by passively observing network traffic: each device is identified from the protocols it speaks, the addresses it uses and the vendor-specific fingerprints in its communication. The inventory records not just what exists but how devices talk to one another, which reveals the real network topology and the actual zone boundaries.
Because rail networks span thousands of wayside locations and hundreds of trains, the inventory must scale to very large asset counts and organize them hierarchically, by line, site, train and consist.
Why it matters for security
You cannot protect what you do not know exists. Every rail cybersecurity regulation, from the TSA directives and NIS2 to IEC 62443 and IEC 63452, begins with identifying critical assets, and vulnerability management, segmentation and incident response all depend on an accurate, current inventory.
Related solution
Building an asset inventory for rail OT
Continuous, passive discovery of every asset across wayside and onboard networks.
See the solution →

